MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08666ddfc8c8b1a9901914a2c3b8388da30ff532e598c88169fc42ee2fe3c8d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 08666ddfc8c8b1a9901914a2c3b8388da30ff532e598c88169fc42ee2fe3c8d4
SHA3-384 hash: 414bcbb2e63982aaf377b3d770abee50c6053c3bcce9032005446e4373cd74b6338726478289f44b0ce8e55d1ce33690
SHA1 hash: 1861526acc42bde948c5f01649ba6b7c4bf3f07a
MD5 hash: c280b597dd2ada5c78d39bb6a2809632
humanhash: shade-washington-hotel-utah
File name:Uso_Exclusivo_Interno_99.img
Download: download sample
File size:6'121'472 bytes
First seen:2026-07-30 12:27:07 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 98304:91HuUcIzAjbncF+4f+0UuIjOH7tUejyb+c3hKYd9:tczbc04GkISH5Bjs+cwY
TLSH T1F2560117F6A240DDC5AFC534C39A9773AA30B46D13247E1E6E68DB322F50D50AB2EB14
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter proxylife
Tags:img

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
DE DE
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:libvlc.dll
File size:4'815'707 bytes
SHA256 hash: bf945125454667e45f5817b898b20d82ba7952f8e9f053dbb7c546586cc0ed42
MD5 hash: e2b99d224f6fe1c7895883632d456ab4
MIME type:application/x-dosexec
File name:Uso_Exclusivo_Interno.pdf.lnk
File size:1'861 bytes
SHA256 hash: ea15a28347c3e88e77cf45c72d4837355799d324736677a224242e51f954760c
MD5 hash: 7ccf316b77f27ef40e26874f6141b35b
MIME type:application/octet-stream
File name:libvlc_original.dll
File size:192'408 bytes
SHA256 hash: 8ae9f16a72441f43fb4ae8f72c843736726e067ea4a8def2646748631cc4e872
MD5 hash: cbfbca59dd83388486cb52fffce2ccb0
MIME type:application/x-dosexec
File name:vlc.exe
File size:1'046'424 bytes
SHA256 hash: bfa5740f028a8f310ca01c779bbc5f2f1b435c41539c54de592f715bb0c10389
MD5 hash: f0a4d5c3492115bfe2f346bc7bdce396
MIME type:application/x-dosexec
Vendor Threat Intelligence
Malware configuration found for:
Archives LNK
Details
Verdict:
Unknown
Threat level:
n/a  -.1.0/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm crypto mingw overlay packed reconnaissance signed
Verdict:
Malicious
File Type:
unknown
First seen:
2026-07-30T11:04:00Z UTC
Last seen:
2026-08-01T09:35:00Z UTC
Hits:
~10
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-30 12:28:34 UTC
File Type:
Binary (Archive)
Extracted files:
17
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:iso_lnk
Author:tdawg
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments