🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f101a45d8085c6fc1fa111aa9219abe2adcc16705f3ebeb91626fbd085ba9d13. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ConnectWise


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f101a45d8085c6fc1fa111aa9219abe2adcc16705f3ebeb91626fbd085ba9d13
SHA3-384 hash: 3694721d9f93e76339910f1e8d9297adc5a6bd7b0814ff6e12606f849730c753f9f2a675d6a52a9e7890cd7f5ffded2c
SHA1 hash: 4b54fdc4845245edb8b64a8adf5156a43f3a1827
MD5 hash: 11724fce9f766a838d7dc18e4b2132d6
humanhash: early-sink-idaho-oxygen
File name:ryujinx.zip
Download: download sample
Signature ConnectWise
File size:81'508'113 bytes
First seen:2026-07-10 02:56:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:L92refS7gojGaqKR3Nporg118m0Fml3ldyUyIWgQcmx9HjfjO2EjP7ueL9YJYu+v:LsISuaxR3Nporgff1pdWgQrxViPr9K+v
TLSH T17C0833406C98FE7D3D0668B624EDA11F25263A0443B10777FBF9227E628B751DEA4B13
Magika zip
Reporter aachum
Tags:ConnectWise micro-vpn-expres-top zip


Avatar
iamaachum
https://ryujinx.co/ and https://ryujinx.dev/download.html => https://start-download.duckdns.org/ryujinx/2gle1u2i83oyapzk5k541o

ConnectWise ScreenConnect C2: micro.vpn-expres.top

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
ES ES
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:Ryujinx_Setup.exe
File size:517'976 bytes
SHA256 hash: 8f47d7121ef6532ad9ad9901e44e237f5c30448b752028c58a9d19521414e40d
MD5 hash: bf3f290275c21bdd3951955c9c3cf32c
MIME type:application/x-dosexec
Signature ConnectWise
File name:dsetup_orig.dll
File size:95'576 bytes
SHA256 hash: 2a61679eeedabf7d0d0ac14e5447486575622d6b7cfa56f136c1576ff96da21f
MD5 hash: eb701def7d0809e8da765a752ab42be5
MIME type:application/x-dosexec
Signature ConnectWise
File name:dsetup.dll
File size:83'886'080 bytes
SHA256 hash: c25a08d59a215dce54ce9aed5636d5958eb6b87daee3b40ae666f92951be37f6
MD5 hash: 1ef0113bc0e9e2d0efe9021c0b3421e8
MIME type:application/x-dosexec
Signature ConnectWise
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Score:
81.4%
Tags:
virus
Verdict:
Unknown
Threat level:
n/a  -.1.0/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive expired-cert fingerprint microsoft_visual_cc signed
Gathering data
Threat name:
Win32.Trojan.Suschil
Status:
Malicious
First seen:
2026-07-10 02:59:50 UTC
File Type:
Binary (Archive)
Extracted files:
8176
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery persistence privilege_escalation revoked_codesign
Behaviour
Checks SCSI registry key(s)
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Boot or Logon Autostart Execution: Authentication Package
Drops file in System32 directory
Checks for any installed AV software in registry
Checks installed software on the system
Enumerates connected drives
Checks computer location settings
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Sets service image path in registry
Signed with revoked ConnectWise certificate
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ConnectWise

zip f101a45d8085c6fc1fa111aa9219abe2adcc16705f3ebeb91626fbd085ba9d13

(this sample)

  
Delivery method
Distributed via web download

Comments