MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fecc709e85c8951c24b3c315c235c99c46c1cd0a843779d4f4cba545cec0f52c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: fecc709e85c8951c24b3c315c235c99c46c1cd0a843779d4f4cba545cec0f52c
SHA3-384 hash: be76d8a9eae99b1f5cdfa09a54162ad6840790dff0bda8d9fcc7159790248f420464f5d6d86aff534c256d32611682c1
SHA1 hash: 9bcb52b8cbe56db9067798da5b817290a5069219
MD5 hash: b442132b53b81260bf4b4224bb7f728b
humanhash: blue-twenty-hot-arizona
File name:DOC-9M8ORG lnk
Download: download sample
File size:577 bytes
First seen:2026-07-31 12:20:08 UTC
Last seen:2026-07-31 12:51:31 UTC
File type:Shortcut (lnk) lnk
MIME type:application/x-ms-shortcut
ssdeep 6:4xtqsllo1yl//VnmqlDglXONk9bEK9+Yt/n+SkyGkRksSelgMyDdNbKYMiXK8lj1:8YslWm/VnEXzQK9+a+UfaMyDjLdZplX
TLSH T108F0D8046DFA0620D2B3CE7B409B670485FB7553DF66CF5D414445585034100F57AF3B
Magika lnk
Reporter JAMESWT_WT
Tags:lnk pdf-bro-lat remoto-ddins-click Spam-ITA

Intelligence


File Origin
# of uploads :
4
# of downloads :
50
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Payload URLs
URL
File name
https://pdf-bro.lat/h/estagio1.php?r=360761F15794
LNK File
Behaviour
BlacklistAPI detected
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
lolbin mshta pcalua
Verdict:
Malicious
File Type:
lnk
First seen:
2026-07-30T03:24:00Z UTC
Last seen:
2026-08-02T03:14:00Z UTC
Hits:
~100
Detections:
Trojan.WinLNK.Agent.sb HEUR:Trojan-Downloader.WinLNK.Agent.gen HEUR:Trojan-Downloader.Script.Generic Trojan-Downloader.Agent.HTTP.C&C PDM:Trojan.Win32.Generic HEUR:Trojan.Multi.GenBadur.genw Trojan.Win32.Agent.sb HEUR:Trojan.Script.Generic HEUR:Trojan-Dropper.Script.Agent.gen
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
LNK
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-07-30 15:29:00 UTC
File Type:
Binary
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
adware execution persistence ransomware spyware
Behaviour
Modifies Internet Explorer settings
Modifies registry class
Script User-Agent
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
Executes a command shell one-liner
Checks computer location settings
Badlisted process makes network request
Malware Config
Dropper Extraction:
https://pdf-bro.lat/h/estagio1.php?r=360761F15794
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments