MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 4 File information Comments

SHA256 hash: ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80
SHA3-384 hash: 524c0baa59e6cd597e5c57e0be72eae46c74204d195754f7fae111afd9d77c4730916fadc3da79967f20e199669a7a7b
SHA1 hash: b8421d746f47c9c61e3aa98102b484b9b60f7bad
MD5 hash: 05d81eb0e76fe59df6c6fe6088e85eab
humanhash: wolfram-montana-six-illinois
File name:oxmaul.rar
Download: download sample
File size:16'911'100 bytes
First seen:2026-07-27 21:27:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 196608:N4qfRgeCageCggeCdgeCEgeCSgeCOgeC6geCcgeCHgeCm:/fVVT2HRJ5zwp
TLSH T1BF07336BA07869C026E1A1DF58E29F3153712C4BC8C7A48B4CEFF7DDB60B38515A9D48
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:CVE-2025-6218 CVE-2025-8088 rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-25T11:27:00Z UTC
Last seen:
2026-07-25T11:39:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win64.Exploit.CVE-2025-8088
Status:
Malicious
First seen:
2026-07-25 20:40:18 UTC
File Type:
Binary (Archive)
Extracted files:
69
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:SUSP_RAR_NTFS_ADS
Author:Proofpoint
Description:Detects RAR archive with NTFS alternate data stream
Reference:https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments