🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e1d84f7df558a05afe6c9484b246f374032f35fdf8de962c4690412eeeaeada. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments

SHA256 hash: 0e1d84f7df558a05afe6c9484b246f374032f35fdf8de962c4690412eeeaeada
SHA3-384 hash: dd008645ec9a6f142c5aa868278000b9dc6814faf5e3cc285ebc7120c539c7a1538251f034c381b80f82a600792ef21e
SHA1 hash: 4fa7fd2d0c671a2a3a2ae4754e53fd5d0ecf61a4
MD5 hash: 5882adef96ce238ca6f14ab279af6c06
humanhash: ink-zulu-april-mobile
File name:Peace Negotiations between Russia and Ukraine.html
Download: download sample
File size:2'619'517 bytes
First seen:2026-09-30 19:20:23 UTC
Last seen:Never
File type: html
MIME type:text/html
ssdeep 24576:OaOTV3OrZ+yiWXGPKLR2i1Pmkg4sj4gPzOH7Ez2MpyE6OuKDVF+9SusiUEwz0osI:92s+UkAgL7qAl5tuJoaCXByvPyCg
TLSH T121C513754D63BF5A614A53AA30013221BC9491BFD24692C4FBDCA99DDBC9C20BF85EF0
TrID 66.6% (.HTML) HyperText Markup Language (UTF-8) (6000/1/1)
33.3% (.TXT) Text - UTF-8 encoded (3000/1)
Magika html
Reporter smica83
Tags:Blueharvest html HUN UNC6139

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
obfuscated
Result
Threat name:
n/a
Detection:
malicious
Classification:
phis
Score:
56 / 100
Signature
AI detected malicious page (phishing or scam)
HTML file submission containing password form
Joe Sandbox ML detected suspicious webpage
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Html SVG
Threat name:
Document-HTML.Trojan.FakeLogin
Status:
Malicious
First seen:
2026-09-18 11:58:54 UTC
File Type:
Text (HTML)
Extracted files:
11
AV detection:
2 of 36 (5.56%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:LLM_API_OpenAI
Author:llm-api-abuse-pilot
Description:References OpenAI API endpoints or key material
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments