MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureRAT


Vendor detections: 8


Intelligence 8 IOCs YARA 7 File information Comments

SHA256 hash: b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8e
SHA3-384 hash: bb61ca06207fb5a3ae16c0df5d5cd23ed34fead2fada5ddf7240fdc74e1969e7d51e64e18f78e31c23ee42a2ab6a6a82
SHA1 hash: db1c820bd6a3540c4df1591787f17237dcb30e4b
MD5 hash: aff1f5eb09bed6d85dd9a7714c18e9d7
humanhash: social-jig-pizza-mexico
File name:aff1f5eb09bed6d85dd9a7714c18e9d7.exe
Download: download sample
Signature PureRAT
File size:638'464 bytes
First seen:2026-08-20 06:15:32 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'197 x AgentTesla, 20'351 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 12288:0PhujNqyf4FH/gMdAT7QbnKc3CKVRkWODp2aX0x6omBPpRX:0PhuogMdm7QbKc3CIOVYcBP
TLSH T182D49D1B73A28E21D2840236C5E7550583F165877A7BE70E7581239B2D433FAEE8B397
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:exe PureHVNC PureRAT RAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
SE SE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Launching a process
Using the Windows Management Instrumentation requests
Connection attempt to an infection source
Creating a window
Creating a file in the %temp% directory
Setting a keyboard event handler
Query of malicious DNS domain
Sending a TCP request to an infection source
Enabling autorun by creating a file
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Bypasses PowerShell execution policy
Encrypted powershell cmdline option found
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries memory information (via WMI often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive physical memory information (via WMI, Win32_PhysicalMemory, often done to detect virtual machines)
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Suricata IDS alerts for network traffic
Tries to harvest and steal Bitcoin Wallet information
Uses dynamic DNS services
Yara detected MSIL Injector
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win32.Backdoor.AsyncRAT
Status:
Malicious
First seen:
2026-07-31 00:49:01 UTC
File Type:
PE (.Net Exe)
Extracted files:
1
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution spyware stealer
Behaviour
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Reads user/profile data of web browsers
Unpacked files
SH256 hash:
b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8e
MD5 hash:
aff1f5eb09bed6d85dd9a7714c18e9d7
SHA1 hash:
db1c820bd6a3540c4df1591787f17237dcb30e4b
SH256 hash:
76af1414f25aae5715b2583d7d4c6744d7636a06f7e681e9eb5b1ea017a6096d
MD5 hash:
3d45f1822ed0d6f13487df6beafe0718
SHA1 hash:
261367dfa8d6ff0bb8ede7b7ac679cbb7da9ed5a
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
8d063e716004d53d6283d1dc5dd2361a96355df09903c8375f53d71ac49445c4
MD5 hash:
beedfe13564e371dfead67a8c177e333
SHA1 hash:
dd97cb51474b45b9c7f4d6fcb1d0bf4ca65b9a41
SH256 hash:
4a83def00e47e150e2107765706b9092883f6bbffcded38afa2f1e912976aa70
MD5 hash:
a9fc76d07beb3715df85d34f00c870fd
SHA1 hash:
e3717426c5613091ec2bb0d7c716020809874317
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Lumma_Stealer_Detection
Author:ashizZz
Description:Detects a specific Lumma Stealer malware sample using unique strings and behaviors
Reference:https://seanthegeek.net/posts/compromized-store-spread-lumma-stealer-using-fake-captcha/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments