MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d48a386f6f6a4e61542c7882b020d7a8ba71dbb79f0fdf00e8de2e68ad248b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 8 File information Comments

SHA256 hash: 4d48a386f6f6a4e61542c7882b020d7a8ba71dbb79f0fdf00e8de2e68ad248b9
SHA3-384 hash: f9f7ee48b99b2ac9778167a7a57a6cd0b5e837fb7e5f40c43f071fdf9e093095b339eeeb4bda23f54b8d64265659516f
SHA1 hash: 36cb65a5b8f4889110ef4018b62fbf23c1d7874f
MD5 hash: dc11cdf629b06ce714425ea6ca1c45ff
humanhash: illinois-fish-autumn-cup
File name:spisokszch.xlsx.zip
Download: download sample
File size:2'784'491 bytes
First seen:2026-06-06 15:33:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:TZlH6Nef11VUlH677edZ+KzeFHpfh8e3ynCp:tlH6eUlH6rK2fhUA
TLSH T138D5E0802BF41304F176FE768E7AA789493BFE85EE31876C4950DC5C2964A00CE75F6A
Magika zip
Reporter smica83
Tags:UKR zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
HU HU
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:JPG_013.jpg.lnk
File size:929'423 bytes
SHA256 hash: afc2b7166498fe4307a0fcc9da9146c890231fb84efa5defc7a3c46d5fe73c62
MD5 hash: fd1650764b0a943ffffa320ab3cfa706
MIME type:application/octet-stream
File name:JPG_014.jpg.lnk
File size:774'749 bytes
SHA256 hash: 460b61508efe0aca02413f9cd0ae4aacf0ba1e65e19f97db4adc88d34f297772
MD5 hash: 82084ba72bf91b9c5916d3c82c73510b
MIME type:application/octet-stream
File name:spisokszch.xlsx.lnk
File size:19'603 bytes
SHA256 hash: d99d90b6761aa8cd3c416bc8badc33131c2f38535edecc31e4d2560c34d379a1
MD5 hash: d42db01290c0f5a2777420cdf9e325d4
MIME type:application/octet-stream
File name:JPG_012.jpg.lnk
File size:1'060'262 bytes
SHA256 hash: bfc17605500dbd772720be9560c4c56dcb1e80c53ec059ada89b4d4c1a245c0d
MD5 hash: 357dc6f3cc2f2b6c741721ccd56afd9f
MIME type:application/octet-stream
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
obfuscate shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd cscript evasive lolbin masquerade powershell
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-05T14:59:00Z UTC
Last seen:
2026-06-05T15:04:00Z UTC
Hits:
~10
Gathering data
Threat name:
Shortcut.Trojan.Suschil
Status:
Malicious
First seen:
2026-06-04 17:30:38 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:Large_filesize_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file larger than 100KB. Most goodware LNK files are smaller than 100KB.
Rule name:PS_in_LNK
Author:@bartblaze
Description:Identifies PowerShell artefacts in shortcut (LNK) files.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_Big_Link_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspiciously big LNK file - maybe with embedded content
Reference:Internal Research
Rule name:SUSP_LNK_Big_Link_File_RID2EDD
Author:Florian Roth
Description:Detects a suspiciously big LNK file - maybe with embedded content
Reference:Internal Research
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments