MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a643b60556b11d6d85b894148bce93f0547388ec161b58c74a7a28156e6be3da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RevengeRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a643b60556b11d6d85b894148bce93f0547388ec161b58c74a7a28156e6be3da
SHA3-384 hash: 15677c3138e961b24631f4d49ebd6e6d8a8050f4a11ca720872e55820269d56065c0007e9df3b89b1e607b2218e355e1
SHA1 hash: 740031fd9e9a0c8f7129261dea4f7cea9920bd9b
MD5 hash: cfec5b5d14413e1f771b605ee2e678aa
humanhash: september-nine-speaker-delaware
File name:D1vpHZ1a.exe
Download: download sample
Signature RevengeRAT
File size:14'848 bytes
First seen:2020-05-26 13:06:22 UTC
Last seen:2020-06-10 12:34:24 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'663 x AgentTesla, 19'478 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 192:j+8C+EKS0O9ejYTDG8bcp4Ll7SmnieXubWyD9JEBkGxVXT8qoNBRJM:jNVjYTDG8gpXFeXTyD3Enxt1oNW
Threatray 50 similar samples on MalwareBazaar
TLSH 33622909B7EC4339C1BD07BC0CB242256371E5A79A62D71F1CD890FE8992BD45B60BE8
Reporter johannes
Tags:RevengeRAT


Avatar
viql
revengerat via https://pastebin.com/raw/D1vpHZ1a

Intelligence


File Origin
# of uploads :
3
# of downloads :
415
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Rrat
Status:
Malicious
First seen:
2020-05-26 13:36:28 UTC
File Type:
PE (.Net Exe)
AV detection:
28 of 31 (90.32%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Malware Config
C2 Extraction:
127.0.0.1:333
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments