MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9eb046674e605fed5a99e6300c4a4e0bfc9470c4f31b2efebb57932b19e90886. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 11


Intelligence 11 IOCs YARA 17 File information Comments

SHA256 hash: 9eb046674e605fed5a99e6300c4a4e0bfc9470c4f31b2efebb57932b19e90886
SHA3-384 hash: 8d686187ef9cb5e609eadf3f19b6df563fa94725ce97ddd5f64eb4df951b93dbf9fbd86522d11ccec8224914c96534f0
SHA1 hash: 1b59a12c8c44d02dd998c4dbd1e0184865e80ec1
MD5 hash: 1f711fd0600f268dffe5a19e8a4dcfba
humanhash: moon-black-two-colorado
File name:11.13.exe
Download: download sample
Signature ValleyRAT
File size:109'952 bytes
First seen:2026-03-13 04:26:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5d3c0b627d0f2032f4e6d13576e621b5 (2 x ValleyRAT)
ssdeep 3072:375GNDUaunHmshiTBiuJqJnuLLPWpfLTsIih+jhnKIsnT6ss:3o+ILPwDTBih+jUhW
TLSH T147B31806A67D61F9D87A81788AA35B52F7313C194B3C538F8B6446651FA3BD0EF39320
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter Ling
Tags:exe SilverFox Trojan:Win64/PoolInject.FO!MTB ValleyRAT


Avatar
CNGaoLing
This sample has been reviewed by Microsoft researchers and determined to be malware. (Trojan:Win64/PoolInject.FO!MTB)

SilverFox
IOC (Domain zsfvgrf.cn) (IP 54.46.101.216)

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
11.13.exe
Verdict:
Malicious activity
Analysis date:
2026-03-12 16:19:33 UTC
Tags:
valleyrat rat remote silverfox winos

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
injection emotet shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug expired-cert invalid-signature microsoft_visual_cc signed unsafe windows winos
Verdict:
Malicious
Labled as:
Win64/Agent_AGeneric.IOH trojan
Verdict:
Malicious
File Type:
exe x64
Detections:
PDM:Trojan.Win32.Generic Backdoor.Win32.Androm.wbok Backdoor.Androm.HTTP.C&C Trojan-Dropper.Win32.Injector.sb Trojan.Win32.Waldek.sb Trojan.Win32.PoolInject.sba
Gathering data
Threat name:
Win64.Trojan.PoolInject
Status:
Malicious
First seen:
2026-03-13 01:05:08 UTC
File Type:
PE+ (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion
Behaviour
Checks processor information in registry
Delays execution with timeout.exe
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Unpacked files
SH256 hash:
9eb046674e605fed5a99e6300c4a4e0bfc9470c4f31b2efebb57932b19e90886
MD5 hash:
1f711fd0600f268dffe5a19e8a4dcfba
SHA1 hash:
1b59a12c8c44d02dd998c4dbd1e0184865e80ec1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CAS_Malware_Hunting
Author:Michael Reinprecht
Description:DEMO CAS YARA Rules for sample2.exe
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercês
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Trojan_Winos_a60d5880
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

Executable exe 9eb046674e605fed5a99e6300c4a4e0bfc9470c4f31b2efebb57932b19e90886

(this sample)

  
Delivery method
Distributed via web download

Comments