MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bed38d45c308641347f291fa32fa2242ad2fc2525552c54f5abc02551216f9c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 10


Intelligence 10 IOCs YARA 3 File information Comments

SHA256 hash: bed38d45c308641347f291fa32fa2242ad2fc2525552c54f5abc02551216f9c4
SHA3-384 hash: 6309049301960588b843172cb274dc3ee61c0e20caead202388482b1944cda40139fab0da4f8b4113849c7e63a601f2e
SHA1 hash: 3a7c4ed691aff8b85443f99e8aa1c302e645db1e
MD5 hash: 9ed28f5d1bdb399e669d10e1c88f477e
humanhash: bluebird-lamp-november-mexico
File name:Documento.iso
Download: download sample
File size:167'936 bytes
First seen:2026-02-24 07:04:16 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 1536:1hzPCyX2zEsDI1JLZ8j0dU4VjTQTUdvRwbkGrY7WM92yjqtFlwHXoY:HzPC1zEF40dUGQTUdvR8LY7WwqtbN
TLSH T18EF31903E2E410FCE1D8C238539B6A36DD36BEC96534659E3B1C3A121BB3E50B61E765
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter JAMESWT_WT
Tags:iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
IT IT
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:Documento.pdf.lnk
File size:3'021 bytes
SHA256 hash: f919effa4f9af3e3795e4d792d1cf08f7cac42ba083c3c4687b09c8966e530e8
MD5 hash: 109dd7c14603ec3e24dfe3ddabdafd63
MIME type:application/octet-stream
File name:img.jpg
File size:75'264 bytes
SHA256 hash: 0979648739595d4a7f9caae2f9afbb28359b4521b2229201af01a807d757523f
MD5 hash: 2e3c965994e8139a4419a7aa7445924f
MIME type:application/x-dosexec
File name:documento.pdf
File size:26'051 bytes
SHA256 hash: 91fc23972d6b9037c3a2110ac0fad2b3b61afa1bf19887e7785a1257b1f38f19
MD5 hash: 79be321c28e323ff3b1fb401cf5aa1f1
MIME type:application/pdf
Vendor Threat Intelligence
Malware configuration found for:
Archives LNK
Details
Archives
extracted archive contents
LNK
a command line and any observed urls
Verdict:
Malicious
Score:
96.5%
Tags:
dropper
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 context-iso evasive fareit mingw packed stealer
Verdict:
Malicious
File Type:
iso
Detections:
HEUR:Trojan.WinLNK.Starter.gen HEUR:Trojan.WinLNK.Agent.gen
Gathering data
Threat name:
Win32.Trojan.Suschil
Status:
Malicious
First seen:
2026-02-19 13:33:29 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware discovery pdf spyware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Checks computer location settings
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:iso_lnk
Author:tdawg
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

iso bed38d45c308641347f291fa32fa2242ad2fc2525552c54f5abc02551216f9c4

(this sample)

  
Delivery method
Distributed via web download

Comments