MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d5dfbf29d474f2fa504a9e5d625169ab3b09ecec719d5b5ecb0cdd893d2080f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 5 File information Comments

SHA256 hash: 2d5dfbf29d474f2fa504a9e5d625169ab3b09ecec719d5b5ecb0cdd893d2080f
SHA3-384 hash: 2e581d4eec1c0ec1895fb09191df53ab5f78319e28aa09d4d53b3af1a7039d3c47189d9fb3157fb657e7d68f4045c487
SHA1 hash: ce4cc6d321c9ed471a1cf792c850e6f8796160ea
MD5 hash: 7c8df8248b248f2be53b525fd695750b
humanhash: seventeen-montana-victor-avocado
File name:Dohovir.zip
Download: download sample
File size:83'685 bytes
First seen:2026-07-15 20:45:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 96:smLHyO+nj58g2VcL1ynH+njlCpCNys+njPkSS19QXkR5:BHcy06HcRkkcIvXvv
TLSH T1FD83DF3431E90118E1F3FE716DF477D6AD5BB9B7EAB11688594102060D22B80FE26B3B
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
138
Origin country :
HU HU
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:Spisok_na_Zakupivly.xlsx.lnk
File size:38'875 bytes
SHA256 hash: 5fa032ceb017366e473a5ca6f5f98dd799254943a7635b0190995f75b5da4f54
MD5 hash: a3493cae9ddfa077479b43f7f3390f84
MIME type:application/octet-stream
File name:Dohovir.docx.lnk
File size:28'211 bytes
SHA256 hash: be3b89da7df189548aaf80954f46bccda37f048fba2b2e94d0643fe1610c08c4
MD5 hash: 16dde91abaafb0471b0a06e56325936a
MIME type:application/octet-stream
File name:Scan_013.pdf.lnk
File size:16'229 bytes
SHA256 hash: 5781ddf3307fa8e01a3642e1bcd11b42217f05bfa75e73c295af5f7f0bb20e9e
MD5 hash: a7886622207fe86c3379dec8d559db31
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
xtreme shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 certutil cmd dropper evasive lolbin masquerade powershell wscript
Verdict:
Malicious
File Type:
zip
First seen:
2026-07-15T02:11:00Z UTC
Last seen:
2026-07-16T19:10:00Z UTC
Hits:
~10
Gathering data
Threat name:
Shortcut.Trojan.Suschil
Status:
Malicious
First seen:
2026-07-14 17:55:47 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Certutil_Decode_OR_Download
Author:Florian Roth (Nextron Systems)
Description:Certutil Decode
Reference:Internal Research
Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_SuspiciousCommands
Author:Florian Roth (Nextron Systems)
Description:Detects LNK file with suspicious content

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments