MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 192f3ed9b0e879269fee5997c9d5fbb215a8747f872cce81132e2811d12d5684. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XpertRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 192f3ed9b0e879269fee5997c9d5fbb215a8747f872cce81132e2811d12d5684
SHA3-384 hash: acf0ce836f80225cecb8e97b7af905a4f4b14ec06920e1d7ec77a316c2da250a767f669427740c31b0b8166ea855b560
SHA1 hash: ccf43621417a569773f2766e436dac9b086c8ce9
MD5 hash: cb0be933c6bc24c71258767f1dc58ee5
humanhash: summer-vegan-gee-colorado
File name:RFQ 13970 DT.gz
Download: download sample
Signature XpertRAT
File size:441'058 bytes
First seen:2020-06-04 07:14:02 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:miG1lFJG63Uog4YOCMIbu9mqmGmeBffztxgmd0zmdSzXO0H3oMKhvTrdjbcptD:41HJGGfxYN7RatJ2md/QDOd9TZg
TLSH 69942366E23517DA31E4CD7D40687B424A6AB03510EBEF2DB2596BF27A64E0CDD1F830
Reporter abuse_ch
Tags:gz XpertRAT


Avatar
abuse_ch
Malspam distributing XpertRAT:

HELO: server.kibriswebtasarimi.com
Sending IP: 176.9.21.149
From: kavita_d@hindustancopper.com
Subject: CLARRIFICATION RFQ 13970 DT.02 / 03/2020 DUE DT.17 / 05/2020
Attachment: RFQ 13970 DT.gz (contains "RFQ 13970 DT.exe")

XpertRAT C2:
79.134.225.85:3135

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 07:29:25 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XpertRAT

gz 192f3ed9b0e879269fee5997c9d5fbb215a8747f872cce81132e2811d12d5684

(this sample)

  
Dropping
XpertRAT
  
Delivery method
Distributed via e-mail attachment

Comments