🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 089cd5a891a8f212df5f54a6b08205e06e85eacbe6ff9bfcfcb5fd6e51d1813b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 11


Intelligence 11 IOCs YARA 7 File information Comments

SHA256 hash: 089cd5a891a8f212df5f54a6b08205e06e85eacbe6ff9bfcfcb5fd6e51d1813b
SHA3-384 hash: 5f01b7f4bed1e463a5043d76b833026c494afcaee5ee2d5a183a94917b98ac817d5f85f0f194e8ec08c8ea15e404c4db
SHA1 hash: 6a08e4e05a94347b02b0aef2aa2a695e859eb678
MD5 hash: 6200240443329003bc9e2b3ddfbe34da
humanhash: december-orange-purple-timing
File name:instapp.a.1.06.sfx.exe
Download: download sample
Signature ValleyRAT
File size:4'028'963 bytes
First seen:2026-09-23 14:08:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2057790ae7855765d51bdc4142e62f9c (80 x RemusStealer, 8 x ValleyRAT, 6 x SalatStealer)
ssdeep 98304:rKAnKhbJpxL0UCzrqcAiKmnpu0BPbwJIM:ri/g1xpE
TLSH T117162319E7E405FDF1B3E174CE868A02DB773C494775E68F03A8A9660F27690C939722
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9494b494d4aeaeac (918 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter Ling
Tags:exe SilverFox ValleyRAT


Avatar
CNGaoLing
instapp.a.1.06.sfx.exe

SilverFox
IOC (fjifyk.net) (ybjyz0.oss-cn-beijing.aliyuncs.com) (mm2027.oss-cn-hangzhou.aliyuncs.com) (new2027.oss-cn-hongkong.aliyuncs.com)

Intelligence


File Origin
# of uploads :
1
# of downloads :
184
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
ID:
1
File name:
instapp.a.1.06.sfx.exe
Verdict:
Malicious activity
Analysis date:
2026-09-23 13:48:57 UTC
Tags:
rat gh0st stego payload upx

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the Program Files subdirectories
Creating a process from a recently created file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug fingerprint installer-heuristic masquerade microsoft_visual_cc overlay packed reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-23T03:18:00Z UTC
Last seen:
2026-09-24T18:34:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Agent.sba HackTool.Multi.AmsiETWPatch.sb HEUR:Trojan-Dropper.Win32.Generic
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-09-23 14:09:22 UTC
File Type:
PE+ (Exe)
Extracted files:
36
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution exploit persistence privilege_escalation trojan
Behaviour
Uses Task Scheduler COM API
System policy modification
Suspicious use of WriteProcessMemory
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: LoadsDriver
Suspicious behavior: EnumeratesProcesses
Scheduled Task/Job: Scheduled Task
Runs net.exe
Modifies registry class
Modifies Control Panel
Checks processor information in registry
System Location Discovery: System Language Discovery
Executes a command shell one-liner
Event Triggered Execution: Screensaver
Enumerates physical storage devices
Drops file in Program Files directory
Launches sc.exe
Drops file in System32 directory
Indicator Removal: Clear Persistence
Adds Run key to start application
Modifies file permissions
Loads dropped DLL
Executes dropped EXE
Disables service(s)
Checks computer location settings
Checks BIOS information in registry
Possible privilege escalation attempt
Modifies RDP port number used by Windows
Drops file in Drivers directory
Command and Scripting Interpreter: PowerShell
Windows security bypass
UAC bypass
Unpacked files
SH256 hash:
089cd5a891a8f212df5f54a6b08205e06e85eacbe6ff9bfcfcb5fd6e51d1813b
MD5 hash:
6200240443329003bc9e2b3ddfbe34da
SHA1 hash:
6a08e4e05a94347b02b0aef2aa2a695e859eb678
SH256 hash:
c5c2a5ba1f42b31495152c38ada2352d3b564dc84ef99968360ea9d50aa73258
MD5 hash:
ace563ab0781373e08d87c18b084a2c4
SHA1 hash:
bfad38c3e51f6731e63265d74f5f4f41c3597044
SH256 hash:
5327163035ebfe41eb3f912dbcbb78387ac61af6b9318e8ca98cc41602499f18
MD5 hash:
20aa80742086bd1fccfd110534696374
SHA1 hash:
210a9664491d0adf31d485258f09daf202d98df8
Detections:
INDICATOR_SUSPICIOUS_EXE_SandboxUserNames
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

Executable exe 089cd5a891a8f212df5f54a6b08205e06e85eacbe6ff9bfcfcb5fd6e51d1813b

(this sample)

  
Delivery method
Distributed via web download

Comments