MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c66ba5c68ba12eaf045ed415dfa72ec5d7174970e91b45fda9ebb32e0a37784a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ThemeForestRAT


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: c66ba5c68ba12eaf045ed415dfa72ec5d7174970e91b45fda9ebb32e0a37784a
SHA3-384 hash: 78b78b85596f7d00dd32e3c2cf8e32a53a88257f41ef531275f3839cbfd3d2ba989849b3f2f09b33814f2559f4e402c5
SHA1 hash: 8b78a618c8538214c227ee926bbdb1f73318232f
MD5 hash: fc267b195aac7dd5cdf0d2bb0b47c340
humanhash: ink-arizona-princess-spaghetti
File name:c66ba5c68ba12eaf045ed415dfa72ec5d7174970e91b45fda9ebb32e0a37784a_windows_themeforestrat.bin
Download: download sample
Signature ThemeForestRAT
File size:297'472 bytes
First seen:2025-09-15 14:00:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 1c56888e3a32873a957665cac4e85718 (1 x ThemeForestRAT)
ssdeep 6144:VvIFielYL21nybg521cimI5FZ2TB3W98j:V4YAyb82eix2TZ
TLSH T123547D55B7A411F9EDB7823CC9A69A12D77278124B30C75F03A4875A3F13390AE3EB61
TrID 48.7% (.EXE) Win64 Executable (generic) (10522/11/4)
23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
9.2% (.EXE) Generic Win/DOS Executable (2002/3)
9.2% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter SRT
Tags:exe Lazarus RAT ThemeForestRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
109
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
c66ba5c68ba12eaf045ed415dfa72ec5d7174970e91b45fda9ebb32e0a37784a_windows_themeforestrat.bin
Verdict:
No threats detected
Analysis date:
2025-09-15 14:02:06 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the Windows subdirectories
Creating a file
Searching for synchronization primitives
DNS request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive fingerprint masquerade microsoft_visual_cc wiper
Verdict:
Malicious
File Type:
exe x64
First seen:
2025-09-12T10:10:00Z UTC
Last seen:
2025-09-12T10:10:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Checks processor information in registry
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
c66ba5c68ba12eaf045ed415dfa72ec5d7174970e91b45fda9ebb32e0a37784a
MD5 hash:
fc267b195aac7dd5cdf0d2bb0b47c340
SHA1 hash:
8b78a618c8538214c227ee926bbdb1f73318232f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments