MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fffa5be744fc2315cdec4636a6c098c31ca40794a902883362badf0ac3f0c5bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 6 File information Comments

SHA256 hash: fffa5be744fc2315cdec4636a6c098c31ca40794a902883362badf0ac3f0c5bd
SHA3-384 hash: 8559f5474b296eb46eeab006ebd78a95cfb778ffb7a724a570d09e0c955bd0ca4deac60511c8b67d26a0ac2ed535861d
SHA1 hash: 0931356d46971b3d0982a40d3c862ba6bee95f56
MD5 hash: f291c9311c17d8da82db7d3de027218c
humanhash: earth-juliet-eight-fish
File name:0Tramxrsonf_lmay.66772EFFN.iso
Download: download sample
File size:5'632'000 bytes
First seen:2026-08-06 08:27:55 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 49152:OynvPr137EcEDnXzlfZ4jn6OIB0juKTAnvhSxxrLJc9/pOvCZUQyFdm0jid3Goxx:3
TLSH T14C4623335B89592FCAB07375B01E6D227E6F4603424CF29669DCA07637FBBC5422E894
TrID 87.8% (.NULL) null bytes (2048000/1)
10.9% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.5% (.WAR) Warcraft game data archive (12007/4/6)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.2% (.CPT) Mac Compact Pro archive (5000/1/2)
Magika iso
Reporter abuse_ch
Tags:geo iso MEX

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
CH CH
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:2016
File size:192 bytes
SHA256 hash: 3d6142fcbc5d7fb111e217fad8fe36c71a7f2ce3513868065dd7e4ef5bb5e72c
MD5 hash: 75e95fb7a1cab895ee434ee738e11c43
MIME type:application/octet-stream
File name:ltvq2.xml
File size:42'064 bytes
SHA256 hash: 7d750be30b5d239e62585ce223016dbf2c24dccd6c31b1c4737e03936c755c2e
MD5 hash: 8790abac4c4b63b922ba21ad5004884a
MIME type:application/x-dosexec
File name:string.txt
File size:8'532 bytes
SHA256 hash: 54d7d588d1f47fb3f000b6f14d208e0071a2e9a454c2a5dd64e02dcd27cbd69b
MD5 hash: df117588591a8fbf909d7e80ddd5f5e0
MIME type:application/octet-stream
File name:tptam1.xml
File size:22'304 bytes
SHA256 hash: 4ffe6536a9e8ef8231c0b46c80e633af298b275f406439c6234a52c37b35a502
MD5 hash: 9b3fe1d9f53a30a98c79b155d4260834
MIME type:application/x-dosexec
File name:2000
File size:516 bytes
SHA256 hash: 1d457872b3352b4aebe909730297b9a5f093358b1c9b73ad7c7273c6541f6810
MD5 hash: 7b3cc3a282327d555b88a7e47199fa24
MIME type:application/octet-stream
File name:2014
File size:192 bytes
SHA256 hash: 95177ea6b793dcc5fef2c6ae5d30a7e7961098e2e600f7addd7f91232c73c0e5
MD5 hash: 8b835189b8ff7c1bcadb9457aafad63a
MIME type:application/octet-stream
File name:_Pedid805120IZ68GG_FESMZZRHXY-Vrfcejyu.vbs
File size:5'119'905 bytes
SHA256 hash: 3a2584e9d358beacb1c65df6697c26e08d3bbd40febb1f4d94e3bc615b55a126
MD5 hash: 7e792f5a07c2bb48baa09584b24e07cc
MIME type:text/plain
File name:gssstv1.pdf
File size:26'232 bytes
SHA256 hash: 9ac4720f28e78e2b1b6018f3197bbed351b09b2184ebed72cf5d9265d5fa88d8
MD5 hash: 54c3542ca29bd3d219dee1479a199799
MIME type:application/pdf
File name:1000.bmp
File size:18'054 bytes
SHA256 hash: 65bf023f4050ebb3fdfed9555ab5d2a11003f57cff9eec2996c37d7e2297fbfe
MD5 hash: c409abcfc20665de9495b9baa0747870
MIME type:image/bmp
File name:bhouhv2.pdf
File size:28'637 bytes
SHA256 hash: 28db7f9abee695a72199093ba7474693111323f5c1e4bfb2f2fef0c408111338
MD5 hash: 0a95a73b6a33e76788b6376eb6a00518
MIME type:application/pdf
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Verdict:
Malware
YARA:
3 match(es)
Tags:
.Net DeObfuscated Executable ISO9660 Image Managed .NET Obfuscated PDB Path PE (Portable Executable) PE File Layout SOS: 0.15 T1027 T1059.005 VBScript
Gathering data
Result
Malware family:
n/a
Score:
  9/10
Tags:
adware defense_evasion discovery execution link pdf persistence qr ransomware spyware
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Executes a VBScript file via the Windows Script Host.
Checks computer location settings
Executes dropped EXE
Looks for VMWare Tools registry key
Enumerates VirtualBox registry keys
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Looks for VirtualBox Guest Additions in registry
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:NET
Author:malware-lu
Rule name:NETDLLMicrosoft
Author:malware-lu
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

iso fffa5be744fc2315cdec4636a6c098c31ca40794a902883362badf0ac3f0c5bd

(this sample)

  
Delivery method
Distributed via web download

Comments