MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0aa8796ec42231ee70586d3d48c7271bad38377c208fbbbfad578f6eef04313d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 0aa8796ec42231ee70586d3d48c7271bad38377c208fbbbfad578f6eef04313d
SHA3-384 hash: 8080369d5a3c23e2cf3c6458f20de273a81b148972f6b9d38c376ee8d039d2acabb9ff45d4b6739328197d93b8ccd8ee
SHA1 hash: b6de0cd902523e50da8c248935d83b1f31135835
MD5 hash: fc96309caf93421f63c646c5b94194d5
humanhash: mirror-snake-lake-yankee
File name:Loader.7z
Download: download sample
File size:10'683'732 bytes
First seen:2026-07-25 19:46:13 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 196608:JIs1tRMNHL5V5yn3E6Ywo8aQZeolG9+5xru8xwGxtNrHPHBIhpI93hGAwIjZ:D7GHFan06Yr8hUQGMru8t98C3hJw2Z
TLSH T1F2B6332345E5CF3F9F2E2C1C964E465D75BA8A9FB091D320CB6A9A4624DDA0CD4321FC
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter Anonymous
Tags:7z

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
DE DE
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Loader.exe
File size:12'899'328 bytes
SHA256 hash: d0dfbb238ba41aaba6f12aad81662ca512058afe12ad865840c4583264625360
MD5 hash: 4ac2d1f635e97ea2699d5e43da5fc1cc
MIME type:application/x-dosexec
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm crypto fingerprint keylogger obfuscated packed packed reconnaissance vmprotect
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive Executable PE (Portable Executable) PE File Layout SFX 7z
Threat name:
Win64.Trojan.Suschil
Status:
Malicious
First seen:
2026-07-25 19:47:00 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments