🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82b6f8b1671bfcebe13007d11ba79e06554b260b3d610b4a2a721d12f7ec3f96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 6 File information Comments

SHA256 hash: 82b6f8b1671bfcebe13007d11ba79e06554b260b3d610b4a2a721d12f7ec3f96
SHA3-384 hash: 7064355f6898cb8b41a55b935c0486c53d06075b82aa5bc00bf1c5c416313290c323f8338bc62a88ecef58afad723fe1
SHA1 hash: 884df1e44e6ceec6d874091cf789ab83047bd694
MD5 hash: c22f745b6cf425bb47691fe2822e5af1
humanhash: black-cat-cup-uncle
File name:suspicious.zip
Download: download sample
File size:34'641 bytes
First seen:2026-09-26 19:15:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:G9K8BaOVRLdXzXJA0BWuLPO99oaUurCgsD0HX4UaFgTWHP:G9K8BxVzraw3OIZurg0HIUmggP
TLSH T159F2D022DE9314C2CE5962FB68079519F580CB0E8A5B3DC9E74D944D0F928772FAC3A7
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
HU HU
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:No. 4.png.lnk
File size:1'460 bytes
SHA256 hash: dab9927289572a20934bdf9ded5b3a51c0a330d7e2fd5e1c4a3ef8620c908089
MD5 hash: a7500752407b16dc505f2555cd011c3e
MIME type:application/octet-stream
File name:Purchase List .txt.lnk
File size:1'030 bytes
SHA256 hash: c5eb3417d6873fb9ac7406a4599991b5a4348321ebb2c5f54ff0ce50ce4217e1
MD5 hash: 35821f217d3167bea42d37ada27ff935
MIME type:application/octet-stream
File name:demo.mp4.lnk
File size:1'024 bytes
SHA256 hash: ea7d17815fb64a99b4e672d29a13a52f7420e8078e76d4df8cc077b846a0fc39
MD5 hash: 88866f1bafd04960b8e4b5d39c49bf0e
MIME type:application/octet-stream
File name:Rlocal.hta
File size:68'358 bytes
SHA256 hash: 4d5f6180d6fa45610616e66dcd3b8db324bd8d9b3d16a82c94024d4d013dfaa8
MD5 hash: 13e912d92e34c80ea643c539db1a0a68
MIME type:text/html
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-09-26T03:53:00Z UTC
Last seen:
2026-09-26T04:11:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
3 match(es)
Tags:
DeObfuscated Execution: CMD in LNK LNK LOLBin LOLBin:cmd.exe Malicious Obfuscated SOS: 0.27 T1027 T1059.003 T1059.005 T1202: Indirect Command Execution T1204.002 T1218: System Binary Proxy Execution VBScript Zip Archive
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-09-24 23:53:33 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
2 of 36 (5.56%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments