MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 67bc27edf75ac2cbda6aca3c276571190d77d6b1314ae86662c2fed2bfdfb9ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 67bc27edf75ac2cbda6aca3c276571190d77d6b1314ae86662c2fed2bfdfb9ad
SHA3-384 hash: aadeb6c559c053c10b0caa09f3171851abcb628319971a374874bafa4230f061d368fd8a1063220f054409271c0d7342
SHA1 hash: cddf0e15854478d38c9d11a18012e76fafc0d238
MD5 hash: 0169f36d9f26d3a29bbf4cd4abcece15
humanhash: quebec-juliet-uranus-wisconsin
File name:2_19_7_1105_17.02.2026.rar
Download: download sample
File size:79'628 bytes
First seen:2026-02-17 10:51:15 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:EvJKFDPqcNesp8N0VggggggggPzzzzzzzzzzzzzzzzzzzzzzzzzzzzz+EEEEy19B:iMTqgPlzzzzzzzzzzzzzzzzzzzzzzzzn
TLSH T100737D07A0FAFE922B56DD317A8744B69106F29A21433380D8B05C7DABF35CA55B4B73
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:CVE-2025-8088 rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Постанова_2_19_7_1105_17.02.2026.pdf:.._.._.._.._.._.._AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Startup_2_19_7_1105_17.02.2026.HTA
File size:59'279 bytes
SHA256 hash: 444c495e2afc6b2d2c77b6ea300f9e110ea62807b279610ce8109213570aaec8
MD5 hash: debf1ab5acd9b38365c8e20b14f8eed7
MIME type:text/html
File name:Постанова_2_19_7_1105_17.02.2026.pdf
File size:1'763 bytes
SHA256 hash: fdbe3a4529edf04d94320d99db8a133372720ee77f7ee17d30fc2b51159375ef
MD5 hash: 57bf20108977770f7879fdf2abed34c0
MIME type:text/plain
Vendor Threat Intelligence
Gathering data
Threat name:
Binary.Exploit.CVE-2025-8088
Status:
Malicious
First seen:
2026-02-17 10:52:20 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
actor:romcom actor:storm_0978 adware apt discovery exploit spyware vuln:cve_2025_8088
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:SUSP_RAR_NTFS_ADS
Author:Proofpoint
Description:Detects RAR archive with NTFS alternate data stream
Reference:https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

rar 67bc27edf75ac2cbda6aca3c276571190d77d6b1314ae86662c2fed2bfdfb9ad

(this sample)

Comments