MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 28f58061348a1c54fa6e7ff6618630259618d4afdf78514d5fccfc993797cdff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 4 File information Comments 1

SHA256 hash: 28f58061348a1c54fa6e7ff6618630259618d4afdf78514d5fccfc993797cdff
SHA3-384 hash: f89e495b0da9c361b9bb81f8579561f1d60fd6636e5a74a2cf74195018e8c0f10a05180feeae0a1524b6f65040873174
SHA1 hash: 82f0e23207f747295527279c58d4f203cd210b9b
MD5 hash: e0a7b7c9ab907476236149f5d0258183
humanhash: skylark-violet-foxtrot-indigo
File name:Besomar_documentation.rar
Download: download sample
File size:64'965'906 bytes
First seen:2026-06-21 19:25:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1572864:SGF2Gd33Fi7CA7ZUJ1R09O2SY/ceQ4PPUwlq:S8LnF9jm9JSCx91M
TLSH T17BE733429ED965C2ED2AFFE12D3D94D3D89D1DDDA0D20077A082F7BEBD382806096746
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:CVE-2025-8088 rar UAC-0226 UKR

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
HU HU
File Archive Information

This file archive contains 8 file(s), sorted by their relevance:

File name:Переваги співпраці.pdf
File size:9'287'387 bytes
SHA256 hash: 3ec6c91d68b416381ac9f6310a9e011f4060369c63416021864a6d5b91e97dc4
MD5 hash: 750cd146d3ce175c8c7918409adeae8d
MIME type:application/pdf
File name:БпЛА Besomar 3210.pdf:.._.._.._.._.._.._AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Startup_MicrosoftUpdate-1.302.1609.vbs
File size:719 bytes
SHA256 hash: cff6007dbb9826d0a08865f47a71b31e90c5067c637ac863e360315da984f107
MD5 hash: 0eddae234f63bca470de0793683b2281
MIME type:text/plain
File name:Зарядна станція.pdf
File size:9'287'387 bytes
SHA256 hash: c5c458a7b1bdfa3cbffdbcd0791912ff19267ad2808a5266a9975b22a53e73e0
MD5 hash: 7e3e9d5d054e7617cd06a7d967d97791
MIME type:application/pdf
File name:Про компанію.pdf
File size:9'287'390 bytes
SHA256 hash: a8dfa5a35f30c1789ce08b7e16660423bb1545fc8ec7411d24cfd41d1439bb45
MD5 hash: aee74f8a7c1ca720c40c51c6709ddaeb
MIME type:application/pdf
File name:БпЛА Besomar 3210.pdf
File size:9'287'387 bytes
SHA256 hash: a938b7291dbdcdcadb67d560b94bfee366e7f97f06d6f666b25e298c442d8542
MD5 hash: 9c97fa5bf1ce21ed0ace9f73efe09d70
MIME type:application/pdf
File name:Комплектація БпЛА Besomar.pdf
File size:9'287'387 bytes
SHA256 hash: 59842745dafd1537c3e2187f82fae7791e646a74251fe20d6c8ebaadf5720880
MD5 hash: 7c55575a5c85f673c222841f1d1e9b9d
MIME type:application/pdf
File name:Модифікація Besomar 3210-N.pdf
File size:9'287'387 bytes
SHA256 hash: 54218a8f2d1acc5d1beb576b970bb5333a4b78b05493754d2d1457ebf22a0ac1
MD5 hash: 7f9cee3ba18cfc60b369f1421dc7bc95
MIME type:application/pdf
File name:Катапульта.pdf
File size:9'287'387 bytes
SHA256 hash: e4d377b339f96c69c3001b854b22decae41883bd31f2f5a8c20f57d931ae0b44
MD5 hash: a8e8987d7a36b780d98d7a3d870e8f02
MIME type:application/pdf
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
rar
First seen:
2026-06-21T17:36:00Z UTC
Last seen:
2026-06-22T23:48:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-Macro.Trojan.Gamaredon
Status:
Malicious
First seen:
2026-06-20 13:06:07 UTC
File Type:
Binary (Archive)
Extracted files:
160
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:telebot_framework
Author:vietdx.mb
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-06-22 22:28:20 UTC

Attribution Wrong. This is not UAC-0226