🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b2ce323f3eef892d7fdc6a89419b2593b7557a7e8873fa196f6e01648aa67c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NetSupport


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: 4b2ce323f3eef892d7fdc6a89419b2593b7557a7e8873fa196f6e01648aa67c0
SHA3-384 hash: 646c7cabc97655fe53d32d63245a9f7239b8a9661755a4df52c1aa94b21d4b7ef6ca69ab6c116c71e3f7882dc8daba33
SHA1 hash: 9c9fc660da68775629ab48bb82dd4775b153597a
MD5 hash: bcfd6a7b699f9ff643d346a958ca04a9
humanhash: spaghetti-carpet-freddie-stairway
File name:4b2ce323f3eef892d7fdc6a89419b2593b7557a7e8873fa196f6e01648aa67c0
Download: download sample
Signature NetSupport
File size:2'030 bytes
First seen:2026-06-03 06:45:11 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/x-ms-shortcut
ssdeep 24:8SYe9NcrGFjc6aKKILhWhWAsuWkp+/CWP2+/C46DwW8loxO4I0WROkOFpK6+/CIz:8StNcqUbsmHn8lSIL3ABcatdMq4z
Threatray 1'329 similar samples on MalwareBazaar
TLSH T15A41A11617E50715D7F78A3A9CF7F3128635B915ED624FEE024092881CA4128E875F6F
Magika lnk
Reporter JAMESWT_WT
Tags:djkmgndkjfgndfg-com iisexpness-com lnk NetSupport printerdrvrs-com skadfjsdijfhsfso9to-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
IT IT
Vendor Threat Intelligence
Malware configuration found for:
LNK
Details
LNK
a command line and any observed urls
Verdict:
Malicious
Score:
96.5%
Tags:
shell virus sage
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive masquerade powershell
Verdict:
Malicious
Labled as:
TrojanDownloader/LNK.NetLoader
Verdict:
Malicious
File Type:
lnk
First seen:
2026-06-03T12:40:00Z UTC
Last seen:
2026-06-04T20:17:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.WinLNK.Agent.gen
Gathering data
Threat name:
Win32.Trojan.WinLnk
Status:
Malicious
First seen:
2026-05-30 22:47:51 UTC
File Type:
Binary
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Badlisted process makes network request
Malware family:
NetSupport
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:SUSP_LNK_PowerShell
Author:SECUINFRA Falcon Team
Description:Detects the reference to powershell inside an lnk file, which is suspicious
Rule name:SUSP_LNK_SuspiciousCommands
Author:Florian Roth (Nextron Systems)
Description:Detects LNK file with suspicious content

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments