🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b1c1b85784b92f8d4e7a7f3e6edd8a3b90cd708c75c09f17e62241433c2f3f9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 9 File information Comments

SHA256 hash: 7b1c1b85784b92f8d4e7a7f3e6edd8a3b90cd708c75c09f17e62241433c2f3f9
SHA3-384 hash: 255aeff14d14f7c0eb848851cfabdcf6a0dafa3d5ebc58aaf6c1a4bd1eb1eda167aa2e3852ce302abeff181e227ec895
SHA1 hash: bc278d4f960053847d201f60592051565142a863
MD5 hash: 592b04c38ff195bae20623ccada92224
humanhash: nuts-blossom-arkansas-sweet
File name:Documents.zip
Download: download sample
File size:1'215'916 bytes
First seen:2026-09-29 19:49:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:Fvtj3jH7Ifkg/2IEqejW7bwO2Geng+rc97ZCTdkAeQvFKrueC51Rug:Fvtj7eH2hy7bvStm0T2pCbMg
TLSH T130452314C728906EC0B61AB2A0F1193DE4715EF9590FEB4DEFE7294A909B244377533A
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
HU HU
File Archive Information

This file archive contains 7 file(s), sorted by their relevance:

File name:Terms of Partnership.lnk
File size:2'578 bytes
SHA256 hash: 523d6d2479a05d5a3c854fe6a76af1156afc05c9a46e1e8f74bea5c8b8d87aa0
MD5 hash: 8cf57f185a27f84a284c7850493748de
MIME type:application/octet-stream
File name:5. Key findings.pdf
File size:113'471 bytes
SHA256 hash: aa6228ea4495bf3a6d0d73e150bf5f00083d2a8c864c1943451b0e4d9406e593
MD5 hash: 0ff1ba1a5c7c7a1d29d1a8c92eec2297
MIME type:application/pdf
File name:4. Analytics.pdf
File size:412'243 bytes
SHA256 hash: 88b38a47ae9fcba076dc0310e522ec60785d43772652bc4326099663a6260643
MD5 hash: 4f39686fd996161b89ce95b4a4675db7
MIME type:application/pdf
File name:2. Office Network and Local Statistics.pdf
File size:287'584 bytes
SHA256 hash: f701ec227139df27b43435b2c77c932dbaa2a1c9d2df389eb3021afd5545716e
MD5 hash: 1cb41db6a26ba0343ed11b988d11074a
MIME type:application/pdf
File name:6. Supplement Panel Architecture and Operating Logic.pdf
File size:422'066 bytes
SHA256 hash: 977971d5b7b591d7364e7f2e92a3c4352b59812d6f1e579d63d955b57c8a3c8c
MD5 hash: 9ac2828b17bae91a6835da6a29dedad2
MIME type:application/pdf
File name:1.Operations Overview and Dashboard.pdf
File size:118'861 bytes
SHA256 hash: d8fc08f2fe600eca8333307c277d2d698ff623a4abc83483d2566bcf1acdffbd
MD5 hash: 8997c9fc84de97e4f9bb55b024e9e988
MIME type:application/pdf
File name:3. Office statistics.pdf
File size:119'576 bytes
SHA256 hash: b1b31f256902fc5d46d7aee0a33fd31b769a31da36ce277dbe1ce002b76ffe31
MD5 hash: f883a788a45f8a0fee24ffb91f989928
MIME type:application/pdf
Vendor Threat Intelligence
Verdict:
Malware
YARA:
3 match(es)
Tags:
Batch Command DeObfuscated Execution: CMD in LNK Execution: PowerShell in LNK LNK LOLBin LOLBin:powershell.exe Malicious PowerShell PowerShell Call T1027 T1059.001 T1059.003 T1202: Indirect Command Execution T1204.002 T1218: System Binary Proxy Execution Zip Archive
Threat name:
Win32.Trojan.Suschil
Status:
Malicious
First seen:
2026-09-27 10:55:17 UTC
File Type:
Binary (Archive)
Extracted files:
113
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:PS_in_LNK
Author:@bartblaze
Description:Identifies PowerShell artefacts in shortcut (LNK) files.
Rule name:SUSP_LNK_PowerShell
Author:SECUINFRA Falcon Team
Description:Detects the reference to powershell inside an lnk file, which is suspicious
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments