🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 07f2d8f3a9c9430d91620d6a8b83c20dc9d020f00b7066b3ff9bd0fec20b7c2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 3 File information Comments

SHA256 hash: 07f2d8f3a9c9430d91620d6a8b83c20dc9d020f00b7066b3ff9bd0fec20b7c2d
SHA3-384 hash: f8df7cacc80ce86cb0df76d4b00675118f56852a58f94fe537353ab1b10350eba0e428c05acf1a15aa6731f6f3103d18
SHA1 hash: d6bc109e57ea20cb66361883d7292906c0a0ef14
MD5 hash: ed029c8a13695830139de2b222827940
humanhash: virginia-georgia-island-spring
File name:fiyat teklifi.rar
Download: download sample
File size:31'424'554 bytes
First seen:2026-04-04 19:39:20 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:qWEsrg2srgasrgpsrgwsrgMsrgcsrg1srgssrg2srgQsrgXsrg4srgLsrg8srgyQ:qiiqvIM4/w20pklIqE79bC/Il6dNom3p
TLSH T1E9675B3B4FCDF2DAE8C155315AD8368A9BC5E48D7F99CC56E152E17B234A3A0487A0F0
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:CVE-2025-8088 rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
HU HU
File Archive Information

This file archive contains 3 file(s), sorted by their relevance:

File name:_wr_storage_pad_5288.bin
File size:31'326'765 bytes
SHA256 hash: c35beecc30dde0aa7081049b144c5b68afdf4715d38ee1db706b83e042fa26a0
MD5 hash: d1c3d8bf964437a7527d5b6720e234b3
MIME type:application/octet-stream
File name:fiyat teklifi.pdf:.._ AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Startup_Updater.exe
File size:6'656 bytes
SHA256 hash: f130fafb1d81adb66184751b96b8673fbbff7118990753f97c3a1ef33ee0fd84
MD5 hash: e2ab90098a1745330ac38f491118a73e
MIME type:application/x-dosexec
File name:fiyat teklifi.pdf
File size:3'682 bytes
SHA256 hash: dc4268f52b742829a105c0d89498c24b2dfffd6c8a8ca99bb447b47b9661718a
MD5 hash: 183542d56d6bfd3604a78ad3ed7ac4e9
MIME type:application/pdf
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
rar
First seen:
2026-04-04T08:45:00Z UTC
Last seen:
2026-04-04T18:39:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.PhishLeonem
Status:
Malicious
First seen:
2026-04-04 13:36:34 UTC
File Type:
Binary (Archive)
Extracted files:
63
AV detection:
11 of 37 (29.73%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments