MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6856bbd7fdff4f2c068a73fee87f5498f69d5fe4f6caf5370e851811ef70a3a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



OverlordRAT


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments

SHA256 hash: c6856bbd7fdff4f2c068a73fee87f5498f69d5fe4f6caf5370e851811ef70a3a
SHA3-384 hash: 525e6fe1acd856eed356ca58adc0c927a0b0d2693353c2964d63a33388b6ad4f6a94ed4dc1b29d6a9619aacefd3944d3
SHA1 hash: 40617d93a616517d9a798c5871854a4db5c741a0
MD5 hash: 27addb17de726ba7c3e0938ce1c7063e
humanhash: diet-uncle-batman-monkey
File name:FLStudio2025.zip
Download: download sample
Signature OverlordRAT
File size:12'901'749 bytes
First seen:2026-07-21 07:51:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 2026
ssdeep 393216:BYWc+5Db/3dU7XSsPHH1yJhISvvvSoQRcCYk:Bxc+5Db/NU7XSsHH1GhISv87
TLSH T121D633BF59127D6EFB1CC0D8C34BA442BF492E2C71560FC115DCD619E2B622A7249EB2
Magika zip
Reporter aachum
Tags:download-windows-update-live file-pumped OverlordRAT pw-2026 zip


Avatar
iamaachum
https://friendihelp.info/

C2: download-windows-update.live (151.243.113.94:5173)

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
ES ES
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Password - 2026.txt
File size:1'189 bytes
SHA256 hash: 9865aae47ed50caf39ba0458e4d3d1f6e2364bb67ac8cf03786a4c20a38508f0
MD5 hash: 56bebe3bf545a24e5092b4f30d772a3e
MIME type:text/plain
Signature OverlordRAT
File name:FLStudio2025 Crack.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:945'146'880 bytes
SHA256 hash: 9f606d1a99fd594993bb3f6573bc55263cf3e265a1c70fc8260ed979a571bec3
MD5 hash: e3796d9bfcf652e0441dff193fcbf5dc
De-pumped file size:12'049'408 bytes (Vs. original size of 945'146'880 bytes)
De-pumped SHA256 hash: 3148ffe9917d2aa33cf61f1f2858ae35d659fedcdc15a2dead0cb6e4792579cd
De-pumped MD5 hash: 4a2a776bed68a7ac1fa2b07a8f6cd7ae
MIME type:application/x-dosexec
Signature OverlordRAT
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Zip Archive
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-21 07:52:41 UTC
File Type:
Binary (Archive)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence spyware stealer upx
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Network Configuration Discovery: Wi-Fi Discovery
System Time Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
UPX packed file
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:NET
Author:malware-lu
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:win32_dotnet_form_obfuscate
Author:Reedus0
Description:Rule for detecting .NET form obfuscate malware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

OverlordRAT

zip c6856bbd7fdff4f2c068a73fee87f5498f69d5fe4f6caf5370e851811ef70a3a

(this sample)

Comments