MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2add9429d2822ae0c01c08bbd66c3a110ef2e9c3a00cded1477657e9024e391e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gamaredon


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 2add9429d2822ae0c01c08bbd66c3a110ef2e9c3a00cded1477657e9024e391e
SHA3-384 hash: 929c8953b302d58e46d3a5000e8fbbefbdfafb955074e9175175983b1381806f11834556f2db60890297d4b5309985ee
SHA1 hash: d8d789af0ede2ce38a50b516f7603376589ae141
MD5 hash: 473c65b922d3308a98c6b76c7d99a196
humanhash: spaghetti-zebra-lake-two
File name:Повідомлення 4908-451.rar
Download: download sample
Signature Gamaredon
File size:828'496 bytes
First seen:2026-06-05 15:53:05 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:YQ94THFClJLWjLK24pc9BBb5SpRuWH7UCjQN/O:RiHMlNgGu/WRTjQN/O
TLSH T1CD0523377734D211E1EF821D35F04F70D95949BA48AC61A8340A2D65AFA3FEB2055F8A
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:apt CVE-2025-8088 gamaredon rar UKR

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
HU HU
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:Повідомлення 4908-45.pdf
File size:144'316 bytes
SHA256 hash: ad6071a44089df433f23a7dcd17fc4c49b67521d40f600bad875e2b1e312c8e0
MD5 hash: 1abfa9ff34ad13ea7bb8b365cf4a75b8
MIME type:application/pdf
Signature Gamaredon
File name:Повідомлення 4908-45.pdf:.._.._.._.._.._.._.._.._.._.._.._.._ProgramData_CiJL
File size:1'144'320 bytes
SHA256 hash: aa8a0dc974e090ae6f0a9cf90096646514b9c178ec8119ec211df2cb106f681e
MD5 hash: 4bf74974daa989e12bc805063b545cfa
MIME type:application/octet-stream
Signature Gamaredon
File name:Повідомлення 4908-45.pdf:.._.._.._.._.._Roaming_Microsoft_Windows_Start Menu_Programs_Startup_U0asnHrRyNSI5H4.lnk
File size:1'213 bytes
SHA256 hash: 39dd1bd3bccc314d8933e5c41ed2ab084e4e20af569f77b7cf09abc5855b9483
MD5 hash: 13772e08c6a0aedcfdeb8fc0fe72a825
MIME type:application/octet-stream
Signature Gamaredon
File name:Повідомлення 4908-45.pdf:.._.._.._.._.._.._.._.._.._.._.._.._ProgramData_StQ
File size:92'616 bytes
SHA256 hash: fcbeef11f392809cf96cceb94055f33b1f0fde94a4e3ee9223a01fcf55e9f0e0
MD5 hash: 6bb1b81ee808fae51a259bbb8c0d0f23
MIME type:text/plain
Signature Gamaredon
Vendor Threat Intelligence
Malware configuration found for:
GiftedCrook LNK
Details
Verdict:
Malicious
File Type:
rar
First seen:
2026-06-05T05:52:00Z UTC
Last seen:
2026-06-05T06:08:00Z UTC
Hits:
~10
Gathering data
Threat name:
Shortcut.Exploit.CVE-2025-8088
Status:
Malicious
First seen:
2026-06-05 09:26:40 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
10 of 23 (43.48%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_RAR_NTFS_ADS
Author:Proofpoint
Description:Detects RAR archive with NTFS alternate data stream
Reference:https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments