MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 483aa1d69ef169d16b8f89c67fd31310ecba07adf6d2c7ed907f63da7425b97f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 13


Intelligence 13 IOCs 1 YARA 12 File information Comments

SHA256 hash: 483aa1d69ef169d16b8f89c67fd31310ecba07adf6d2c7ed907f63da7425b97f
SHA3-384 hash: 2e8c22bc825dccd4fa99e5a12cb77e85429ac3c95448643fbfa73c85d20e8ae209d0fbaee68003c657b04464e0f52e4f
SHA1 hash: c473ebe9354843f262c9e49c660e180153e5bebc
MD5 hash: 0c1399470cac4a44234827eabedc52d3
humanhash: spring-alpha-west-september
File name:0c1399470cac4a44234827eabedc52d3.exe
Download: download sample
Signature ValleyRAT
File size:3'256'320 bytes
First seen:2025-06-13 05:15:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4cd7cf12a3acbee5a887180657d56cd6 (1 x ValleyRAT)
ssdeep 49152:tepTIlf+hj6dd6CdymDSzvik+MqjYgjTU8O0JAAMbpC:tITIlf+hj6dd1dylD+NjYkI8libpC
Threatray 35 similar samples on MalwareBazaar
TLSH T131E5F11176D1C072D352163049A6B3728ABEB9312F31A7C76399EF1D2E701D29E353AB
TrID 36.8% (.EXE) InstallShield setup (43053/19/16)
26.6% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
14.1% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
9.0% (.EXE) Win64 Executable (generic) (10522/11/4)
4.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon 0049c8e9d4d6d410 (1 x AsyncRAT, 1 x ValleyRAT)
Reporter abuse_ch
Tags:exe RAT ValleyRAT


Avatar
abuse_ch
ValleyRAT C2:
101.126.157.9:6666

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
101.126.157.9:6666 https://threatfox.abuse.ch/ioc/1544359/

Intelligence


File Origin
# of uploads :
1
# of downloads :
478
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
0c1399470cac4a44234827eabedc52d3.exe
Verdict:
No threats detected
Analysis date:
2025-06-13 05:19:52 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
shellcode dropper cobalt shell
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Creating a file in the Windows directory
Creating a process from a recently created file
Сreating synchronization primitives
Creating a process with a hidden window
Connection attempt
Running batch commands
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm explorer fingerprint iceid keylogger lolbin microsoft_visual_cc packed packed packer_detected
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Bypasses PowerShell execution policy
Connects to many ports of the same IP (likely port scanning)
Contains functionality to infect the boot sector
Drops executables to the windows directory (C:\Windows) and starts them
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1713813 Sample: x0nDSnI2KE.exe Startdate: 13/06/2025 Architecture: WINDOWS Score: 100 84 Suricata IDS alerts for network traffic 2->84 86 Multi AV Scanner detection for submitted file 2->86 88 Connects to many ports of the same IP (likely port scanning) 2->88 90 2 other signatures 2->90 10 x0nDSnI2KE.exe 1 2->10         started        process3 file4 66 C:\Windows\123.exe, PE32 10->66 dropped 98 Drops executables to the windows directory (C:\Windows) and starts them 10->98 14 123.exe 10 10->14         started        signatures5 process6 dnsIp7 74 101.126.157.9, 18852, 18853, 49720 JDCOMBeijingJingdong360DegreeE-commerceCoLtdCN China 14->74 68 C:\Users\user\AppData\...\insttect.exe, PE32 14->68 dropped 70 C:\Users\user\AppData\...\Microsoft.dll, PE32 14->70 dropped 72 C:\Users\user\AppData\...\insttect.exe (copy), PE32 14->72 dropped 76 Multi AV Scanner detection for dropped file 14->76 78 Contains functionality to infect the boot sector 14->78 80 Bypasses PowerShell execution policy 14->80 82 Adds a directory exclusion to Windows Defender 14->82 19 cmd.exe 1 14->19         started        21 cmd.exe 1 14->21         started        24 powershell.exe 23 14->24         started        26 insttect.exe 4 4 14->26         started        file8 signatures9 process10 signatures11 28 regsvr32.exe 3 7 19->28         started        31 conhost.exe 19->31         started        92 Adds a directory exclusion to Windows Defender 21->92 33 powershell.exe 23 21->33         started        35 conhost.exe 21->35         started        94 Loading BitLocker PowerShell Module 24->94 37 conhost.exe 24->37         started        process12 signatures13 100 System process connects to network (likely due to code injection or exploit) 28->100 39 cmd.exe 1 28->39         started        41 cmd.exe 28->41         started        43 cmd.exe 28->43         started        45 2 other processes 28->45 102 Loading BitLocker PowerShell Module 33->102 process14 process15 47 conhost.exe 39->47         started        49 tasklist.exe 39->49         started        51 findstr.exe 39->51         started        62 25 other processes 39->62 53 powershell.exe 41->53         started        56 conhost.exe 41->56         started        58 powershell.exe 43->58         started        60 conhost.exe 43->60         started        64 4 other processes 45->64 signatures16 96 Loading BitLocker PowerShell Module 53->96
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2025-06-09 12:39:00 UTC
AV detection:
22 of 38 (57.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Drops file in Windows directory
Executes dropped EXE
Unpacked files
SH256 hash:
2ec84fa2bff51e4c84f091f680b262540c01acb9b7f4b1497a8e45ec40b9f0f8
MD5 hash:
34ccb7237931b36915d57f1d9d50a5ba
SHA1 hash:
eef520f1a9d33dbced2d8b6c739e00c605b95017
SH256 hash:
483aa1d69ef169d16b8f89c67fd31310ecba07adf6d2c7ed907f63da7425b97f
MD5 hash:
0c1399470cac4a44234827eabedc52d3
SHA1 hash:
c473ebe9354843f262c9e49c660e180153e5bebc
Malware family:
ValleyRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Hacktools_CN_Panda_andrew
Author:Florian Roth
Description:Disclosed hacktool set - file andrew.exe - sethc.exe Debugger backdoor
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:Windows_Shellcode_Rdi_eee75d2c
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
MULTIMEDIA_APICan Play MultimediaWINMM.dll::midiOutPrepareHeader
WINMM.dll::midiOutReset
WINMM.dll::midiOutUnprepareHeader
WINMM.dll::midiStreamClose
WINMM.dll::midiStreamOpen
WINMM.dll::midiStreamOut
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteA
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CreateProcessA
KERNEL32.dll::CloseHandle
KERNEL32.dll::CreateThread
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryA
KERNEL32.dll::GetVolumeInformationA
KERNEL32.dll::GetStartupInfoA
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WinExec
KERNEL32.dll::SetStdHandle
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateFileA
KERNEL32.dll::GetFileAttributesA
KERNEL32.dll::FindFirstFileA
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegCreateKeyExA
ADVAPI32.dll::RegOpenKeyExA
ADVAPI32.dll::RegQueryValueA
ADVAPI32.dll::RegSetValueExA
WIN_USER_APIPerforms GUI ActionsUSER32.dll::AppendMenuA
USER32.dll::CreateMenu
USER32.dll::EmptyClipboard
USER32.dll::OpenClipboard
USER32.dll::PeekMessageA
USER32.dll::CreateWindowExA

Comments