MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0540737f42ebd2e42dcc1fbc5d43d9b0c55b97fb3fa228e20aa51a392f55804c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 0540737f42ebd2e42dcc1fbc5d43d9b0c55b97fb3fa228e20aa51a392f55804c
SHA3-384 hash: 446c21be8b29b8c617eb2c56ab1f77951628659c71f46caa17c43fbd16418f38fbb35bcb5f73c122f615c5f833997fe9
SHA1 hash: 632ab46346ead28f71de7e51461fe3549eee5174
MD5 hash: e0bed9f3a37fb6e3cae427829ab350b3
humanhash: summer-double-orange-edward
File name:e0bed9f3a37fb6e3cae427829ab350b3.rar
Download: download sample
File size:1'784'319 bytes
First seen:2026-03-09 23:06:45 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 49152:Xk7EE19j/kZ7GBNSwZeT/Zq7I34njUVjuOsl:XAEE1GG/SdsUMOi
TLSH T1188533955185EFFBD72BA03A1DE16E7F70A8329640BDE3C46ADD05DE28274931A070BC
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Remark.pdf:.._.._.._.._.._.._.._.._.._.._.._.._.._.._.._.._ProgramData_Microsoft_Windows_Start Menu_Programs_Startup_Windows-Update.exe
File size:4'651'008 bytes
SHA256 hash: fcd834147536bc9be995cd52383239e787b1979521863b4f13f114d5b24c707c
MD5 hash: 0363f11acf525421ba3256eeb719ea10
MIME type:application/x-dosexec
File name:Remark.pdf
File size:5 bytes
SHA256 hash: c83255c62d043e7101bb31683ac08d0b7b9696ec87607cea26e79586cfcbe149
MD5 hash: f3c1e0090afab4fdb5735fa9b343bce4
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-03-09 23:07:19 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
adware discovery spyware
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_RAR_NTFS_ADS
Author:Proofpoint
Description:Detects RAR archive with NTFS alternate data stream
Reference:https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments