MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fc548d4267d30acd658a3a43e30b4924dade9371cf6448cb1ae9e374f7dd69a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AshenLoader


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4fc548d4267d30acd658a3a43e30b4924dade9371cf6448cb1ae9e374f7dd69a
SHA3-384 hash: 1f29bb381dad26e714d6e22f6290220211e9c3119d09818861e5be59d22f7366a44f5b891853e15eca61cfada47a81a3
SHA1 hash: d9f554eb2d81ab6293235c42e19d4113f91b7725
MD5 hash: 561b4d321e756c05752571b54bce8a65
humanhash: speaker-october-burger-six
File name:communigatepro.tar
Download: download sample
Signature AshenLoader
File size:291'328 bytes
First seen:2026-07-28 21:12:11 UTC
Last seen:Never
File type: tar
MIME type:application/x-tar
ssdeep 6144:oNJX3NAbLf8KTloA8rEQ4FLyj2Un161ajwC+57v5:oN28KlFLM16
TLSH T1E2542B71B0C4589DE8C9C97C44E9760A0B3D7D1F8AE928AB371CEE25A7043C1BF15A67
TrID 98.1% (.ASSETS) Unity binary serialized Assets (generic) (2509/3/1)
0.7% (.DBF) Sybase iAnywhere database files (19/3)
0.6% (.TAR/USTAR) TAR - Tape ARchive (POSIX) (17/3)
0.3% (.TAR) TAR - Tape ARchive (file) (10/3)
Magika tar
Reporter smica83
Tags:AshenLoader tar

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
HU HU
File Archive Information

This file archive contains 5 file(s), sorted by their relevance:

File name:calibre.exe
File size:65'472 bytes
SHA256 hash: 64bdde10cfff243a25b021296773816057db1620df56ebd4db9178dcb88d2eaa
MD5 hash: 853d888553d002a04484c098a3d7045f
MIME type:application/x-dosexec
Signature AshenLoader
File name:88.lnk
File size:1'005 bytes
SHA256 hash: 9f30f57c0fb56f08adc8fb72ceee5053becaad9d54cfdb09be08bb37b60f2a2b
MD5 hash: c2a6feac7dac61a2afc794d373636a04
MIME type:application/octet-stream
Signature AshenLoader
File name:CGP_Заполненный_опросный_лист_по_внедрению_CommuniGate
File size:165 bytes
SHA256 hash: 19157390b2c4e571fc8fe72d6e524fcbaed420c323b209c01e325c120276d506
MD5 hash: 36c49f32b749426787e28695eb0ba6ac
MIME type:text/plain
Signature AshenLoader
File name:CGP_Заполненный_опросный_лист_по_внедрению_CommuniGate_Pro_Дел
File size:101'532 bytes
SHA256 hash: 1267af291173042a790da71024c76ae917235b273598ba8716a6a2e9e371581c
MD5 hash: 111961c168d77f5eae2de5c86d96ae04
MIME type:application/pdf
Signature AshenLoader
File name:calibre-launcher.dll
File size:116'224 bytes
SHA256 hash: ac8428684424dbae254570f757ac2b79eb5bf78e6dfbb0d4247fd814bb1e95cb
MD5 hash: ff25b675d13f530762e15f265e846f01
MIME type:application/x-dosexec
Signature AshenLoader
Vendor Threat Intelligence
No detections
Verdict:
Malware
YARA:
3 match(es)
Tags:
Executable Execution: CMD in LNK LNK LOLBin LOLBin:cmd.exe Malicious PDB Path PDF /OpenAction PDF Contains AutoAction PE (Portable Executable) PE File Layout T1059.003 T1202: Indirect Command Execution T1204.002 Tar Archive
Threat name:
Shortcut.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-27 13:47:43 UTC
File Type:
Binary (Archive)
Extracted files:
28
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

AshenLoader

tar 4fc548d4267d30acd658a3a43e30b4924dade9371cf6448cb1ae9e374f7dd69a

(this sample)

Comments