🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a58f5fe338e416dbc8cf88b0b3cabebc5ba2f6ae632e50e703127519331660fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 10


Intelligence 10 IOCs YARA 8 File information Comments

SHA256 hash: a58f5fe338e416dbc8cf88b0b3cabebc5ba2f6ae632e50e703127519331660fc
SHA3-384 hash: d0981cc44149e1c2c1b7d4fd3c093d6527bfe804ff849f6cb210628d4371d971480f1186fe37081de38f06e30d021c72
SHA1 hash: 2c760321782a419ada907cb66b2653f6e16ff17f
MD5 hash: cd4247e33148b91be70282885447f757
humanhash: may-fillet-hawaii-shade
File name:156.247.41.88_1357.exe
Download: download sample
Signature ValleyRAT
File size:7'385'088 bytes
First seen:2026-09-23 14:07:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash a46cc72b550adb245047c9a14f95beb2 (1 x ValleyRAT)
ssdeep 196608:Tzb3YCea7gQ1Oqk0AxVSN4zwl2IdlUNbR:DCfxVo4zg2IjyR
TLSH T19576D03BD6AAC5EDC856D435A5A55B33A1703C0E85329177E7C21F242EB6328CEBD708
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter Ling
Tags:exe SilverFox Trojan/SilverFox.sad ValleyRAT


Avatar
CNGaoLing
156.247.41.88_1357.exe

Trojan/SilverFox.sad
IOC (IP 156.247.41.88:2222)

Intelligence


File Origin
# of uploads :
1
# of downloads :
194
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
156.247.41.88_1357.exe
Verdict:
Malicious activity
Analysis date:
2026-09-23 13:40:17 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Using the Windows Management Instrumentation requests
Connection attempt
Sending an HTTP POST request
Creating a file
Launching the default Windows debugger (dwwin.exe)
Moving of the original file
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug anti-vm expired-cert fingerprint fingerprint microsoft_visual_cc overlay packed packed reconnaissance
Verdict:
Malicious
Labled as:
Win64/Agent_AGeneric.RIH trojan
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-23T01:09:00Z UTC
Last seen:
2026-09-25T11:17:00Z UTC
Hits:
~100
Detections:
VHO:Trojan-Spy.Win32.Stealer.gen PDM:Trojan.Win32.Generic HackTool.Multi.AmsiETWPatch.sb HEUR:Trojan.Win64.Generic
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Agentagen
Status:
Malicious
First seen:
2026-09-23 08:19:43 UTC
File Type:
PE+ (Exe)
Extracted files:
710
AV detection:
27 of 38 (71.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
discovery
Behaviour
Checks processor information in registry
Modifies data under HKEY_USERS
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: RenamesItself
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Checks installed software on the system
Unpacked files
SH256 hash:
a58f5fe338e416dbc8cf88b0b3cabebc5ba2f6ae632e50e703127519331660fc
MD5 hash:
cd4247e33148b91be70282885447f757
SHA1 hash:
2c760321782a419ada907cb66b2653f6e16ff17f
SH256 hash:
b893bda254224c81374f0ebaaec9d4ec4e9cfc3d13baab068ad2d6c72e6ce834
MD5 hash:
a857ee5d9e962bcc68e18605ba156fe3
SHA1 hash:
e6e9d0cea0485dec784f7e63cb1036878119dc24
SH256 hash:
a206880c4f2ac5f1511e76860d7607dcda8c831f9dff0f3c10632bdc6736d92b
MD5 hash:
46c89239a97ed2cf67e6afb5d332d553
SHA1 hash:
7f68b1c454cf3160b4c2e3f66449a905b3d3938a
SH256 hash:
b709217a21c305a9d658d3c7db6defc61a8d9c5ab7a122f434006640cfba4ae1
MD5 hash:
0abec55df79894b5c4434cb9e6b4bbc4
SHA1 hash:
12a16269830c6fe3782909f9fd501841dbf2cb39
SH256 hash:
f4953bebeb4b71f3f83e4684c5349b0ee9263499df3cc0b2be830ef2c478d50a
MD5 hash:
85026cfba1afed081a84f70c3cf46815
SHA1 hash:
4231a9a70229fe7a6f8aa92109002caeb642a8ce
SH256 hash:
f8391b78ecee7417bd45735e715fd6c676d967367af322c047e85feba5c69f15
MD5 hash:
b81c1256137dcd56e9b71688946de7de
SHA1 hash:
a408d1f6542cefe293eabf55a738a433e4effd29
SH256 hash:
ff1ab67a25b624a63baf8c44632d2952c64d3ec069da2ed66c28d2071eb48e1e
MD5 hash:
d7ed42308087a1da39030138d9287a18
SHA1 hash:
8580370cc1be73174e1cf00d4f8e430faaf4b7e8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TigerRAT_pe_yaraify
Author:hunts-yara-code
Description:YARAify-tightened byte rule from 9 sample(s) -- VERIFY hits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

Executable exe a58f5fe338e416dbc8cf88b0b3cabebc5ba2f6ae632e50e703127519331660fc

(this sample)

  
Delivery method
Distributed via web download

Comments