MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bac13f55cd0c9230ff905f6840388e86161ea8d39d791bd66108366494f75061. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BitRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: bac13f55cd0c9230ff905f6840388e86161ea8d39d791bd66108366494f75061
SHA3-384 hash: df33d9d6f3ff6b2ef7a4a7d352011fe19090055d97fc5b31b205deea8660a01477457b420b5a46451c735394f798ae1b
SHA1 hash: b10f65dd683899efbd04d5d424e7946e5c55caee
MD5 hash: ebe1da7d5d4b00cc9648e4b3232ca786
humanhash: king-cola-harry-jersey
File name:Check#85290.zip
Download: download sample
Signature BitRAT
File size:1'921'698 bytes
First seen:2022-04-15 15:13:25 UTC
Last seen:2022-04-20 10:22:25 UTC
File type: zip
MIME type:application/zip
ssdeep 49152:sMq42s4m4uIcK5M/Eo2Eq9bo7Ys7iv6PFa:fH2uIzM1H0okwiy9a
TLSH T17F9533C2061231C3E12CD4BE98F055A7FBD0DE6A4981D7DA11A79E64A3FAD5CBCB3508
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter proxylife
Tags:BitRAT exe iso zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
581
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2022-04-15 15:14:55 UTC
File Type:
Binary (Archive)
Extracted files:
17
AV detection:
6 of 41 (14.63%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:bitrat trojan upx
Behaviour
Creates scheduled task(s)
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Executes dropped EXE
UPX packed file
BitRAT
Malware Config
C2 Extraction:
bitratnew9100.duckdns.org:9100
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments