MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41adec097d93034cc669bc98a4e7e723f62c3f4bdcf6e017025dd9ad5b7d1585. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: 41adec097d93034cc669bc98a4e7e723f62c3f4bdcf6e017025dd9ad5b7d1585
SHA3-384 hash: e8d37514181a351da9508dee0ddf07983fcfc1e9975c3c1da8174c2ae2b76efe03f08cc9cbc0f32e026b5fb55ddecdc0
SHA1 hash: 0ea4abb22477cb4b659850cc8d6c62323641b84b
MD5 hash: 26cfc1787e6277b95f634b73cb4a43a3
humanhash: oscar-aspen-kitten-nitrogen
File name:Документы к договору.zip
Download: download sample
File size:3'530 bytes
First seen:2026-05-26 10:31:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:9jhrL8vBpYxdRschrL8vBpYxdXbndhrL8vBpYxdGdVsXbn1/:LrwZpCsmrwZpsb3rwZpHvsXb1/
TLSH T1DA71E902429B9B8481FDB5B3120F97C7F734A66469233B734375A6794EB32808D6011F
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Счет на оплату № 4135 от 23.05.2026.pdf.lnk
File size:1'747 bytes
SHA256 hash: 053e74cbbf69f26dbe7981b297b7578a8eb7950d1c968200bc27b4d853565e86
MD5 hash: 02044b2d1674a060ea2551af6fcbd620
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
virus agent hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade powershell
Verdict:
Malicious
File Type:
zip
First seen:
2026-05-24T18:38:00Z UTC
Last seen:
2026-05-28T02:11:00Z UTC
Hits:
~100
Gathering data
Threat name:
Shortcut.Trojan.WinLnk
Status:
Malicious
First seen:
2026-05-26 10:32:35 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
16 of 38 (42.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_PowerShell
Author:SECUINFRA Falcon Team
Description:Detects the reference to powershell inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments