🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 06b26a3a39109341bad9c455b284ec9eec39b9f7e897a47de83ddffd47a13a80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 06b26a3a39109341bad9c455b284ec9eec39b9f7e897a47de83ddffd47a13a80
SHA3-384 hash: 56d51db0f8459d75d45f2a931c0fd391a941d9d3d8b5b5c6a597e317fcb9bc789ef4c1b3996db1125a0786ba2e07ab61
SHA1 hash: 6aa644ba8a591b2af9dd825a59146d3c971a9b76
MD5 hash: d4a27017c0e2eb48d59a3cc1a679eb79
humanhash: carbon-queen-eleven-papa
File name:9.23.iso
Download: download sample
File size:5'183'488 bytes
First seen:2026-09-23 16:48:59 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 49152:9iZX6NtfD7tQOvL2IJkLIB+hHRk+26N6DprGnmSBLb4CJ5bEpPev1:SKDtVvqakLby+2k6kLb4gVv
TLSH T11B36E061BE01E875C58965308F3AC5BAC7303F794B79C59772D53E2B36B36528032A2E
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter smica83
Tags:iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
HU HU
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:FYD.487893851.EXE
File size:600'392 bytes
SHA256 hash: a09c4cafbaa82d6a6ff98bd41523ed41fc7e4016ae67e9518c289d11fd76ac95
MD5 hash: 31b11ffa4658170f121176d09748d065
MIME type:application/x-dosexec
File name:msvbvm60.dll
File size:4'514'272 bytes
SHA256 hash: 019f522abd00f6060973b3db7d1cc3c644270da0ccc67078c5fcff45be49fa37
MD5 hash: 48cfda4c88dcd5852289a037afc7573f
MIME type:application/x-dosexec
File name:IO.png
File size:3'463 bytes
SHA256 hash: b444766e45b2e180b33d2dc486f0a355cedfc0857b5eb3efd1643589ffce4ac3
MD5 hash: 4c6de60785c03e21925427d8aff25b6f
MIME type:image/png
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expand expired-cert lolbin signed visual_basic
Verdict:
Malicious
File Type:
iso
First seen:
2026-09-23T14:45:00Z UTC
Last seen:
2026-09-23T15:03:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Executable ISO9660 Image PE (Portable Executable) PE File Layout Visual Basic Visual Basic 6
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-23 16:49:21 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:SEH__vba
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments