🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b4cbe7838d5c2e166b446a2fdf63fec79e033c4ced7eb5cc60431b8f22e6700. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RevengeRAT


Vendor detections: 14


Intelligence 14 IOCs YARA 10 File information Comments

SHA256 hash: 0b4cbe7838d5c2e166b446a2fdf63fec79e033c4ced7eb5cc60431b8f22e6700
SHA3-384 hash: 410469b9f63132681d3d92f7ac145858903f6f851ddad6cb2db65c0723f30d83c50d1b079a3aa8fb40590805f3f2f656
SHA1 hash: 2408b526db41cad7cff345aa5753476147f8f0b4
MD5 hash: 875a806f3b37f0268e47db10e410a761
humanhash: freddie-video-saturn-virginia
File name:IEXPLORE.EXE
Download: download sample
Signature RevengeRAT
File size:923'832 bytes
First seen:2023-11-02 16:04:52 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash afcdf79be1557326c854b6e20cb900a7 (1'103 x FormBook, 936 x AgentTesla, 399 x RemcosRAT)
ssdeep 24576:ZAHnh+eWsN3skA4RV1Hom2KXMmHaKZa5H:gh+ZkldoPK8YaKGH
Threatray 4 similar samples on MalwareBazaar
TLSH T18C158C0273D1C036FFAB92739B6AB24556BC79254133852F13982DB9BD701B2263E763
TrID 85.7% (.CPL) Windows Control Panel Item (generic) (197083/11/60)
4.5% (.EXE) Win64 Executable (generic) (10523/12/4)
2.8% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
2.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
1.9% (.EXE) Win32 Executable (generic) (4505/5/1)
File icon (PE):PE icon
dhash icon aae2f3e38383b629 (2'698 x Formbook, 1'203 x CredentialFlusher, 928 x AgentTesla)
Reporter adm1n_usa32
Tags:exe RevengeRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
345
Origin country :
RO RO
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Launching a process
Searching for synchronization primitives
DNS request
Adding an access-denied ACE
Creating a file in the %AppData% subdirectories
Unauthorized injection to a system process
Enabling autorun by creating a file
Gathering data
Verdict:
Likely Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
autoit control explorer greyware keylogger lolbin masquerade overlay shell32
Result
Threat name:
Revenge
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Binary is likely a compiled AutoIt script file
Contains functionality to inject code into remote processes
Contains functionality to modify clipboard data
Detected Revenge RAT
Found malware configuration
Found RAT behaviour (information extraction to be send to C&C)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Uses dynamic DNS services
Writes to foreign memory regions
Yara detected RevengeRAT
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.AtomicRat
Status:
Malicious
First seen:
2023-11-01 18:32:00 UTC
File Type:
PE (Exe)
Extracted files:
28
AV detection:
29 of 38 (76.32%)
Threat level:
  5/5
Result
Malware family:
revengerat
Score:
  10/10
Tags:
family:revengerat botnet:marzo26 stealer trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Drops startup file
RevengeRat Executable
RevengeRAT
Malware Config
C2 Extraction:
marzorevenger.duckdns.org:4230
Unpacked files
SH256 hash:
627522cd66b223b7c388a31fbd03e7561a8b1441b6f0c281f6a7996cd250c45a
MD5 hash:
70b010a0ab9a296665bec2f45ca9f317
SHA1 hash:
09f71f03997401ac4932b5000e4af92fe2f7dfec
SH256 hash:
0b4cbe7838d5c2e166b446a2fdf63fec79e033c4ced7eb5cc60431b8f22e6700
MD5 hash:
875a806f3b37f0268e47db10e410a761
SHA1 hash:
2408b526db41cad7cff345aa5753476147f8f0b4
Malware family:
RevengeRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Compiled
Author:@bartblaze
Description:Identifies compiled AutoIT script (as EXE).
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MALWARE_Win_RevengeRAT
Author:ditekSHen
Description:RevengeRAT and variants payload
Rule name:MSIL_TinyDownloader_Generic
Author:albertzsigovits
Description:Detects small-sized dotNET downloaders
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:RevengeRAT_Sep17
Author:Florian Roth (Nextron Systems)
Description:Detects RevengeRAT malware
Reference:Internal Research
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:SUSP_Imphash_Mar23_3
Author:Arnim Rupp (https://github.com/ruppde)
Description:Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits
Reference:Internal Research
Rule name:Windows_Trojan_Revengerat_db91bcc6
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments