MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 60977eca0c78ae08cb9a2ea3a52ce0f8b49f3df7522b5fb5ee8eeb1a46510f56. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SiriusRAT


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: 60977eca0c78ae08cb9a2ea3a52ce0f8b49f3df7522b5fb5ee8eeb1a46510f56
SHA3-384 hash: 2f32ab161669cf9bc0f2c428ef8cb59df12e8e282acb8d64d439a8c948948bd4eeabd21406f0cd85bd5be4f2d244dfc1
SHA1 hash: 6c672941ca5610ea2b50863fdfdac6180645986c
MD5 hash: ddeb98aef74364d5068836f404613d92
humanhash: monkey-fourteen-king-three
File name:60977eca0c78ae08cb9a2ea3a52ce0f8b49f3df7522b5fb5ee8eeb1a46510f56
Download: download sample
Signature SiriusRAT
File size:2'987'520 bytes
First seen:2026-07-07 14:10:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 49152:3YNnGDNaciFItbKJZ6HlTbFav4l+ZzEUINav8aOuMBNn4VBj6Og6n/QwS2Ke:oJUNdiFItAZ6HlHFpUJvVOuy4V5a6/QG
Threatray 69 similar samples on MalwareBazaar
TLSH T11FD52398661AE913CB5423344AB2F2744278AFDEB901D22B5FD9BEFB7931F410C405A7
TrID 44.6% (.EXE) Win64 Executable (generic) (6522/11/2)
14.0% (.ICL) Windows Icons Library (generic) (2059/9)
13.8% (.EXE) OS/2 Executable (generic) (2029/13)
13.7% (.EXE) Generic Win/DOS Executable (2002/3)
13.6% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 33e8c8d9c9c8c873 (2 x SiriusRAT)
Reporter adrian__luca
Tags:exe SiriusRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
99.1%
Tags:
autorun virus msil hype
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Restart of the analyzed sample
Creating a file
DNS request
Connection attempt
Sending an HTTP GET request
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Enabling the 'hidden' option for recently created files
Creating a file in the Windows subdirectories
Unauthorized injection to a recently created process
Unauthorized injection to a recently created process by context flags manipulation
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun by creating a file
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-06-09T04:53:00Z UTC
Last seen:
2026-07-07T23:48:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.32 Win 64 Exe x64
Threat name:
ByteCode-MSIL.Ransomware.RedLine
Status:
Malicious
First seen:
2026-06-09 07:29:32 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
8
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
siriusrat
Score:
  10/10
Tags:
family:siriusrat adware persistence rat spyware
Behaviour
Checks SCSI registry key(s)
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Drops file in Windows directory
Suspicious use of SetThreadContext
Adds Run key to start application
Enumerates connected drives
Looks up external IP address via web service
Drops startup file
Executes dropped EXE
Boot or Logon Autostart Execution: Active Setup
Detects SiriusRAT
Family: SiriusRAT
Unpacked files
SH256 hash:
60977eca0c78ae08cb9a2ea3a52ce0f8b49f3df7522b5fb5ee8eeb1a46510f56
MD5 hash:
ddeb98aef74364d5068836f404613d92
SHA1 hash:
6c672941ca5610ea2b50863fdfdac6180645986c
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments