🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d90ee2e0ceed931717be11b0ce7f4f634d3efc8ccc1ee63156c5573ecb054e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 15


Intelligence 15 IOCs YARA 21 File information Comments

SHA256 hash: 4d90ee2e0ceed931717be11b0ce7f4f634d3efc8ccc1ee63156c5573ecb054e9
SHA3-384 hash: 67a3dd084a9abb422a5eb59f12efd30e2bff7fe1f51955ffd2c9d80240318ec0097e54477d86aede76ab30cb4962d0ec
SHA1 hash: bf5df13161d95234a21efb1823c59d5adcdcd29e
MD5 hash: 5c9861c1c50e2aff2d29bb2a2aeebca9
humanhash: blossom-bluebird-equal-sad
File name:5c9861c1c50e2aff2d29bb2a2aeebca9.exe
Download: download sample
Signature ValleyRAT
File size:4'612'768 bytes
First seen:2026-10-05 08:53:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/vnd.microsoft.portable-executable
imphash 88016fcdef7f227c62171d0afad9aae4 (29 x ValleyRAT, 21 x OffLoader, 15 x Tofsee)
ssdeep 98304:R5OOAiPE2dHr8+siEARo4FqyiB5xFzX/gL7kBO5WIw0XDR6Pkt5:LxA2Vo+YAlFz4VXI3kG9t6Pkt5
TLSH T19D26023BF28B753EE02A5A367AB6D110543B7A20A5024C169AECF48CCF755711E3E787
TrID 50.8% (.EXE) Inno Setup installer (107240/4/30)
20.4% (.EXE) InstallShield setup (43053/19/16)
19.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.0% (.EXE) Win64 Executable (generic) (6522/11/2)
2.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 5050d270cccc82ae (115 x Adware.Generic, 86 x OffLoader, 50 x ValleyRAT)
Reporter abuse_ch
Tags:exe ValleyRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
189
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-10-05 09:52:22 UTC
Tags:
k7rkscan-sys vuln-driver valleyrat silverfox rat winos donutloader loader lua

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Moving a recently created file
Deleting a recently created file
Creating a service
Launching a service
Loading a system driver
Connection attempt
Sending a custom TCP request
Enabling autorun for a service
Gathering data
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-10-02T13:11:00Z UTC
Last seen:
2026-10-06T20:02:00Z UTC
Hits:
~10
Result
Threat name:
DonutLoader, ValleyRAT
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
C2 URLs / IPs found in malware configuration
Contains functionality to prevent local Windows debugging
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Unusual module load detection (module proxying)
Yara detected DonutLoader
Yara detected ValleyRAT
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Vuldriver
Status:
Suspicious
First seen:
2026-10-03 04:24:46 UTC
File Type:
PE (Exe)
Extracted files:
61
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
valleyrat_s2
Score:
  10/10
Tags:
family:donutloader family:valleyrat_s2 backdoor discovery installer loader
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Checks installed software on the system
Enumerates connected drives
Executes dropped EXE
Loads dropped DLL
Detects DonutLoader
Detects ValleyRAT payload
Family: DonutLoader
Family: ValleyRat
Unpacked files
SH256 hash:
4d90ee2e0ceed931717be11b0ce7f4f634d3efc8ccc1ee63156c5573ecb054e9
MD5 hash:
5c9861c1c50e2aff2d29bb2a2aeebca9
SHA1 hash:
bf5df13161d95234a21efb1823c59d5adcdcd29e
SH256 hash:
98f21855266cd14d5ba00b880b15584e71dcdd23cdaaf6bcd97b3f8dfdb322ab
MD5 hash:
554ca54274c3a1b24be4317a56dddb28
SHA1 hash:
5bb1181ca6debbbfa5d3f189d7dbaa8f57634e25
SH256 hash:
f44d87130760a8d50ae002566e6b1d09fabf315f2182d7e718669f0cec9a11ed
MD5 hash:
e985eb5f007d6b38b3205c1bc5963843
SHA1 hash:
f41be4d7b753563abcc778c491acaeda20b5b6b5
Malware family:
DonutLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:MULTI_Malware_AgentTesla_ForgeAuto_ed343f78_Extrait
Author:Marjoriefort
Description:Detects AgentTesla (inconnu, etat extrait)
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Donutloader_f40e3759
Author:Elastic Security
Rule name:Windows_Trojan_Winos_464b8a2e
Author:Elastic Security
Rule name:WinosStager
Author:YungBinary
Description:https://www.esentire.com/blog/winos4-0-online-module-staging-component-used-in-cleversoar-campaign
Rule name:WIN_Malware_ACRStealer_ForgeAuto_1084c837_Extrait
Author:Marjoriefort
Description:Detects ACRStealer (pe, etat extrait)
Rule name:WIN_Malware_Fantom_ForgeAuto_98e6f354_Extrait
Author:Marjoriefort
Description:Detects Fantom (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_1708427c_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_4ab123d7_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_6422f546_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)
Rule name:WIN_Malware_Unknown_ForgeAuto_f5d58a9e_Extrait
Author:Marjoriefort
Description:Detects Unknown (pe, etat extrait)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments