MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9fdfc80a452df13292b647a9b9ea6362420261fdd0839039b207ec8c3d6c807. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RevengeRAT


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: c9fdfc80a452df13292b647a9b9ea6362420261fdd0839039b207ec8c3d6c807
SHA3-384 hash: 5937b165da590e1d63db3443668f801b2e89a82d0d49f2ce499d9381752866c0ce21c8524410af1d66d0dcbabfb84801
SHA1 hash: 60a1630b9e0af215709f87598194af637f71d074
MD5 hash: 8e5b8045d8b15a615c84049d95a795ed
humanhash: king-michigan-spring-sweet
File name:zgZBQr1M.exe
Download: download sample
Signature RevengeRAT
File size:14'848 bytes
First seen:2020-10-30 18:02:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'663 x AgentTesla, 19'478 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 192:2+8C+EKS0O9ejYTDG8bcp4LlSwinieXubWyD9JEBkGxVXpqoNbRJI:2NVjYTDG8gpKJeXTyD3EnxaoNs
Threatray 34 similar samples on MalwareBazaar
TLSH 01622A09B7EC4339C1BD07BC0DB242356371E5A79A62D71F1CD890FA8992BD45B60BE8
Reporter pmelson
Tags:exe Revenge RevengeRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
579
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
RevengeRAT
Detection:
malicious
Classification:
troj.evad
Score:
72 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Potential time zone aware malware
Yara detected RevengeRAT
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.RevengeRAT
Status:
Malicious
First seen:
2020-10-30 18:04:04 UTC
AV detection:
27 of 29 (93.10%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Malware Config
C2 Extraction:
103.82.249.79:5556
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RevengeRAT

Executable exe c9fdfc80a452df13292b647a9b9ea6362420261fdd0839039b207ec8c3d6c807

(this sample)

Comments