MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16a4fc7ddaa1ebd0d8604b04cf5a02168e89c5ff646c6a53fea5cfe9ceea7156. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: 16a4fc7ddaa1ebd0d8604b04cf5a02168e89c5ff646c6a53fea5cfe9ceea7156
SHA3-384 hash: 5b71ff286f085f59ca529f76264f03b99bf34eaa92e961358b29e2caa9a9ac6432c5e18e4c7ae763c4ea67b037dadead
SHA1 hash: e6243c37c279e4cb4710962b1386affbb51d97e9
MD5 hash: 11955cae15c492c4a86116840e4c5b37
humanhash: kitten-lamp-aspen-low
File name:Fexoglobal_CRM_API_Documentation.zip
Download: download sample
File size:2'268 bytes
First seen:2026-06-23 14:05:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 48:92/2e1sGgL0mPQybCcGN+CgAA377VuFm/iVxiS8CrF/jG:76dgL0m401GXgAaXVcCcMfIt6
TLSH T1B841E9064FDA1748CBEBC57AE729032CA7AA9876293DE64D1B67880585320A6D23831D
Magika zip
Reporter smica83
Tags:UKR zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Fexoglobal_CRM_API_Credentials.pdf.lnk
File size:2'942 bytes
SHA256 hash: d829a13a08f0c3b34dfd608c5697c16c15d26dcab3c3621d230a3e4bf74e295f
MD5 hash: 0e500520ee4d90572a53a9480ff32aa7
MIME type:application/octet-stream
File name:Fexoglobal_CRM_API_Documentation.pdf.lnk
File size:2'954 bytes
SHA256 hash: d0e6355116245357d96f1c70c40fad11da2c3d5befe6a72fab7438f2d0a9f37a
MD5 hash: cd1a8b836902b2458c6e4d7f3c3e4b3b
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
infosteal obfuscate xtreme sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug autoit conhost evasive fingerprint keylogger masquerade reconnaissance
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-23T13:04:00Z UTC
Last seen:
2026-06-25T06:43:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Suschil
Status:
Malicious
First seen:
2026-06-23 14:06:38 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware discovery spyware
Behaviour
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Time Discovery
Drops file in Windows directory
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:PDF_in_LNK
Author:@bartblaze
Description:Identifies Adobe Acrobat artefacts in shortcut (LNK) files. A PDF document is typically used as decoy in a malicious LNK.
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments