MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6efac5ee99ea63b5f927bcd342073ff2d3540d572ab7b5d353fe857f8f08d49. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: c6efac5ee99ea63b5f927bcd342073ff2d3540d572ab7b5d353fe857f8f08d49
SHA3-384 hash: 4d9e0d5a00141938068ccc0d5bc14e6e5dbb482fe4b4e8d8619e92a78e4d6fbcadf6c8ec8bfc82b5a397ca6251d0483d
SHA1 hash: 7e30f3bf54ef65c52141cbcd5a63299ed49429f0
MD5 hash: 1d608e6c13f745342b88f763c49b0eb2
humanhash: delaware-twenty-king-lima
File name:c6efac5ee99ea63b5f927bcd342073ff2d3540d572ab7b5d353fe857f8f08d49
Download: download sample
File size:307 bytes
First seen:2026-04-13 07:51:56 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/x-ms-shortcut
ssdeep 3:4xtllvptkldQ3kNP9Kklw7BJizl//Lr1UYrll8wWXiPTFFyC6w5fJWXCBLGPebRJ:4xtJCUOblw7BJYXHpQtXiPTFBQebRJ
TLSH T1BAE023F44F19FE25C1700435C216F3100F1579274540B1F100D050D1D4701863E3E295
Magika lnk
Reporter JAMESWT_WT
Tags:lnk refundonex-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
IT IT
Vendor Threat Intelligence
Malware configuration found for:
LNK
Details
LNK
a command line and any observed urls
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin opendir smb wscript
Verdict:
Malicious
File Type:
lnk
First seen:
2026-04-13T12:20:00Z UTC
Last seen:
2026-04-14T15:10:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.WinLNK.Agent.gen
Gathering data
Threat name:
Win32.Trojan.WinLnk
Status:
Malicious
First seen:
2026-04-11 18:03:53 UTC
File Type:
Binary
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PDF_in_LNK
Author:@bartblaze
Description:Identifies Adobe Acrobat artefacts in shortcut (LNK) files. A PDF document is typically used as decoy in a malicious LNK.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments