🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b74cab9d6eac63c8aa8bc5b022405ca71c24ad0386014c2e7d4a7d9fa82d0d71. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 19 File information Comments

SHA256 hash: b74cab9d6eac63c8aa8bc5b022405ca71c24ad0386014c2e7d4a7d9fa82d0d71
SHA3-384 hash: 64b617fcbc361a8cddd11a964b78434a33335efb594ccc1cc3eb92928abdfea1c63482a72b0ad3de38d386ff7fa643ef
SHA1 hash: 92df3acdfcc3982a19d719dd43949f1038f3f45a
MD5 hash: ada8b9ddedd43791a25669ee83dd49fc
humanhash: one-sodium-kitten-connecticut
File name:KLAS-CGE 2025 Application Forms.zip.iso
Download: download sample
File size:6'516'736 bytes
First seen:2026-09-29 20:02:30 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 24576:Ui0mAhJtAltnt8h6gs4vZ+H5yPYx6ykpH0vFuf+uspTkYoLAcMVIdyjoyQBdbfSu:Ui0xPtA/t8hps4EZI2PVyUeVBdH3
TLSH T1CD66C6E0D9A659C2E013D47C54A8B6E201323893FFD40DF3977E6708CF7DAA56A59A0C
TrID 88.0% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.5% (.WAR) Warcraft game data archive (12007/4/6)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter smica83
Tags:iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:TNLAS_CGE_Application Forms.pdf.lnk
File size:3'130 bytes
SHA256 hash: 167557f5a7769c028691cd7bd106a3ef5ae537fe04c4c68201ff39a0ef1f0ec8
MD5 hash: 7d1462c874ac3adea59fb235e24b4abb
MIME type:application/octet-stream
File name:TNLAS_CGE_Forms.zip.exe
File size:6'398'464 bytes
SHA256 hash: 6892797ff2b0d12ea8afd54f2c3e6d72ff92dcaeec3cd8588451d3d1cf5e85eb
MD5 hash: 9556c8252794060d1f80d615e0a7af78
MIME type:application/x-dosexec
Vendor Threat Intelligence
Malware configuration found for:
Archives LNK
Details
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm golang masquerade obfuscated packed
Verdict:
Malicious
File Type:
iso
First seen:
2026-09-30T08:16:00Z UTC
Last seen:
2026-09-30T08:26:00Z UTC
Hits:
~10
Verdict:
Go Loader (Factory-v3)
YARA:
1 match(es)
Tags:
Executable Execution: CMD in LNK Go Loader (Factory-v3) ISO9660 Image LNK LOLBin LOLBin:cmd.exe Malicious PE (Portable Executable) PE File Layout Stealer Loader T1027 T1055 T1059.003 T1202: Indirect Command Execution T1204.002 T1218: System Binary Proxy Execution
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-24 11:27:57 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Archive_in_LNK
Author:@bartblaze
Description:Identifies archive (compressed) files in shortcut (LNK) files.
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__ConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:iso_lnk
Author:tdawg
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:SUSP_LNK_CMD
Author:SECUINFRA Falcon Team
Description:Detects the reference to cmd.exe inside an lnk file, which is suspicious
Rule name:SUSP_LNK_PowerShell
Author:SECUINFRA Falcon Team
Description:Detects the reference to powershell inside an lnk file, which is suspicious
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments