🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c668fdf9cd5bc613c047c64dbc6c1e68b76c178b08a1df57463a9404d2cc4328. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 9


Intelligence 9 IOCs 1 YARA 15 File information Comments

SHA256 hash: c668fdf9cd5bc613c047c64dbc6c1e68b76c178b08a1df57463a9404d2cc4328
SHA3-384 hash: a7d8bafa7b96abaec6141101090088354e5e899ad8c9ddefdf3b6f3a7f4541200cf3f0f8f4609d58e6a4821913cf3a56
SHA1 hash: 0c7618f9eb757018fcd2aebb1aaa597c3dbbdfc8
MD5 hash: c7070dc55dccf091e0ff6a80a2c41c0f
humanhash: utah-oxygen-iowa-network
File name:115Q3????M??.hta
Download: download sample
Signature ValleyRAT
File size:5'571'755 bytes
First seen:2026-09-28 20:15:16 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 12288:KbL/PYur3KmSHFBQFiStbiqaEAr4fQD8nq4iy0F2y3jjyILgB+VhLEnFk7Zx5Q1t:K
TLSH T1CE461CE73102F55EC18543B16F2917E0543ED6189ACA4D0AFA89CF9DA1CDCDB3AAD381
Magika html
Reporter abuse_ch
Tags:hta RAT ValleyRAT


Avatar
abuse_ch
ValleyRAT C2:
108.187.43.208:449

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
108.187.43.208:449 https://threatfox.abuse.ch/ioc/1941228/

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm base64 cmd dropper evasive evasive exploit explorer fingerprint lolbin obfuscated ping reconnaissance
Verdict:
Malicious
File Type:
hta
First seen:
2026-09-27T19:55:00Z UTC
Last seen:
2026-09-29T06:26:00Z UTC
Hits:
~1000
Result
Threat name:
SilverFox Rootkit, ValleyRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Contains functionality to modify Windows User Account Control (UAC) settings
Detected unpacking (creates a PE file in dynamic memory)
Disable UAC(promptonsecuredesktop)
Found malware configuration
Found stalling execution ending in API Sleep call
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Sample is not signed and drops a device driver
Self deletion via cmd or bat file
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious Ping/Del Command Combination
Suricata IDS alerts for network traffic
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Unusual module load detection (module proxying)
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Writes to foreign memory regions
Yara detected SilverFox Rootkit
Yara detected UAC Bypass using CMSTP
Yara detected ValleyRAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1979136 Sample: 115Q3____M__.hta Startdate: 28/09/2026 Architecture: WINDOWS Score: 100 65 Suricata IDS alerts for network traffic 2->65 67 Found malware configuration 2->67 69 Malicious sample detected (through community Yara rule) 2->69 71 8 other signatures 2->71 7 mshta.exe 3 2->7         started        11 explorer.exe 3 2->11         started        13 SvcHostLoader.exe 2->13         started        15 4 other processes 2->15 process3 file4 57 C:\Users\user\...\app_14697342.exe (copy), PE32+ 7->57 dropped 59 C:\Users\user\AppData\...\app_14697342.bin, PE32+ 7->59 dropped 93 Self deletion via cmd or bat file 7->93 17 app_14697342.exe 1 3 7->17         started        21 cmd.exe 1 7->21         started        23 cmd.exe 1 7->23         started        25 SvcHostLoader.exe 11->25         started        27 cmd.exe 1 13->27         started        29 consent.exe 2 15->29         started        31 cmd.exe 15->31         started        signatures5 process6 file7 53 C:\Users\user\AppData\...\~sys_51590.sys, PE32+ 17->53 dropped 55 C:\ProgramData\...\SvcHostLoader.exe, PE32+ 17->55 dropped 73 Sample is not signed and drops a device driver 17->73 75 Contains functionality to modify Windows User Account Control (UAC) settings 17->75 77 Disable UAC(promptonsecuredesktop) 17->77 33 explorer.exe 17->33         started        79 Uses ping.exe to sleep 21->79 81 Uses ping.exe to check the status of other devices and networks 21->81 35 PING.EXE 1 21->35         started        38 conhost.exe 21->38         started        40 conhost.exe 23->40         started        42 PING.EXE 1 23->42         started        83 Multi AV Scanner detection for dropped file 25->83 85 Detected unpacking (creates a PE file in dynamic memory) 25->85 87 Found stalling execution ending in API Sleep call 25->87 91 3 other signatures 25->91 44 SvcHostLoader.exe 3 27->44         started        47 conhost.exe 27->47         started        89 Writes to foreign memory regions 29->89 49 SvcHostLoader.exe 31->49         started        51 conhost.exe 31->51         started        signatures8 process9 dnsIp10 61 127.0.0.1 unknown unknown 35->61 63 108.187.43.208, 443, 449, 49711 ANTBOX1-AS-APAntboxNetworksLimitedHK Hong Kong SAR China 44->63 95 Tries to detect sandboxes / dynamic malware analysis system (Installed program check) 44->95 signatures11
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Html
Result
Malware family:
valleyrat_s2
Score:
  10/10
Tags:
family:valleyrat_s2 backdoor defense_evasion discovery execution persistence trojan
Behaviour
Modifies registry class
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
System policy modification
Enumerates physical storage devices
Executes a command shell one-liner
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Adds Run key to start application
Checks installed software on the system
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Detects ValleyRAT payload
Family: ValleyRat
UAC bypass
Malware Config
C2 Extraction:
108.187.43.208:449
108.187.43.208:443
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CMD_Ping_Localhost
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Gh0stKCP
Author:Netresec
Description:Detects HP-Socket ARQ and KCP implementations, which are used in Gh0stKCP. Forked from @stvemillertime's KCP catchall rule.
Reference:https://netresec.com/?b=259a5af
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:ValleyRAT
Author:NDA0E
Description:Detects ValleyRAT
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Generic_Threat_3055c14a
Author:Elastic Security
Rule name:WinosStager
Author:YungBinary
Description:https://www.esentire.com/blog/winos4-0-online-module-staging-component-used-in-cleversoar-campaign

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments