MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b4194bdfe40d94031a94b30397ffd8a4b09d0a4057668e897b8bdcd1703dd01. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DonutLoader


Vendor detections: 14


Intelligence 14 IOCs YARA 1 File information Comments 1

SHA256 hash: 3b4194bdfe40d94031a94b30397ffd8a4b09d0a4057668e897b8bdcd1703dd01
SHA3-384 hash: 864c5ecef6902d60fa82add603650496016867275634e989cee187ddc0cd1409ca34a56ff6cbc2a7e32f293d4ee2bef4
SHA1 hash: dcac34657f59ac8e99edcc1d1aacc618a5131aa9
MD5 hash: 0b937b7da4602a8aa5346681b13a3466
humanhash: lactose-spring-sierra-nebraska
File name:د_هغو_کارکوونکو_لېست_چې_د_فکري_او_رواني_جګړې_سیمینار_ته_ورپېژندل_شوي_وو.pdf.lnk
Download: download sample
Signature DonutLoader
File size:1'133 bytes
First seen:2026-05-20 12:18:44 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/x-ms-shortcut
ssdeep 24:84TEyGxCCKhBUwd+/eJ+3xakCak6rlOePFabqumb:84oiBnuxaLa1Btat0
TLSH T15521CB0819D45F66D7B2C93B006BA3088666BA0BE922CF1E019455CD1C1E250E829E6E
Magika lnk
Reporter smica83
Tags:donutloader lnk XenoRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
LNK
Details
LNK
a command line and any observed urls
Verdict:
Malicious
Score:
94.1%
Tags:
virus shell sage
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Payload URLs
URL
File name
https://abimj.edu.af/institute/cloudiyaf/index.php
LNK File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
dropper lolbin masquerade mshta
Verdict:
Malicious
File Type:
lnk
First seen:
2026-03-09T15:32:00Z UTC
Last seen:
2026-05-22T06:37:00Z UTC
Hits:
~100
Detections:
Trojan.Win32.Agent.sb HEUR:Trojan.WinLNK.Agent.gen Trojan-Downloader.Agent.HTTP.C&C PDM:Trojan.Win32.Generic HEUR:Trojan.Script.Generic Trojan.WinLNK.Agent.sb
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Sigma detected: Suspicious MSHTA Child Process
Uses an obfuscated file name to hide its real file extension (double extension)
Windows shortcut file (LNK) contains suspicious command line arguments
Windows shortcut file (LNK) starts blacklisted processes
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1916312 Sample: U062a#U0647_#U0648#U0631#U0... Startdate: 20/05/2026 Architecture: WINDOWS Score: 76 28 abimj.edu.af 2->28 34 Antivirus detection for URL or domain 2->34 36 Windows shortcut file (LNK) starts blacklisted processes 2->36 38 Multi AV Scanner detection for submitted file 2->38 40 3 other signatures 2->40 10 mshta.exe 14 20 2->10         started        signatures3 process4 dnsIp5 32 abimj.edu.af 103.132.98.226, 443, 49717, 49722 MOCI-AS-APMinistryofCommunicationITAF Afghanistan 10->32 26 C:\Users\user\AppData\Local\...\document.pdf, PDF 10->26 dropped 42 Windows shortcut file (LNK) starts blacklisted processes 10->42 15 cmd.exe 3 2 10->15         started        file6 signatures7 process8 process9 17 Acrobat.exe 57 15->17         started        19 conhost.exe 15->19         started        process10 21 AcroCEF.exe 87 17->21         started        process11 23 AcroCEF.exe 3 21->23         started        dnsIp12 30 23.48.8.182, 443, 49739 AKAMAI-AS-AkamaiTechnologiesIncUS United States 23->30
Gathering data
Threat name:
Shortcut.Backdoor.Xenorat
Status:
Malicious
First seen:
2026-05-14 14:20:43 UTC
File Type:
Binary
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
xenorat
Score:
  10/10
Tags:
family:donutloader family:xenorat discovery loader persistence rat trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Adds Run key to start application
Checks computer location settings
Badlisted process makes network request
Detect XenoRat Payload
Detects DonutLoader
Family: DonutLoader
Family: XenoRat
Malware Config
C2 Extraction:
185.235.137.106:8996
Dropper Extraction:
https://abimj.edu.af/institute/cloudiyaf/index.php
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-05-20 15:42:39 UTC

Payload URL:
https://abimj.edu.af/institute/cloudiyaf/index.php