MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 969d32afca0623f627cdff73d547934b5237b0a3c513bc058600899beccc5a14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 969d32afca0623f627cdff73d547934b5237b0a3c513bc058600899beccc5a14
SHA3-384 hash: 2aaa8a2c40bfbe45a6602491e2d7ed53e40f2fa80f7e990a1a4984c5a84c09fded571f2c9b61a5abbc92590115ce47eb
SHA1 hash: 19bd29c8a56aa1d62904e8259004221c1b29925f
MD5 hash: 167100db0d172822b3db978853e47d5d
humanhash: mobile-connecticut-bluebird-wyoming
File name:ScreenShot.png.tar
Download: download sample
Signature PureRAT
File size:12'288 bytes
First seen:2025-12-23 18:13:18 UTC
Last seen:Never
File type: tar
MIME type:application/x-tar
ssdeep 192:VzdDqyJLxR61rxTAPzNVw9XSafBtkUHD41tcY+OferUIVfrtXcyQcT1vDh:Vp3xR2tTAPJmhSaptkUHAtcYPluf5TQ0
TLSH T1A74200BCC5E0FCC0CB5F31F175DAFAD2129ADB13BD6A1968E98844940B80714EBE9548
TrID 62.9% (.TAR/USTAR) TAR - Tape ARchive (POSIX) (17/3)
37.0% (.TAR) TAR - Tape ARchive (file) (10/3)
Magika tar
Reporter aachum
Tags:lastmin1917-dynuddns-com PureRAT ReverseLoader tar


Avatar
iamaachum
https://downloadtorrentfile.com/hash/3081c921b5c9b2ecbd7dd593c529bb392e27ed4d?name=Predator%20Badlands%202025%201080p%20HDRip%20HEVC%20x265.iso

IOCs:
vvvpmscvtlhcjbybrwjg.supabase.co
xkdrz4tn6l.ufs.sh
https://xkdrz4tn6l.ufs.sh/f/Byenrkx7DKMySGg3FeDn36N2em9fVg7wxUTzA1BHjMIZ5XtY?12711343
https://raw.githubusercontent.com/xxWorker/xWork/refs/heads/main/Vdqxyjz2222purupload.txt
lastmin1917.dynuddns.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
FR FR
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:txsnd.bat
File size:10'283 bytes
SHA256 hash: 5398dfa9b21d13c9881b8775353022160a05f203b981432c15d0d7ca17e2eb54
MD5 hash: bd767aaad67134a3dfb38e4c708f9927
MIME type:text/x-msdos-batch
Signature PureRAT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
94.1%
Tags:
ransomware shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 obfuscated obfuscated powershell powershell
Verdict:
Malicious
File Type:
tar
First seen:
2025-12-24T15:20:00Z UTC
Last seen:
2025-12-24T15:27:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
3 match(es)
Tags:
DeObfuscated PowerShell Tar Archive
Verdict:
Malicious
Threat:
AuxiliaryAnalysis.Malware.Generic
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-23 18:13:24 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PureRAT

tar 969d32afca0623f627cdff73d547934b5237b0a3c513bc058600899beccc5a14

(this sample)

  
Delivery method
Distributed via web download

Comments