MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 4 File information Comments

SHA256 hash: ffa5c396a37ef0dbabf541cecc4e1bda84675eace39d2a8d2ccf355f08a9ca80
SHA3-384 hash: 524c0baa59e6cd597e5c57e0be72eae46c74204d195754f7fae111afd9d77c4730916fadc3da79967f20e199669a7a7b
SHA1 hash: b8421d746f47c9c61e3aa98102b484b9b60f7bad
MD5 hash: 05d81eb0e76fe59df6c6fe6088e85eab
humanhash: wolfram-montana-six-illinois
File name:oxmaul.rar
Download: download sample
File size:16'911'100 bytes
First seen:2026-07-27 21:27:22 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 196608:N4qfRgeCageCggeCdgeCEgeCSgeCOgeC6geCcgeCHgeCm:/fVVT2HRJ5zwp
TLSH T1BF07336BA07869C026E1A1DF58E29F3153712C4BC8C7A48B4CEFF7DDB60B38515A9D48
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter smica83
Tags:CVE-2025-6218 CVE-2025-8088 rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
HU HU
File Archive Information

This file archive contains 22 file(s), sorted by their relevance:

File name:mike_oxmaul_cv.pdf:.._.._.._.._.._.._AppData_Roaming_Microsoft_Windows_Start Menu_Programs_Startup_WinRAR.exe
File size:3'593'176 bytes
SHA256 hash: aa34665443216685d3e382f21834d05ba121bc977087b288ae91aaf12791d18a
MD5 hash: 9d50393360ba1941796f5b32d200e61b
MIME type:application/x-dosexec
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$30575.24668
File size:62'986 bytes
SHA256 hash: 6e974adbe4ea09a23610f35aab50a682fea76ad60efea0d5d89cac442f751bf9
MD5 hash: c3e54a8b95e9eccb669e4fb79dda3bea
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$24025.24223
File size:8'195 bytes
SHA256 hash: e1126435e1356a12d6b3cd63ad19bafff3836133d7f4905eb4933726dfec2607
MD5 hash: 07a1a3060552b242caf6b0e919fdc8be
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$81851.79342
File size:37'423 bytes
SHA256 hash: 9f12d722f62f09a69e8857f9026ca2f0458ef5ac976b4da963e5df001b1b529c
MD5 hash: 1da1d8a5bcd2fc619c01b9170def9f5f
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$42657.25869
File size:6'092 bytes
SHA256 hash: 8fbf26c71c2fd8c5b0a6d001e197fc187f99f8309cf7e15651579abe9b49eb8a
MD5 hash: d3d1d4511deeed59fab2363fc06aa71b
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$35434.22832
File size:49'019 bytes
SHA256 hash: e7f569ff5ea60bb7295be05265bebe749c1cb806a0f16801be4295fc946cf686
MD5 hash: 836adfd8a48bb69f2d58a52f02af7df0
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$21713.95689
File size:6'245 bytes
SHA256 hash: d8a9bf71601ac3100abaa6b80a894f071005cae983e57c1307c51a423e485bfa
MD5 hash: d7dc3e3c38460e59c4d478a4719ff5fb
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$72276.10114
File size:34'275 bytes
SHA256 hash: b6f0fa351e8dbeb144413453f70e753572d1e9c31ba7583f8b7b180424e1b0ec
MD5 hash: dd84085531480a312137ef3389734db9
MIME type:application/x-dosexec
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$64048.17271
File size:7'442 bytes
SHA256 hash: 548b24ccb5abae1b3ac593c2efb50c52b8aec8807c9c5c2647c4c8ce4664a595
MD5 hash: 08707758e01646d48714e880b4d9f3b2
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$98152.86969
File size:33'599 bytes
SHA256 hash: 5956c52b5e759076d4f0fa1adafb3c4e7de3efe698725aef7dce061b2e8986b4
MD5 hash: 18c81fabd1853c92d00eaec064e8a7b2
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$86751.99661
File size:42'183 bytes
SHA256 hash: e351de7ed19f451decb0b2c7bfa67c16ef9eea91cdb8c3957d9e64894d179fce
MD5 hash: 64ecf09da99c7459b103c7e965165442
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$79139.87603
File size:63'472 bytes
SHA256 hash: 2b4603fc7dacd3ac61409cc3e8234b252397bd5ea96b196b8cde9651e761b2ee
MD5 hash: 2130eb33e0002d139a69cf4e458e094e
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$68433.22049
File size:9'934 bytes
SHA256 hash: e139db2aed3e18d068a3f006f7394a2272626f6d5094509964d77b32bf7d4a20
MD5 hash: 09fd90da437c3047d4c6ba51446add0a
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$52596.48371
File size:7'867 bytes
SHA256 hash: 5cba38343121d7097db818d30fb6358aa5a910b85443d4a176a594a92fcbaf7a
MD5 hash: 2dedfcade8c1266ab7e8e1b8bf46fa76
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$61663.68388
File size:20'185 bytes
SHA256 hash: f43b092937c1a7c938e310e4e27b6f4f69503fc987f0d84c503164269e584a32
MD5 hash: b340efa545d0f6d0eabb95deaa92d398
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$94324.13290
File size:58'587 bytes
SHA256 hash: fef6ab677b7c64a88c4a7cb755aa9e4ef7cc8c15c88bc57db76114a91dfec5fb
MD5 hash: 04f1a437bdba928e74551d32a368782b
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$82648.71655
File size:62'316 bytes
SHA256 hash: eff87ff18287448668218ff5931e3ad13d4439a2a3664c6671e3f16797d21bd6
MD5 hash: 8a6d57aca2feebf8d4900ed8e8c27fb6
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$44970.58399
File size:45'810 bytes
SHA256 hash: 4ce15450bc27abf748b78b0eadcd664790137ab45b4c3735f81546c864bc261e
MD5 hash: d254e8085de6071201dfd321e6bf1ad5
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$70791.30283
File size:34'426 bytes
SHA256 hash: a7220974570dd8e14e606d5707065804b7f728a07ece6f8eda842c8b30e5ceb6
MD5 hash: 87c3e8948ab9117bd9ff38517fe8938c
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$46070.81118
File size:40'962 bytes
SHA256 hash: 03c59e0515112ae3236284aa166e12b757eb404df1005c9e1a5a06910e13ace8
MD5 hash: 36207a24ec79dcad68a78948a4910d79
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf:%WINDIR%_Temp_Rar$57871.30514
File size:59'186 bytes
SHA256 hash: 1be02a460b0cf759a7dd6503b9e181319a8f12b87858c34bb74a464fbb28cf55
MD5 hash: a19626cb19fd4ba8dd36669e359295d3
MIME type:application/octet-stream
File name:mike_oxmaul_cv.pdf
File size:38'870 bytes
SHA256 hash: d7a01944086740884ccf3f8d91a0958e74f39c8baf9e40cf6c6a29e6c7c41a91
MD5 hash: 1275351130bafd034efd071f95cd3bd4
MIME type:application/pdf
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-25T11:27:00Z UTC
Last seen:
2026-07-29T10:50:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win64.Exploit.CVE-2025-8088
Status:
Malicious
First seen:
2026-07-25 20:40:18 UTC
File Type:
Binary (Archive)
Extracted files:
69
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:SUSP_RAR_NTFS_ADS
Author:Proofpoint
Description:Detects RAR archive with NTFS alternate data stream
Reference:https://www.proofpoint.com/us/blog/threat-insight/hidden-plain-sight-ta397s-new-attack-chain-delivers-espionage-rats
Rule name:WinRAR_ADS_Traversal
Author:@bartblaze
Description:Identifies potential ADS traversal in RAR archives, seen in vulnerabilities such as CVE‑2025‑6218 and CVE-2025-8088.
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/
Rule name:WinRAR_CVE_2025_8088_Exploit
Author:marcin@ulikowski.pl
Description:Detects RAR archives exploiting CVE-2025-8088 in WinRAR
Reference:https://www.welivesecurity.com/en/eset-research/update-winrar-tools-now-romcom-and-others-exploiting-zero-day-vulnerability/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments