MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bbcbc88d04615079fa17708c62f07ccb138c19bb9ed78ae43f9172cd91931ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 2bbcbc88d04615079fa17708c62f07ccb138c19bb9ed78ae43f9172cd91931ba
SHA3-384 hash: 9596453b766b872e40a5804e556629da2843f4d775641abfdeaf04ca72f3de63c4abebaa4bc8265e5a22333137977fd3
SHA1 hash: 419aaddb4740de5ae83b3bd1af1e7703ac147666
MD5 hash: e0d883fa1a601b2fd7b08ba300d7e6f8
humanhash: coffee-india-fruit-skylark
File name:АКТ проверки транспортного средства.rtf
Download: download sample
File size:672'755 bytes
First seen:2026-02-24 17:10:16 UTC
Last seen:2026-03-27 10:56:40 UTC
File type:Rich Text Format (RTF) rtf
MIME type:text/rtf
ssdeep 12288:Gj1UF1a/49mx9hqnuXdlw0ihTVo8LKpJejfzfJB1b+:Go0/iugv5XLKpkf7JvK
TLSH T1D0E47DA8665C2AB533472D569C67FBC62370DB37B761AE7CC0355381805A3E49BE2C0B
TrID 83.3% (.RTF) Rich Text Format (5000/1)
16.6% (.JSON) JSON object (generic) (1000/1)
Magika rtf
Reporter smica83
Tags:CVE-2026-21509 HoodyHyena rtf

Intelligence


File Origin
# of uploads :
3
# of downloads :
155
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
MSO
Details
MSO
extracted component(s) such as package(s) and OLE files
Malware family:
n/a
ID:
1
File name:
_2bbcbc88d04615079fa17708c62f07ccb138c19bb9ed78ae43f9172cd91931ba.rtf
Verdict:
Malicious activity
Analysis date:
2026-02-24 17:12:00 UTC
Tags:
generated-doc ole-embedded smb CVE-2026-21509 webdav

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/rtf
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malicious
File Type:
RTF File
Behaviour
BlacklistAPI detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
webdav
Verdict:
Malicious
File Type:
rtf
Detections:
HEUR:Exploit.RTF.CVE-2026-21509.gen
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl
Score:
52 / 100
Signature
Microsoft Office loads Shell.Explorer.1 (likely related to CVE-2026-21509)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Document-RTF.Exploit.CVE-2026-21509
Status:
Malicious
First seen:
2026-02-24 14:39:17 UTC
File Type:
Document
Extracted files:
19
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments