MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92f8f069c032422eb6048ce1a648bd140dab9d3cfca5c855e2b56e1ac6f1cc7b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SheetRAT


Vendor detections: 14


Intelligence 14 IOCs YARA 12 File information Comments

SHA256 hash: 92f8f069c032422eb6048ce1a648bd140dab9d3cfca5c855e2b56e1ac6f1cc7b
SHA3-384 hash: 98f664216e95d06ff1055d14f6cf13d9722d08560e05680f6cbdcd768aaa565dc27a64f26b4ad665d093046594475da6
SHA1 hash: 66daed03974ace9055154d3e818bd5ef957ef651
MD5 hash: da4dc2203770bb12d6a2d5b38a5880a0
humanhash: july-neptune-seventeen-oklahoma
File name:pulse_launchеr.exe
Download: download sample
Signature SheetRAT
File size:3'229'184 bytes
First seen:2026-08-14 01:08:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'192 x AgentTesla, 20'344 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 98304:0xPvhSPnC38hCUL7Ig5Us7gYyE35CXbbVtY8K04:0Pv4PEeIg5xgYR3EXbZm8Z
TLSH T1D5E533F9937653CCDB2AA2353FC3F9542305C189BE9149D86174B250EB394E6FEC6228
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter aachum
Tags:91-92-47-228 exe RUS SheetRat


Avatar
iamaachum
https://www.youtube.com/watch?v=S17Qy7ly76A => https://drive.google.com/file/d/1ycp9MN4P7zHfeXeIprFBq8OLdV1EG5Un/view

SheetRAT C2: 91.92.47.228:1154

Intelligence


File Origin
# of uploads :
1
# of downloads :
133
Origin country :
ES ES
Vendor Threat Intelligence
Malware configuration found for:
EvilCoder SheetRat
Details
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-14 01:18:56 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file
DNS request
Connection attempt
Using the Windows Management Instrumentation requests
Sending a custom TCP request
Sending an HTTP GET request
Deleting a recently created file
Creating a window
Running batch commands
Creating a file in the Program Files directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Launching a process
Creating a file in the Windows directory
Enabling the libraries to load when starting the app (AppInit_DLLs)
Unauthorized injection to a recently created process
Enabling autorun
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
asyncrat base64 dropper packed reconnaissance remoteaccesstool vbnet xworm
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-12T06:18:00Z UTC
Last seen:
2026-08-14T17:59:00Z UTC
Hits:
~10
Result
Threat name:
SheetRat
Detection:
malicious
Classification:
troj.evad.mine.expl
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Found strings related to Crypto-Mining
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries memory information (via WMI often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Unusual module load detection (module proxying)
Yara detected SheetRat
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1957999 Sample: pulse_launch#U0435r.exe Startdate: 14/08/2026 Architecture: WINDOWS Score: 100 36 ru.pulsevisuals.pro 2->36 38 pulsevisuals.pro 2->38 40 eu.pulsevisuals.pro 2->40 56 Found malware configuration 2->56 58 Antivirus detection for URL or domain 2->58 60 Antivirus / Scanner detection for submitted sample 2->60 62 5 other signatures 2->62 9 pulse_launch#U0435r.exe 4 2->9         started        signatures3 process4 file5 30 C:\Users\user\AppData\...\pulse_launcher.exe, PE32+ 9->30 dropped 32 C:\Users\user\AppData\...\mrshtclient.exe, PE32 9->32 dropped 34 C:\Users\user\...\pulse_launch#U0435r.exe.log, CSV 9->34 dropped 12 pulse_launcher.exe 9 9->12         started        16 mrshtclient.exe 1 9->16         started        process6 dnsIp7 48 ru.pulsevisuals.pro 94.228.116.166, 443, 49729 TIMEWEB-ASRU Russia 12->48 50 pulsevisuals.pro 186.2.163.85, 443, 49728 IQWEBAE Belize 12->50 52 eu.pulsevisuals.pro 104.21.13.107, 443, 49730 CLOUDFLARENET-CloudflareIncUS Canada 12->52 64 Unusual module load detection (module proxying) 12->64 18 msedgewebview2.exe 33 238 12->18         started        66 Multi AV Scanner detection for dropped file 16->66 68 Queries memory information (via WMI often done to detect virtual machines) 16->68 signatures8 process9 signatures10 54 Found strings related to Crypto-Mining 18->54 21 msedgewebview2.exe 18->21         started        24 msedgewebview2.exe 18->24         started        26 msedgewebview2.exe 4 18->26         started        28 3 other processes 18->28 process11 dnsIp12 42 150.171.28.11, 443, 49746 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 21->42 44 teams-mrc-ww-perf.tm-4.office.com 52.123.255.134, 443, 49727 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 21->44 46 6 other IPs or domains 21->46
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.21 Win 32 Exe x86
Threat name:
ByteCode-MSIL.Trojan.XWormRAT
Status:
Malicious
First seen:
2026-08-12 04:14:42 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
22 of 24 (91.67%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
NightCoreLoader SheetRAT
Result
Malware family:
sheetrat
Score:
  10/10
Tags:
family:sheetrat campaign:sheet_jdrwrjcimkcahs defense_evasion discovery execution persistence privilege_escalation spyware trojan
Behaviour
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Modifies system certificate store
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Executes a command shell one-liner
Modifies trusted root certificate store through registry
Drops file in Program Files directory
Drops file in Windows directory
Checks whether UAC is enabled
Network Share Discovery
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Event Triggered Execution: AppInit DLLs
Detects Sheetrat obfuscated V1.8 and higher
Detects Sheetrat obfuscated version
Family: Sheetrat, NonEuclid rat
Modifies WinLogon for persistence
Malware Config
C2 Extraction:
91.92.47.228:1154
Unpacked files
SH256 hash:
92f8f069c032422eb6048ce1a648bd140dab9d3cfca5c855e2b56e1ac6f1cc7b
MD5 hash:
da4dc2203770bb12d6a2d5b38a5880a0
SHA1 hash:
66daed03974ace9055154d3e818bd5ef957ef651
SH256 hash:
43043678fa13cea97870af3dd34f74e028f35bc190ab55f6ffeaa6a2f2a58172
MD5 hash:
f315724a6cf41aa2d2ed2bf71ba9a6d1
SHA1 hash:
6a9d26541a555757f1b44d920fcbdc473e724430
SH256 hash:
a46aa937433c10dc4bb5c98e42c038b8afd3904c924b1444d5c703a32c414f44
MD5 hash:
9520b72f97049eefa145afdb4c536036
SHA1 hash:
f62f1e1c51f4fe10bb60e4e3a281f688981b67ee
SH256 hash:
35c8d022e1d917f1aabdceae98097ccc072161b302f84c768ca63e4b32ac2b66
MD5 hash:
16e5a492c9c6ae34c59683be9c51fa31
SHA1 hash:
97031b41f5c56f371c28ae0d62a2df7d585adaba
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SheetRAT

Executable exe 92f8f069c032422eb6048ce1a648bd140dab9d3cfca5c855e2b56e1ac6f1cc7b

(this sample)

  
Delivery method
Distributed via web download

Comments