Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Files.lnk

Overview

General Information

Sample Name:Files.lnk
Analysis ID:796592
MD5:b0166f01c48a7a117019d1ebdb77e8a2
SHA1:2091cc337e6a69bf6bc5126c0e66afd12fad2514
SHA256:b968bc92e3f0f62037ab6f29c13ba6895b6b2d78ea04f32eb1aceca9b509208a
Tags:lnk
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: C00104C7

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file

Classification

No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Files.lnkAvira: detected
Source: Files.lnkReversingLabs: Detection: 20%
Source: Files.lnkVirustotal: Detection: 16%Perma Link
Source: Files.lnkReversingLabs: Detection: 20%
Source: Files.lnkVirustotal: Detection: 16%
Source: Files.lnkLNK file: ..\..\..\..\ivy\texture.bat
Source: classification engineClassification label: mal56.winLNK@0/0@0/0
No Mitre Att&ck techniques found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Files.lnk21%ReversingLabsShortcut.Trojan.MalLink
Files.lnk16%VirustotalBrowse
Files.lnk100%AviraLNK/Runner.VPOY
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox Version:36.0.0 Rainbow Opal
Analysis ID:796592
Start date and time:2023-02-02 00:33:56 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 3m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
Number of analysed new started processes analysed:0
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
  • HDC enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample file name:Files.lnk
Detection:MAL
Classification:mal56.winLNK@0/0@0/0
Cookbook Comments:
  • Found application associated with file extension: .lnk
  • Unable to launch sample, stop analysis
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: C00104C7
  • Excluded domains from analysis (whitelisted): fs.microsoft.com
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:MS Windows shortcut, Item id list present, Has Relative path, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hidenormalshowminimized
Entropy (8bit):1.6915641824581837
TrID:
  • Windows Shortcut (20020/1) 100.00%
File name:Files.lnk
File size:1228
MD5:b0166f01c48a7a117019d1ebdb77e8a2
SHA1:2091cc337e6a69bf6bc5126c0e66afd12fad2514
SHA256:b968bc92e3f0f62037ab6f29c13ba6895b6b2d78ea04f32eb1aceca9b509208a
SHA512:a715389b3f0797bf38ead485640f6a4ccbc0f6ce884dee1048915a67f59969cfe81d4bf1bd5d375fb22ce66a5569b6af2370085261d1da97a54e289da60968ef
SSDEEP:6:4xt/98el//t5zC7lkcFw1IxcFwR+SkEMl47J6jclRaQmZAMl47tKHkWBdW:8X8K/takCwiCwEIMm9lDm1XHLy
TLSH:1B21DF246EEB6B21EBE2D6B22071A3A54E773852F951C3CC0104AA8D203760479B9F27
File Content Preview:L..................F.@...........................................................P.O. .:i.....+00.../C:\...................J.1...........ivy.8.............................................i.v.y.....b.2...........texture.bat.H...............................
Icon Hash:0c9ea2b28eb9bd0d

General

Relative Path:..\..\..\..\ivy\texture.bat
Command Line Argument:
Icon location:c:\windows\explorer.exe
Report size exceeds maximum size, go to the download page of this report and download PCAP to see all network behavior.
No statistics
No system behavior
No disassembly