🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 325a8b36cd43c91d8a678907611a8ec5c78719809cf1a4cdb3d03f84de59ec50. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XpertRAT


Vendor detections: 12


Intelligence 12 IOCs YARA 4 File information Comments

SHA256 hash: 325a8b36cd43c91d8a678907611a8ec5c78719809cf1a4cdb3d03f84de59ec50
SHA3-384 hash: 3963d996cb79dd3d0de756bef793afbd63c1c31c5932d05c69ad15ade1262ab338b94bf28ef988297ce0f832926a79bc
SHA1 hash: bb3841b237127c1654d602283026996f62001012
MD5 hash: b8c759b59611c0776e62fc70aa89ffb6
humanhash: mobile-georgia-texas-twenty
File name:Cotización ref#8024108130.pdf(89kb).exe
Download: download sample
Signature XpertRAT
File size:1'352'192 bytes
First seen:2021-12-06 11:32:59 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'243 x AgentTesla, 20'499 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 24576:vXyLThHEgYcS80Evqe/eDyqeTH9C4107M4H9ru:/yLdHEV8xvpeDyqeTHb10r9S
Threatray 811 similar samples on MalwareBazaar
TLSH T18C556A5C317025AFE83A853145541F3B9EF12C7D966B53CE7217309F8ABE9828F242E9
File icon (PE):PE icon
dhash icon 86e8c0c8ccd89ce6 (18 x AgentTesla, 18 x Formbook, 8 x Loki)
Reporter abuse_ch
Tags:exe XpertRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
183
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Cotización ref#8024108130.pdf(89kb).exe
Verdict:
Malicious activity
Analysis date:
2021-12-06 11:47:28 UTC
Tags:
trojan rat xpertrat stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
DNS request
Using the Windows Management Instrumentation requests
Creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated packed
Malware family:
Malicious Packer
Verdict:
Malicious
Result
Threat name:
MailPassView XpertRAT
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Changes security center settings (notifications, updates, antivirus, firewall)
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Creates an undocumented autostart registry key
Creates autostart registry keys with suspicious names
Disables UAC (registry)
Disables user account control notifications
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
PE file contains section with special chars
PE file has nameless sections
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Generic Dropper
Yara detected MailPassView
Yara detected WebBrowserPassView password recovery tool
Yara detected XpertRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 534675 Sample: Cotizaci#U00f3n ref#8024108... Startdate: 06/12/2021 Architecture: WINDOWS Score: 100 53 Found malware configuration 2->53 55 Malicious sample detected (through community Yara rule) 2->55 57 Multi AV Scanner detection for submitted file 2->57 59 12 other signatures 2->59 9 Cotizaci#U00f3n ref#8024108130.pdf(89kb).exe 3 2->9         started        13 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe 3 2->13         started        15 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe 2 2->15         started        17 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe 2 2->17         started        process3 file4 45 Cotizaci#U00f3n re...0.pdf(89kb).exe.log, ASCII 9->45 dropped 69 Injects a PE file into a foreign processes 9->69 19 Cotizaci#U00f3n ref#8024108130.pdf(89kb).exe 1 1 9->19         started        71 Multi AV Scanner detection for dropped file 13->71 73 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 13->73 75 Machine Learning detection for dropped file 13->75 77 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 13->77 22 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe 1 13->22         started        24 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe 15->24         started        26 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe 1 17->26         started        signatures5 process6 signatures7 61 Changes security center settings (notifications, updates, antivirus, firewall) 19->61 63 Disables user account control notifications 19->63 65 Writes to foreign memory regions 19->65 67 3 other signatures 19->67 28 iexplore.exe 3 8 19->28         started        process8 dnsIp9 51 QW.sly.io 195.133.18.115, 1016, 49744, 49745 AS-REGRU Russian Federation 28->51 47 P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6.exe, PE32 28->47 dropped 49 C:\...\P0U4M118-N5L3-V331-S114-L7S6L4U0H6I6, data 28->49 dropped 79 Creates an undocumented autostart registry key 28->79 81 Creates autostart registry keys with suspicious names 28->81 33 iexplore.exe 28->33         started        35 iexplore.exe 28->35         started        37 iexplore.exe 2 28->37         started        39 4 other processes 28->39 file10 signatures11 process12 process13 41 WerFault.exe 33->41         started        43 WerFault.exe 35->43         started       
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-12-06 11:33:13 UTC
File Type:
PE (.Net Exe)
Extracted files:
22
AV detection:
21 of 27 (77.78%)
Threat level:
  5/5
Result
Malware family:
xpertrat
Score:
  10/10
Tags:
family:xpertrat collection evasion persistence rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Adds Run key to start application
Checks whether UAC is enabled
Maps connected drives based on registry
Program crash
Checks BIOS information in registry
Windows security modification
Adds policy Run key to start application
Looks for VMWare Tools registry key
Looks for VirtualBox Guest Additions in registry
UAC bypass
Windows security bypass
XpertRAT
Unpacked files
SH256 hash:
0c987408f442d577a4b5f16c9f1f3c6f5d9b4f05116e6bca93b93c201b60fa74
MD5 hash:
73d6bdae4df763c222d0615a34aec1a1
SHA1 hash:
a9ff294b18769128e05fafd703e487cd6085b801
Detections:
win_xpertrat_a0 win_xpertrat_auto
SH256 hash:
fe67fb2b928798938fc2ec1100da841dd57e401530357585a8a707b8971c3d7c
MD5 hash:
4edd1516fa1e014b1f4d03424e54c05e
SHA1 hash:
60392b60b6703a253f1eaf99ab7c4f2739bbb5e3
SH256 hash:
ddc60b54f5e516874c02d980d2dd9e006a4944a505e92fbccac36b9f6ed302b2
MD5 hash:
b965e5c6a7db66d0665aea85ae796afb
SHA1 hash:
f62b56badc281777488458c723ca7313ad381b32
SH256 hash:
fdb256a562c32e4a299bf1ab5f38488bd78bd0c60abc3c5eafdbc08edc0dd584
MD5 hash:
91883215a201aa7f0d63bd23ae41d20b
SHA1 hash:
2a2b588671a2cdfe3d2968279690e3911a86cc09
SH256 hash:
325a8b36cd43c91d8a678907611a8ec5c78719809cf1a4cdb3d03f84de59ec50
MD5 hash:
b8c759b59611c0776e62fc70aa89ffb6
SHA1 hash:
bb3841b237127c1654d602283026996f62001012
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFuture
Author:ditekSHen
Description:Detect executables with stomped PE compilation timestamp that is greater than local current time
Rule name:pe_imphash
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

XpertRAT

Executable exe 325a8b36cd43c91d8a678907611a8ec5c78719809cf1a4cdb3d03f84de59ec50

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments