Summary | ZeroBOX

inv.lnk

GIF Format Lnk Format
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 20, 2024, 9:11 a.m. Nov. 20, 2024, 9:14 a.m.
Size 1.9KB
Type MS Windows shortcut, Points to a file or directory, Icon number=11, Archive, ctime=Tue Nov 12 01:01:00 2024, mtime=Tue Nov 12 01:00:50 2024, atime=Tue Nov 12 01:00:50 2024, length=156, window=hidenormalshowminimized
MD5 842132a519bc8f532382c78c1895cb02
SHA256 b5bb66a242f901ac5c82eaa653209a45faa6efc968282e1ad1af38738947fadb
CRC32 9282D044
ssdeep 24:8nps8zZHWWY6/wHcmPnqQE58S5V74DCj+7SToX2JQvMP37tAX2xV74u:8np3HWWf0cuqQE74D75X2JzKX2j74
Yara
  • lnk_file_format - Microsoft Windows Shortcut File Format
  • Lnk_Format_Zero - LNK Format

IP Address Status Action
164.124.101.2 Active Moloch

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Access is denied.
console_handle: 0x0000000b
1 1 0
file C:\Users\test22\AppData\Local\Temp\inv.lnk
Symantec Trojan Horse
ESET-NOD32 LNK/TrojanDownloader.Agent.CDU
Sophos Troj/DownLnk-CN
Google Detected
GData Win32.Trojan.Agent.7ROWFL
Ikarus Trojan-Downloader.LNK.Agent
Tencent Win32.Trojan-Downloader.Der.Dplw
huorong TrojanDownloader/LNK.Agent.en
alibabacloud Trojan[downloader]:Win/Agent.CFW
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\Mozilla Thunderbird\Capabilities\Hidden