MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0d4755125431b2df6a5232950b6c475bb6ae459a35503d64a6bc2c8075f5e2e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ValleyRAT
Vendor detections: 14
| SHA256 hash: | 0d4755125431b2df6a5232950b6c475bb6ae459a35503d64a6bc2c8075f5e2e5 |
|---|---|
| SHA3-384 hash: | 7aa810b8c34158910ff3cb7c4ef371eba5ff0060683afd333772561593f524bc0f0c1586bf0a1287aea9702fcaf32e84 |
| SHA1 hash: | 6790e1cbf6798382504915d09bbf8b5aacc10dfe |
| MD5 hash: | 858d6d91e6d04cb26acb51fcb516f9c1 |
| humanhash: | angel-two-xray-delaware |
| File name: | Drv_ceo_12.8.1_x64.exe |
| Download: | download sample |
| Signature | ValleyRAT |
| File size: | 15'318'651 bytes |
| First seen: | 2026-08-08 15:54:55 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 57e98d9a5a72c8d7ad8fb7a6a58b3daf (66 x GuLoader, 20 x AZORult, 15 x RemcosRAT) |
| ssdeep | 393216:xxVCkFeObsJGHu9zwkXiJlrWqMudtVzBNdzV3:xxV7FtluRXFxudrzlR |
| TLSH | T1C2F6334225E634E7F273A3B47C7BA9386A13CC359AA707A00384F5E5BC5574528B72CB |
| TrID | 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 10.5% (.EXE) Win64 Executable (generic) (6522/11/2) 8.1% (.EXE) Win16 NE executable (generic) (5038/12/1) 7.2% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| dhash icon | c4ccb392f1f192cc (4 x LummaStealer, 4 x ValleyRAT, 2 x AsyncRAT) |
| Reporter | |
| Tags: | exe SilverFox ValleyRAT |
Intelligence
File Origin
USVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
35dab11414d17ad15b9992ba51ad57fc768fd3f4fc449d50fce08b2c46cbe270
cba8e79b90c98fe396da2d0243e1c98b13bdf586b8e60034be52fe6efdc42ce8
20343f047964ef95901941b2406ee66ec976e2d849abbe991f94b6a0fe634881
22a936860e45162049f713f1305e801899f8eb47a13fdb3504cf978a456efc16
588cdd2ac6167b34eaac919a31bf18ca7831183da6b1c2eccc5966808c2b3733
3515de6eccfc4e2b39dd34a21b1e7501673d598792b797907f40683ffb081592
0d4755125431b2df6a5232950b6c475bb6ae459a35503d64a6bc2c8075f5e2e5
cba8e79b90c98fe396da2d0243e1c98b13bdf586b8e60034be52fe6efdc42ce8
20343f047964ef95901941b2406ee66ec976e2d849abbe991f94b6a0fe634881
22a936860e45162049f713f1305e801899f8eb47a13fdb3504cf978a456efc16
588cdd2ac6167b34eaac919a31bf18ca7831183da6b1c2eccc5966808c2b3733
0d4755125431b2df6a5232950b6c475bb6ae459a35503d64a6bc2c8075f5e2e5
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | cobalt_strike_tmp01925d3f |
|---|---|
| Author: | The DFIR Report |
| Description: | files - file ~tmp01925d3f.exe |
| Reference: | https://thedfirreport.com |
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | golang_bin_JCorn_CSC846 |
|---|---|
| Author: | Justin Cornwell |
| Description: | CSC-846 Golang detection ruleset |
| Rule name: | Ins_NSIS_Buer_Nov_2020_1 |
|---|---|
| Author: | Arkbird_SOLG |
| Description: | Detect NSIS installer used for Buer loader |
| Rule name: | NSIS |
|---|---|
| Author: | kevoreilly |
| Description: | NSIS Integrity Check function |
| Rule name: | pe_detect_tls_callbacks |
|---|
| Rule name: | reverse_http |
|---|---|
| Author: | CD_R0M_ |
| Description: | Identify strings with http reversed (ptth) |
| Rule name: | SuspiciousDll |
|---|---|
| Author: | martclau |
| Description: | Detects SolarWinds Orion backdoor |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | telebot_framework |
|---|---|
| Author: | vietdx.mb |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
| Rule name: | TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE |
|---|---|
| Author: | CYFARE |
| Description: | Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments |
| Reference: | https://cyfare.net/ |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
| Rule name: | Windows_Shellcode_Rdi_918f8e2f |
|---|---|
| Author: | Elastic Security |
| Rule name: | Windows_Trojan_CobaltStrike_f0b627fc |
|---|---|
| Description: | Rule for beacon reflective loader |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.