MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1f460d60bed7c6c97dad6cd21d2acdd319d2dcce3e297c06a84430dea2b818c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: e1f460d60bed7c6c97dad6cd21d2acdd319d2dcce3e297c06a84430dea2b818c
SHA3-384 hash: 8259b9a16a54e02526b6f11291ed434b3b24107ffda8bb89290ce3780fc28c9e4799fbd944e3a0bf7d57985bc3d253ed
SHA1 hash: 51353bddbeef654530156f4e8d4653ea5b20530a
MD5 hash: 40371daacdb1f729a3215aa7c5ac4be7
humanhash: golf-steak-bulldog-juliet
File name:DOC-1ITNIT.lnk
Download: download sample
File size:1'629 bytes
First seen:2026-08-26 07:43:47 UTC
Last seen:Never
File type:Shortcut (lnk) lnk
MIME type:application/x-ms-shortcut
ssdeep 12:8rlfyA0m/VnEXzZURl2+UvfRi1CYmFFRuenl+glwiuU6U6r6IubdpYrn1IlI7GXR:8YAJtnyUD2++iyR5ns6kZrJqddNXuHY
TLSH T12B3145503AEA0514F2F7AF77C8BB571089BAB8568D70CA1D0550424C1422A42E6BEF67
Magika lnk
Reporter abuse_ch
Tags:lnk

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
SE SE
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd lolbin mshta
Verdict:
Malicious
File Type:
lnk
First seen:
2026-08-24T04:14:00Z UTC
Last seen:
2026-08-26T04:06:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
68 / 100
Signature
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Windows shortcut file (LNK) contains suspicious command line arguments
Windows shortcut file (LNK) starts blacklisted processes
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
2 match(es)
Tags:
Execution: CMD in LNK LNK LOLBin LOLBin:cmd.exe Malicious T1059.003 T1202: Indirect Command Execution T1204.002
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
Checks computer location settings
Badlisted process makes network request
Malware Config
Dropper Extraction:
https://safe-pdf-viewer.lat/h/estagio1.php?r=360761F15794
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Shortcut (lnk) lnk e1f460d60bed7c6c97dad6cd21d2acdd319d2dcce3e297c06a84430dea2b818c

(this sample)

  
Delivery method
Distributed via web download

Comments