🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d107df4b0c98c2880724acbcae920a23076fb90be1e2d4cfd4cb9801d5597b71. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 17 File information Comments

SHA256 hash: d107df4b0c98c2880724acbcae920a23076fb90be1e2d4cfd4cb9801d5597b71
SHA3-384 hash: 455b40fceb0026a941e075c9e0f6a5ec100bb690550067fd9480e7c0a4fed35bf4f2443159f7e869d64a88e3f6c270f4
SHA1 hash: adf28370f661317f8ec35928ea2fede4e77fcef0
MD5 hash: bf3be59eb517929d09e7d942b8aab9c5
humanhash: nineteen-chicken-seven-ack
File name:zrzfcrzxstg.zip
Download: download sample
File size:2'517'195 bytes
First seen:2026-09-22 06:55:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:bMfn6GgEWJR0l+Irh9zSxJH5onsfiL/Zhv8Ap5cU5L4xaej4fKndAdQ4H5:bYn6KC+z9zSJons6L/Zhv8a5c2waXKA5
TLSH T192C533F2C60B4BC84A094BB612E44B6D3ED2893F566672656E9F1F476C0F2315F0272B
Magika zip
Reporter smica83
Tags:Plugx zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
HU HU
File Archive Information

This file archive contains 11 file(s), sorted by their relevance:

File name:adsta.exe
File size:5'412'864 bytes
SHA256 hash: b0d7bba78ca3aa4dc5d105b09b8e27ed6974364148b6ea762e60ced484dc2964
MD5 hash: e7d074e27a478864451015321720d71e
MIME type:application/x-dosexec
File name:ssce5532.dll
File size:557'568 bytes
SHA256 hash: 236e1e85b3b5ee916b2b07e2e896460b8f7c3a5d9e408df59657ddda16359c1e
MD5 hash: ac1657aacc527384307aef12d486f6bb
MIME type:application/x-dosexec
File name:core.xml
File size:731 bytes
SHA256 hash: 70261eb4dcdc280220aa1fb4e3a62f1d594ff3f83085a50a0a3db0b903f13e73
MD5 hash: 03d95515d4a28ce0d7d5f0129308540d
MIME type:text/xml
File name:settings.xml
File size:633 bytes
SHA256 hash: a5b7ec9c3f9071e35b93a9e3d4e5473e37611de7b16ed73c42a115b35e1481af
MD5 hash: 009d09010f6d22111ea597597737888f
MIME type:text/xml
File name:[Content_Types].xml
File size:1'556 bytes
SHA256 hash: c5d12f22d8282996b08987c91a399896a372ad6bbaa8141bb26c27abb76dfe98
MD5 hash: 72d9892a2b7b2c7d6994cb8826484fdf
MIME type:text/xml
File name:document.xml
File size:1'412 bytes
SHA256 hash: 724d4c8c86ea46e805c7ccdfce320253622e34cf776c34b2f21fd176cdf95745
MD5 hash: b660d35b1353cbdce2fc74770d2414b6
MIME type:text/xml
File name:app.xml
File size:573 bytes
SHA256 hash: 0013d6979982bbb9573393963dbe0f0f5dd54b1e677884ed6554d76624a1f3cc
MD5 hash: 5410c830b1d973e7e707489992acb6c8
MIME type:text/xml
File name:theme1.xml
File size:2'257 bytes
SHA256 hash: cecdf4f21275f87c79187622b39191d29095638711bd3fe1b92624c6d5c8c070
MD5 hash: 9cf5befffc84920002424c37965d9427
MIME type:text/xml
File name:document.xml.rels
File size:663 bytes
SHA256 hash: 096af0fdf086896e8ec49c5eea3138066af1b8698932c4150b1bf324a6d1d6bb
MD5 hash: be93a66ed796b297e27735f98ae371a4
MIME type:text/xml
File name:fontTable.xml
File size:913 bytes
SHA256 hash: 40bcd34af598e607b16381c8f087d9b6920613101a84dc43eb36c42ca82e9049
MD5 hash: 3fc1d6703a79ebf1ea911c2d03f9f445
MIME type:text/xml
File name:styles.xml
File size:2'351 bytes
SHA256 hash: c9e2601c15884c5d7a643da01a803d11303cfd49514df4849a4653a574c191dc
MD5 hash: 9705590c4c18dad271e8e4fc60565517
MIME type:text/xml
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 borland_c crypto evasive expired-cert explorer fingerprint installer-heuristic keylogger lolbin obfuscated packed reconnaissance regedit rundll32 signed smb
Verdict:
Malware
YARA:
3 match(es)
Tags:
Corrupted Executable Office Document PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.Suschil
Status:
Malicious
First seen:
2026-09-21 22:59:45 UTC
File Type:
Binary (Archive)
Extracted files:
562
AV detection:
25 of 38 (65.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
adware defense_evasion discovery persistence spyware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Kills process with taskkill
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
Executes dropped EXE
Loads dropped DLL
Checks computer location settings
Adds Run key to start application
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ScanStringsInsocks5systemz
Author:Byambaa@pubcert.mn
Description:Scans presence of the found strings using the in-house brute force method
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments