Report - NATO%20company.lnk.lnk

Lnk Format GIF Format
ScreenShot
Created 2024.08.21 15:16 Machine s1_win7_x6401
Filename NATO%20company.lnk.lnk
Type MS Windows shortcut, Item id list present, Icon number=13, System, Directory, Reparse point, ctime=Thu Dec 12 08:02:54 5275, mtime=Fri Mar 31 01:14:42 5950, atime=Wed Mar 26 14:33:49 7552, length=67504132, window=hide
AI Score Not founds Behavior Score
1.4
ZERO API file : clean
VT API (file) 6 detected (CVE-2010-2568, Save, Link, Crafted)
md5 1099227fc19bfaab01b509e016079fa0
sha256 9557bf84b1c63559c3010d5f4ba0f0a56d58cbe0e4e7a50f86ae888206842d19
ssdeep 3072:LXRwAblQAxtTRMEM8r4ohmJnnL6TPffKaYfRWzPSizmCN1S+zkVJZe:TnblnXTRWGJwnL6bfyH5qKiCfVJZe
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a shortcut to an executable file
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious
info Command line console output was observed

Rules (2cnts)

Level Name Description Collection
info lnk_file_format Microsoft Windows Shortcut File Format binaries (upload)
info Lnk_Format_Zero LNK Format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure