MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 583754e5e682ea83d58fbf76ea5c82ea0f2ab5db06e9e52343c4d52f35f0a4a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 583754e5e682ea83d58fbf76ea5c82ea0f2ab5db06e9e52343c4d52f35f0a4a6
SHA3-384 hash: c77057ad9c1ea7fe54adec0ac46886b3027fbbb0cc293886ac9675aecbe743055322855156a403cfb8fba5ee1c5b269f
SHA1 hash: 0589d2079fbef814dc7bb95c4b3b555c8b933af6
MD5 hash: fe18af8be6a9d1208fa6edf813f80c32
humanhash: stairway-fourteen-illinois-robert
File name:Відомость про самовільне залишення військової частини 3018-4726.rar
Download: download sample
File size:838'864 bytes
First seen:2026-06-08 11:44:47 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:GFyCNSZGZ9ozAqDfLRp5BP8IDO+CkU/X14527Y:0wGZ9wRLLrP8IDO+7
TLSH T11D0533FB45AC33D5F21E0D3A7EAADC75EAE9604A9DC16A90471424779C00793FCD38A2
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:apt CVE-2025-6218 CVE-2025-8088 gamaredon rar UKR

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
GiftedCrook LNK
Details
Verdict:
Malicious
File Type:
rar
First seen:
2026-06-07T14:01:00Z UTC
Last seen:
2026-06-07T14:09:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Exploit.CVE-2025-8088
Status:
Malicious
First seen:
2026-06-07 18:16:45 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
adware discovery spyware
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_RAR_NTFS_ADS
Author:Proofpoint
Description:Detects RAR archive with NTFS alternate data stream
Reference:https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments