MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6510d460395ca3643133817b40d9df4fa0d9dbe8e60b514fdc2d4e26b567dfbd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PondRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 5 File information Comments

SHA256 hash: 6510d460395ca3643133817b40d9df4fa0d9dbe8e60b514fdc2d4e26b567dfbd
SHA3-384 hash: 80e017d10316bde368cc7324fb320fdc606e1e89479a329c99c38dc7fbaa6b34d4d490188b0fc456e04d269853b82dd5
SHA1 hash: 61d506a4a286e6d13138b7c3ce7866c457d113df
MD5 hash: fe0008771a3e5c9c1c789d41ad57d571
humanhash: india-washington-river-cold
File name:6510d460395ca3643133817b40d9df4fa0d9dbe8e60b514fdc2d4e26b567dfbd_windows_pondrat.bin
Download: download sample
Signature PondRAT
File size:148'480 bytes
First seen:2025-09-12 11:26:43 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9cab062b6407ceff6e9df9399380da8b (1 x PondRAT)
ssdeep 3072:lXpLZGidmrvH7c7XNxNyKtk2uMSQ6H0VVlVW:ppdarvbczYa4Mc
TLSH T159E36D17B2A501BBD1374238C9635A12FB77B4611B30AFAF036446751F273A1AE3EB61
TrID 44.4% (.EXE) Win64 Executable (generic) (10522/11/4)
21.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
8.7% (.ICL) Windows Icons Library (generic) (2059/9)
8.5% (.EXE) OS/2 Executable (generic) (2029/13)
8.4% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter SRT
Tags:exe Lazarus PondRAT RAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
6510d460395ca3643133817b40d9df4fa0d9dbe8e60b514fdc2d4e26b567dfbd_windows_pondrat.bin.exe
Verdict:
No threats detected
Analysis date:
2025-09-12 14:21:26 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm crypto masquerade microsoft_visual_cc
Verdict:
Malicious
File Type:
dll x64
First seen:
2025-09-12T10:07:00Z UTC
Last seen:
2025-09-12T10:07:00Z UTC
Hits:
~100
Detections:
Trojan.Win32.APosT.bllg Trojan.APosT.UDP.C&C PDM:Trojan.Win32.Generic
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-12 14:21:26 UTC
File Type:
PE+ (Dll)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Badlisted process makes network request
Verdict:
Unknown
Tags:
apt applejeus
YARA:
Apt_Win_Applejeus_C_Oct22
Unpacked files
SH256 hash:
6510d460395ca3643133817b40d9df4fa0d9dbe8e60b514fdc2d4e26b567dfbd
MD5 hash:
fe0008771a3e5c9c1c789d41ad57d571
SHA1 hash:
61d506a4a286e6d13138b7c3ce7866c457d113df
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:dgaagas
Author:Harshit
Description:Uses certutil.exe to download a file named test.txt
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments