Report - E_Sales_Doc43032234647380921_pdf.lnk

Generic Malware Lnk Format GIF Format
ScreenShot
Created 2024.07.26 18:43 Machine s1_win7_x6402
Filename E_Sales_Doc43032234647380921_pdf.lnk
Type MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Has command line arguments, Icon number=13, Archive, ctime=Fri May 24 04:15:12 2024, mtime=Fri May 24 04:15:12 2024
AI Score Not founds Behavior Score
1.0
ZERO API file : clean
VT API (file)
md5 0a8c019dde3aafa90a3cd96efd391df8
sha256 d04e73e71b3c89b0086321d18cdc6ddd077a7de1aa77353eb6bf4dd29aa2565d
ssdeep 24:8TJbmOuNVz1A4UPAdr+/sdxpAkGYYqVgqe7ab/rMTcm:8T1mjNVze4l1dzBhe7ab4c
imphash
impfuzzy
  Network IP location

Signature (3cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a shortcut to an executable file
info Command line console output was observed

Rules (3cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
info lnk_file_format Microsoft Windows Shortcut File Format binaries (upload)
info Lnk_Format_Zero LNK Format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure