The file is a malicious archive used in cyberattacks, specifically linked to Gamaredon Group (also known as Primitive Bear or APT28-adjacent), a state-sponsored threat actor focused on espionage against Ukrainian targets .

: Predominantly public sector and defense organizations in Ukraine .

: The .rar often contains a malicious LNK (shortcut) file or a disguised executable.

: Often associated with Pterodo (Pteranodon) or custom .NET backdoors. 🛠️ Detection and Analysis

Attackers distribute this file via with themes related to government or military intelligence.

: To see a live recording of how the file behaves in a sandbox environment. ⚠️ Recommendations Do not extract the archive on a primary workstation. Use a segmented virtual machine (VM) for analysis.

If you have the of the file, I can provide a more detailed breakdown of its specific behavior and infrastructure. AI responses may include mistakes. Learn more MalwareBazaar | Malware sample exchange - Abuse.ch

2745tuna.rar

2745tuna.rar -

The file is a malicious archive used in cyberattacks, specifically linked to Gamaredon Group (also known as Primitive Bear or APT28-adjacent), a state-sponsored threat actor focused on espionage against Ukrainian targets .

: Predominantly public sector and defense organizations in Ukraine . 2745tuna.rar

: The .rar often contains a malicious LNK (shortcut) file or a disguised executable. The file is a malicious archive used in

: Often associated with Pterodo (Pteranodon) or custom .NET backdoors. 🛠️ Detection and Analysis : Often associated with Pterodo (Pteranodon) or custom

Attackers distribute this file via with themes related to government or military intelligence.

: To see a live recording of how the file behaves in a sandbox environment. ⚠️ Recommendations Do not extract the archive on a primary workstation. Use a segmented virtual machine (VM) for analysis.

If you have the of the file, I can provide a more detailed breakdown of its specific behavior and infrastructure. AI responses may include mistakes. Learn more MalwareBazaar | Malware sample exchange - Abuse.ch

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.