MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5acbb6ee89b38eb2abf81a2b2349a4c97e7c2dd23ad4daf8d5b5b113176fef53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 13


Intelligence 13 IOCs YARA 2 File information Comments

SHA256 hash: 5acbb6ee89b38eb2abf81a2b2349a4c97e7c2dd23ad4daf8d5b5b113176fef53
SHA3-384 hash: 9c2a039fb820f7349517ab6061e9ddf09c200ec7eb886bfa573ce4fa8bd79d58cd48bb593f983d05c76eb02e03659e38
SHA1 hash: 002048e6ec82b326fe6bae4b6bac64de8e545026
MD5 hash: 04e3a5e74513b7cc7eb540940299806e
humanhash: south-ink-delaware-apart
File name:dingding.exe
Download: download sample
Signature ValleyRAT
File size:17'837'343 bytes
First seen:2026-08-21 15:54:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 311d1e93d89e02a2908fe4b6d6a25ef7 (5 x ValleyRAT)
ssdeep 393216:Oz7+P6gzjM/5IqMDF35s6pLNPX29pgbmjz0diOgJCJLouDW4iV:U7cT1/NpI9ymjz0VvHK4iV
TLSH T1A90733057991C6D4F7C272B9261C62F3837A4F6A183AD9FF24B072611BF5BC7D1120AA
TrID 62.5% (.EXE) Win32 Executable MS Visual C++ 4.x (134693/65)
14.4% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
7.6% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
3.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.0% (.EXE) Win64 Executable (generic) (6522/11/2)
Magika pebin
dhash icon c488b8f0e2b692cc (6 x ValleyRAT, 3 x Gh0stRAT, 2 x CobaltStrike)
Reporter abuse_ch
Tags:exe upx-dec ValleyRAT


Avatar
abuse_ch
UPX decompressed file, sourced from SHA256 65856b5986156143dbedada62799e8b3b18db753f9d519710654b72f2f051d54
File size (compressed) :17'713'439 bytes
File size (de-compressed) :17'837'343 bytes
Format:win32/pe
Packed file: 65856b5986156143dbedada62799e8b3b18db753f9d519710654b72f2f051d54

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
NL NL
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% directory
Changing a file
Launching a service
Creating a process from a recently created file
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Deleting a recently created file
Replacing files
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Creating a process with a hidden window
Searching for the window
Creating a file
Moving a file to the %AppData% subdirectory
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context evasive fingerprint installer installer installer-heuristic overlay packed reconnaissance sfx
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
76 / 100
Signature
Drops large PE files
Found direct / indirect Syscall (likely to bypass EDR)
Injects code into the Windows Explorer (explorer.exe)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Unusual module load detection (module proxying)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1961894 Sample: dingding.exe Startdate: 21/08/2026 Architecture: WINDOWS Score: 76 59 mumuany.com 2->59 61 dtupgrade.dingtalk.com 2->61 63 14 other IPs or domains 2->63 73 Malicious sample detected (through community Yara rule) 2->73 75 Multi AV Scanner detection for submitted file 2->75 77 Sigma detected: New RUN Key Pointing to Suspicious Folder 2->77 9 dingding.exe 4 2->9         started        12 explorer.exe 3 2->12         started        15 2uii3lcc.exe 2->15         started        17 4 other processes 2->17 signatures3 process4 file5 55 C:\Users\user\...\1dingtalk_downloader.exe, PE32 9->55 dropped 57 C:\Users\user\AppData\Local\...\1870000.exe, PE32 9->57 dropped 19 1870000.exe 4 5 9->19         started        22 1dingtalk_downloader.exe 23 9->22         started        85 Injects code into the Windows Explorer (explorer.exe) 12->85 26 explorer.exe 1 12->26         started        87 Found direct / indirect Syscall (likely to bypass EDR) 15->87 28 conhost.exe 15->28         started        30 conhost.exe 1 17->30         started        32 conhost.exe 17->32         started        signatures6 process7 dnsIp8 43 C:\Users\user\AppData\Local\...\2uii3lcc.exe, PE32+ 19->43 dropped 45 C:\Users\user\AppData\Local\Temp\aadrt.dll, PE32+ 19->45 dropped 47 C:\Users\user\AppData\...\CrashReporter.dll, PE32+ 19->47 dropped 34 2uii3lcc.exe 11 19->34         started        39 explorer.exe 19->39         started        67 dtapp-cast.dingtalk.com.queniuak.com 163.181.246.194, 443, 49709, 49714 TAOBAOZhejiangTaobaoNetworkCoLtdCN United States 22->67 69 na-v6-cname.dingtalk.com.gds.alibabadns.com 47.246.137.200, 443, 49713 ALIBABA-CN-NETAlibabaUSTechnologyCoLtdCN United States 22->69 71 2 other IPs or domains 22->71 49 C:\Users\user\...\8.5.0-Release.260817002.exe, PE32 22->49 dropped 83 Drops large PE files 22->83 file9 signatures10 process11 dnsIp12 65 161.248.14.133, 1523, 49715, 49716 BGPNETPTELTD-AS-APBGPNETPTELTDSG Malaysia 34->65 51 C:\Users\user\AppData\Local\...\Q85ZxR6.exe, PE32 34->51 dropped 53 C:\Users\user\AppData\Local\2uii3lcc.exe, PE32+ 34->53 dropped 79 Unusual module load detection (module proxying) 34->79 81 Found direct / indirect Syscall (likely to bypass EDR) 34->81 41 conhost.exe 34->41         started        file13 signatures14 process15
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout SFX 7z Win 32 Exe x86
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2026-08-21 15:55:19 UTC
File Type:
PE (Exe)
Extracted files:
73
AV detection:
14 of 23 (60.87%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware discovery persistence spyware upx
Behaviour
Checks processor information in registry
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
UPX packed file
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Unpacked files
SH256 hash:
5acbb6ee89b38eb2abf81a2b2349a4c97e7c2dd23ad4daf8d5b5b113176fef53
MD5 hash:
04e3a5e74513b7cc7eb540940299806e
SHA1 hash:
002048e6ec82b326fe6bae4b6bac64de8e545026
SH256 hash:
5eaa637cbd7adb47e395eeb4e2ecd467f414a14679f881e3c53925424adc76f3
MD5 hash:
98440376d1b0834c440db237b4a3f291
SHA1 hash:
c33f1c7bb4ddd940f5f34f533fea16cabf7724f4
SH256 hash:
72a2f6d02ffb701df20f2dc6cb878a3b676be40d0a607520967ba981d16eb636
MD5 hash:
2f6b3e49770b100217a04f3f160ead42
SHA1 hash:
c2e066efbc593967aa138f707722e5759ccd9f44
Detections:
OpCloudHopper_Malware_3
SH256 hash:
eebb65d76a6c65b9ecbbe9f067a1c20fa5f4e9cb1e680c272a5fca2e5cb16800
MD5 hash:
5e7b52817f1a00e9f1b4fecba22a9bd2
SHA1 hash:
9dd20e124e8e868c33d8a7be56e39910d7725b2b
Malware family:
CloudHopper
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

Executable exe 5acbb6ee89b38eb2abf81a2b2349a4c97e7c2dd23ad4daf8d5b5b113176fef53

(this sample)

Comments