MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8d04c3d4a97c48d33d9e14009bb3765f22242d51d9a6c9cabdaaa0bb7b22270. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AshenLoader


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: a8d04c3d4a97c48d33d9e14009bb3765f22242d51d9a6c9cabdaaa0bb7b22270
SHA3-384 hash: 45e50b7feee9f92d8028af5525aa52c56ae698d7faccfa2452bf09a58e9deeea1db6374841a2e119d8fee1d5fdcbfc6e
SHA1 hash: 9cc4a2bc84540b8218167b250c2422ec07b22624
MD5 hash: cb0c82265258d1996b059f941b9d529a
humanhash: nitrogen-papa-december-may
File name:CGP_Заполненный_опросный_лист_по_внедрению_CommuniGate_Pro_Деловые_Линии_2026.zip
Download: download sample
Signature AshenLoader
File size:29'777 bytes
First seen:2026-07-28 21:09:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:/CTUty+CFmYiyzFy0ZR3XQ6UyO9iqGMXHgNDWYPCHJ0jL:wUs7tiMy0LQ6U/kjMXUgJoL
TLSH T18FD2E16D6C035C0C89517436F69C6D8694A1FCD829791358FEE8B0835EE70BDB18277E
Magika zip
Reporter smica83
Tags:AshenLoader zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
178
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:CGP_Заполненный_опросный_лист_по_внедрению_CommuniGate_Pro_Деловые_Линии_2026.pdf.lnk
File size:1'066 bytes
SHA256 hash: 57e37123a8c30641640bada2e0712351a457ee6c8d279926819da178d99fabaf
MD5 hash: 0744512363ba3a2464b451a85e3a422c
MIME type:application/octet-stream
Signature AshenLoader
File name:CGP_Опросный лист_новый_2025.xlsx
File size:32'097 bytes
SHA256 hash: 2816f82c2f9ecbe8cf3a85978a88924abeadb1ab5d88c2cbb115ffcb92052ffa
MD5 hash: d1e00cb32c11ef53a563d861487b28bd
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Signature AshenLoader
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
zip
First seen:
2026-07-28T18:13:00Z UTC
Last seen:
2026-07-29T19:35:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
LNK SVG Zip Archive
Threat name:
Shortcut.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-27 13:43:27 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:PDF_in_LNK
Author:@bartblaze
Description:Identifies Adobe Acrobat artefacts in shortcut (LNK) files. A PDF document is typically used as decoy in a malicious LNK.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

AshenLoader

zip a8d04c3d4a97c48d33d9e14009bb3765f22242d51d9a6c9cabdaaa0bb7b22270

(this sample)

Comments