MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d9f49f65be67fcceaf354adf06f3d2b5851e96bbac6f2f334aaeec6851e23a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 6d9f49f65be67fcceaf354adf06f3d2b5851e96bbac6f2f334aaeec6851e23a2
SHA3-384 hash: ac96798d207e463b3f31118b9c30b8828437742f915677a7bfc4163b0dd433705c37313dd844d748c49315cc8b9074eb
SHA1 hash: ae89bdfa85d7934ae481f7434bb92661f8e7c718
MD5 hash: 18bd72d38377bbc8e119e16470abbdbf
humanhash: fifteen-jersey-winner-paris
File name:New_Contract_Document.rar
Download: download sample
File size:12'109 bytes
First seen:2026-06-06 18:41:53 UTC
Last seen:2026-06-08 14:51:35 UTC
File type: rar
MIME type:application/x-rar
ssdeep 192:iEedyRjiErb3AwHebyK3gxFbe0Ikz6wqrGsjp5pXOQyJqokrJ49PDhzWRrk46JIg:iE0yRjiErbwwot0Ikz6xysjsQzob9r0M
TLSH T17242BF6E2982CC014CA3ADF92D36EF03142E3631275C57F6489F81EA7D55B6F78C1A26
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:rar

Intelligence


File Origin
# of uploads :
16
# of downloads :
47
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Document.vbs
File size:27'868 bytes
SHA256 hash: 06fedd0f6fd4475f74abf8e829da0933f2a31613a0cda271339746a554da6ed0
MD5 hash: f2f8fd226aafe72dd53c516ba8d26b00
MIME type:text/plain
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
obfuscate xtreme virus
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
encrypted obfuscated
Verdict:
Malicious
File Type:
rar
First seen:
2026-06-03T18:10:00Z UTC
Last seen:
2026-06-07T08:12:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2026-06-03 01:22:47 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

rar 6d9f49f65be67fcceaf354adf06f3d2b5851e96bbac6f2f334aaeec6851e23a2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments