MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 926bbc1708cf7e113cc11275236b7be69d02776efbd177a2487b898c1c33fbaf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 926bbc1708cf7e113cc11275236b7be69d02776efbd177a2487b898c1c33fbaf
SHA3-384 hash: 605f206b34b9ca4518982887b670d4a560d9e7902a5ddbff315223fef6f716f36014efa6fd0629581e799435406f5d07
SHA1 hash: 4ce57f0f79ed539760c73096b1b52daf8b747aa7
MD5 hash: 49680ab03e532a65e64d7da62be59f4d
humanhash: wyoming-freddie-lima-fourteen
File name:live.lnk
Download: download sample
File size:2'490 bytes
First seen:2026-07-13 17:23:46 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/x-ms-shortcut
ssdeep 24:8KAFpQQpGsSYbPR4Vok3+f8cy4o0gfb4o0OBq8bM4:87FlSyPR4VT8No5koS5
TLSH T128514C040BDD1724D372CD3668FA920244307467EE169F6E4398168E6822614FE36F6F
Magika lnk
Reporter abuse_ch
Tags:lnk

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
SE SE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
obfusc shell sage
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw
Score:
68 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Opens network shares
Windows shortcut file (LNK) starts blacklisted processes
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1941690 Sample: live.lnk Startdate: 13/07/2026 Architecture: WINDOWS Score: 68 41 Antivirus / Scanner detection for submitted sample 2->41 43 Windows shortcut file (LNK) starts blacklisted processes 2->43 45 Multi AV Scanner detection for submitted file 2->45 11 cmd.exe 7 2->11         started        process3 signatures4 57 Windows shortcut file (LNK) starts blacklisted processes 11->57 59 Opens network shares 11->59 14 cmd.exe 11->14         started        17 conhost.exe 1 11->17         started        process5 signatures6 65 Windows shortcut file (LNK) starts blacklisted processes 14->65 67 Opens network shares 14->67 19 cmd.exe 14->19         started        22 conhost.exe 1 14->22         started        process7 signatures8 49 Windows shortcut file (LNK) starts blacklisted processes 19->49 51 Opens network shares 19->51 24 cmd.exe 19->24         started        27 conhost.exe 1 19->27         started        process9 signatures10 53 Windows shortcut file (LNK) starts blacklisted processes 24->53 55 Opens network shares 24->55 29 cmd.exe 24->29         started        32 conhost.exe 1 24->32         started        process11 signatures12 61 Windows shortcut file (LNK) starts blacklisted processes 29->61 63 Opens network shares 29->63 34 cmd.exe 29->34         started        37 conhost.exe 1 29->37         started        process13 signatures14 47 Opens network shares 34->47 39 conhost.exe 1 34->39         started        process15
Verdict:
Malware
YARA:
2 match(es)
Tags:
Execution: CMD in LNK LNK LOLBin LOLBin:cmd.exe Malicious T1059.003 T1202: Indirect Command Execution T1204.002
Threat name:
Shortcut.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-13 01:04:51 UTC
File Type:
Binary
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: LoadsDriver
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Shortcut (lnk) lnk 926bbc1708cf7e113cc11275236b7be69d02776efbd177a2487b898c1c33fbaf

(this sample)

  
Delivery method
Distributed via web download

Comments