MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aedd975e59ffe867bec9be9a33d438b8d34c96e7f42453f7661e2127890aa0e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 6 File information Comments

SHA256 hash: aedd975e59ffe867bec9be9a33d438b8d34c96e7f42453f7661e2127890aa0e2
SHA3-384 hash: 6b935053740e7f8f84a72fda2e043abd6f40ea47e3a8ae71beebedacd99aae2424fd8da41cc388567155a4049d137901
SHA1 hash: d7ed1afdf19ffbf3e667d3fcc0ddeb6342a4d5ab
MD5 hash: 0dd1cf2d9a72fdbef19e77af59ba9d1f
humanhash: moon-don-nevada-salami
File name:2026_4th_K-ICTC_Information.zip
Download: download sample
File size:157'363 bytes
First seen:2026-04-06 18:49:47 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:EAkb7MJFDPnaOJlitktW+HQFVAtbwMcQaaaTIEza7/7m+qbzwCdEf:yi/zJlskVQFVAtbncvWEz1WCdEf
TLSH T1AFF31218462896FEE3F69379AA094B831C8701D9E4A1560C766F3DFD2938CE7130F5C0
Magika zip
Reporter smica83
Tags:DPRK zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:2026 4th K-ICTC Information.pdf.lnk
File size:20'398 bytes
SHA256 hash: 169586b6eb36b17520ef5afd206da86c4de89eb01d6294ba9631414271ba752f
MD5 hash: b3c90f52e4b86a94ec637fee4354bb84
MIME type:application/octet-stream
File name:Official Letter.pdf
File size:174'890 bytes
SHA256 hash: aa24ac3265e44e900d33b4d26bc927562aca74ee469a1720cfac3ccf6579f2df
MD5 hash: ed914a866d4601950c22cc2252b1187d
MIME type:application/pdf
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Score:
99.1%
Tags:
xtreme shell sage
Verdict:
Malicious
File Type:
zip
First seen:
2026-04-03T18:54:00Z UTC
Last seen:
2026-04-07T03:39:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-04-03 10:21:12 UTC
File Type:
Binary (Archive)
Extracted files:
35
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Archive_in_LNK
Author:@bartblaze
Description:Identifies archive (compressed) files in shortcut (LNK) files.
Rule name:Download_in_LNK
Author:@bartblaze
Description:Identifies download artefacts in shortcut (LNK) files.
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:PDF_in_LNK
Author:@bartblaze
Description:Identifies Adobe Acrobat artefacts in shortcut (LNK) files. A PDF document is typically used as decoy in a malicious LNK.
Rule name:Script_in_LNK
Author:@bartblaze
Description:Identifies scripting artefacts in shortcut (LNK) files.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments