MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 634bef6e54d4c795df01131de8f38d9e8b7fea7a562b600beb7307a325669cb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: 634bef6e54d4c795df01131de8f38d9e8b7fea7a562b600beb7307a325669cb2
SHA3-384 hash: 7424fd649a1c7b17180bbe9abdbf4fe43e1c4babef0d0417fdb7c2b2e86e7dbf16a95ed0b5674652e349415accab5a63
SHA1 hash: 711114398890dc526ea252e7693fb14838e811e6
MD5 hash: 9b88e63a666bea9cbc4627c38bc8e895
humanhash: lithium-table-king-fruit
File name:images_20260724_151353.zip
Download: download sample
File size:12'957 bytes
First seen:2026-07-25 10:33:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:WeJC1vINmUoWEi1fp7YCrR2OgKaN5DK+/F6OtgrVXKI:WeYtIN5BE4p7JrfaN5G+MOtgRXn
TLSH T13A42CFCD9FBC0D53A0A8EFB92C43BA20702CB7370675C36AF2B5AB769A1D9544035A01
Magika zip
Reporter JAMESWT_WT
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
IT IT
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:IMG_20260725_062423.jpg.lnk
File size:1'469 bytes
SHA256 hash: 5cfe13bf7ad9e1b263416619bd38936ca1891caa04d037af5060999d4548ea90
MD5 hash: e040dedf64dffd2f6eddcfddd87f6303
MIME type:application/octet-stream
File name:VID_20260725_040204.mp4
File size:11'900 bytes
SHA256 hash: b156c533a0f5305845a907f119aa5b5b7627c5d25026469fa3d429a88c5cef6f
MD5 hash: c29c799d456b3c978f1f49931a225675
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-07-25T08:16:00Z UTC
Last seen:
2026-07-26T18:17:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
3 match(es)
Tags:
Batch Command Execution: CMD in LNK Execution: PowerShell in LNK LNK LOLBin LOLBin:powershell.exe Malicious PowerShell PowerShell Call T1059.001 T1059.003 T1202: Indirect Command Execution T1204.002 Zip Archive
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-07-25 10:33:10 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:SUSP_LNK_PowerShell
Author:SECUINFRA Falcon Team
Description:Detects the reference to powershell inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments