MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9dd2738abd8d9e66c00c2fe7affd710869b5a3232de632c00f5e67fd541cf39. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 15


Intelligence 15 IOCs YARA 31 File information Comments

SHA256 hash: c9dd2738abd8d9e66c00c2fe7affd710869b5a3232de632c00f5e67fd541cf39
SHA3-384 hash: 2b8c5fd2e312537a1fac171d4ea06bca56037ddb5bfe0edd296e48149d1ef596aedad2cc9a220be045e99b70cef43a10
SHA1 hash: d32bce7bdaae8b09c87e99657338ff8ac1befadd
MD5 hash: 6fdfafd6ee99b1da17f1a01be789957d
humanhash: five-batman-summer-autumn
File name:suf_launch.exe
Download: download sample
Signature ValleyRAT
File size:15'067'907 bytes
First seen:2026-07-24 07:34:29 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 6323d82b808d068b6ab4eaefb7c2594a (2 x ValleyRAT)
ssdeep 196608:mCj1QNMep94Esfo0CiU9Twg765T2L9FLOyomFHKnPPYy0ZFms4I:tB2p1SHW9qyF77ZFms
TLSH T175E6BE12FBE840F5D0BF82318966671AD2F6BD41173087CB52946A6E6F337C11D3AA63
TrID 34.6% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
25.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
13.7% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
5.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
5.4% (.EXE) Win64 Executable (generic) (6522/11/2)
Magika pebin
dhash icon fadadac2a2b8c4e4 (21 x ValleyRAT, 11 x Nitol, 5 x Gh0stRAT)
Reporter zhuzhu0009
Tags:exe SilverFox ValleyRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
JP JP
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
25524591411.zip
Verdict:
Malicious activity
Analysis date:
2026-07-23 09:42:04 UTC
Tags:
silverfox backdoor payload valleyrat rat winos

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Searching for synchronization primitives
Creating a process from a recently created file
Creating a window
Deleting a recently created file
Creating a file in the Program Files subdirectories
Searching for the window
Сreating synchronization primitives
Launching a process
Creating a process with a hidden window
Unauthorized injection to a recently created process
Unauthorized injection to a recently created process by context flags manipulation
Connection attempt to an infection source
Sending a TCP request to an infection source
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun by creating a file
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context adaptive-context anti-debug base64 crypto explorer fingerprint fingerprint installer installer installer-heuristic lolbin microsoft_visual_cc msiexec obfuscated overlay packed packed reconnaissance regsvr32 runonce xor-pe
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-22T13:14:00Z UTC
Last seen:
2026-07-23T19:38:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-23 00:04:08 UTC
File Type:
PE+ (Exe)
Extracted files:
967
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
valleyrat_s2
Score:
  10/10
Tags:
family:valleyrat_s2 backdoor discovery execution persistence
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Suspicious use of SetThreadContext
Adds Run key to start application
Checks installed software on the system
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Detects ValleyRAT payload
Family: ValleyRat
Malware Config
C2 Extraction:
23.226.57.16:771
127.0.0.1:80
Unpacked files
SH256 hash:
c9dd2738abd8d9e66c00c2fe7affd710869b5a3232de632c00f5e67fd541cf39
MD5 hash:
6fdfafd6ee99b1da17f1a01be789957d
SHA1 hash:
d32bce7bdaae8b09c87e99657338ff8ac1befadd
SH256 hash:
85328d4ce8297d0734df0cf7a55cb573e98f5aa69d9fd5de7ee3243ac883b427
MD5 hash:
33f9b5d6439e5e5d022763c0cbbd01ad
SHA1 hash:
a5a54326d29c6bcd24696ba4f3768fc2d0842b31
SH256 hash:
1675b15b679c28cf84dfe893cb34e84601c50736433cc7fd8723c48a6f31c782
MD5 hash:
faea4a5d8f672ea62ea571c44cd3b26d
SHA1 hash:
ae5c5cae23d11deb4395966db1199b4358fa368d
SH256 hash:
2118a36f32de1930c0a918606036191b38c19e07c69828bbfd0d63ec169f3d90
MD5 hash:
b88916731af21fe7dfd22c37e29a9a03
SHA1 hash:
c011d611887829957b88a249cbfb4a3dad333b2b
SH256 hash:
71a357e77433b7e28cfb3d29318c10138a3d60e0396ce0e49baff55e0e9e6cd3
MD5 hash:
13e8b154b122fc8ae211b7a98d5c9734
SHA1 hash:
a2daa3d1d6f967e752f5d3447c87871f909aa6ad
SH256 hash:
9fe8961a71bf2f7006bc32ba0623dd77367a79608d8f468eb685080bb4278d2c
MD5 hash:
a3a63673d8d5d02f8c9f783c0c50cd41
SHA1 hash:
ac0ed372c8430ad637bd720d1db7c98a5b1c16b3
SH256 hash:
ec59fd460e8d4a7b1cfb2d7ad18edf9e2b9c9863831b0fe1ac2fbbae6eb99fc2
MD5 hash:
9235d0a7a5c2a56677de4f41a22af57d
SHA1 hash:
e656585f5221b48a02ff5379026f1abb0d1ce70f
SH256 hash:
5dd0f68b40fa2806c7e289f0d73200dcff25edf252dfd74f0c2dd98f2e3ac498
MD5 hash:
8d417adf27c305d779bc1bc74224508b
SHA1 hash:
378fe584b1a06e7465c3104270ba509838e01038
SH256 hash:
7940f7fb120681cc7da7d980c3fac3ac08c75dbd9d5c16bd60a7999c1672b289
MD5 hash:
f7cc1935719abb33636d4bdcae553e8c
SHA1 hash:
c3edd771d231c73c4e51bf2797228d3a2686fe85
SH256 hash:
63e1985a37d5993d170373bc28d067c13c1541ca2b63968b82e35eaacd927b49
MD5 hash:
3e9a33113d663d8bd5ed38858e669652
SHA1 hash:
1292dc7ffc35a1ef2b761672361bcffa7483169e
SH256 hash:
696eef2f7c85a9fe768a991ebd7e84d24dceda7d6e93ff7ad2999d4a460b31b1
MD5 hash:
9d204cfbc350a9d5da2839c3cff192e6
SHA1 hash:
076cd3c50b8352cf0480c917a92abb876cdf635f
SH256 hash:
23c7b86e7378c7ff97061bd2cf0d2e59e588033c582d4a630e922193a7fc2be3
MD5 hash:
d39706af792134b2ceb3432f97ad5d04
SHA1 hash:
59cef504e2c03bdf15d300e0721160d045d9d4ed
SH256 hash:
2f29036b30a998b1c9939c47594511b296007e981b86ad98fab514434c6ccab7
MD5 hash:
258f1216c4ddb74ad42e09b5d184be4f
SHA1 hash:
935aab6589297dfebf01fa1b8dabbcd2189e2f07
SH256 hash:
a2ac851f35066c2f13a7452b7a9a3fee05bfb42907ae77a6b85b212a2227fc36
MD5 hash:
686b224b4987c22b153fbb545fee9657
SHA1 hash:
684ee9f018fbb0bbf6ffa590f3782ba49d5d096c
SH256 hash:
2ec6ab28d982e158703424153e0c50e5430edf90f49c4d42b019b4ac24c3aa55
MD5 hash:
c6bc911c13e09345c4dcd4190cdcca1b
SHA1 hash:
5ef3bf14b1747e88dbd5d3e3d6c2fe1da31520ee
SH256 hash:
adc27c290b7dfb75cfddae01818e5e3af152add60185d17cbe2652a547272053
MD5 hash:
80704cd1adc3a7a9d084487fa028a4b7
SHA1 hash:
5a10fe23a6c9a029976c65257c95ee74fcfe976d
Malware family:
ValleyRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Capability_Embedded_Lua
Author:Obscurity Labs LLC
Description:Detects embedded Lua engines by looking for multiple Lua API symbols or env-var hooks
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:FormhookB
Author:kevoreilly
Description:Formbook Anti-hook Bypass
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:GenericGh0st
Author:Still
Rule name:Gh0stKCP
Author:Netresec
Description:Detects HP-Socket ARQ and KCP implementations, which are used in Gh0stKCP. Forked from @stvemillertime's KCP catchall rule.
Reference:https://netresec.com/?b=259a5af
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:ValleyRAT
Author:NDA0E
Description:Detects ValleyRAT
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Generic_Threat_4b0b73ce
Author:Elastic Security
Rule name:WinosStager
Author:YungBinary
Description:https://www.esentire.com/blog/winos4-0-online-module-staging-component-used-in-cleversoar-campaign
Rule name:win_winos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.winos.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments