MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d066c9129eaa023a8841cbca3cd3586e217abd3517d193fd432b4a8660cf02c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SheetRAT


Vendor detections: 12


Intelligence 12 IOCs YARA 5 File information Comments

SHA256 hash: d066c9129eaa023a8841cbca3cd3586e217abd3517d193fd432b4a8660cf02c4
SHA3-384 hash: 153156b6028a7958aeb7b61e6d64187c4a805f6c33762e1c9270122d697ab2296fb7d26d22a9b15fe3437dbffaf82f93
SHA1 hash: f2a647751fcea2ada8d454c2eef5193f8ae580d0
MD5 hash: 36358fdd96f1dc6ec7f582e860eb2b84
humanhash: idaho-bakerloo-lithium-sodium
File name:36358fdd96f1dc6ec7f582e860eb2b84.exe
Download: download sample
Signature SheetRAT
File size:10'485'760 bytes
First seen:2026-07-15 06:52:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 12288:vVvJgjTOFJfbjVtcwPggfWDl8QH75X2T+I/kqT1jOS2Uz9xqBbV:pJOTOF5tAguR822T+GkqxjO1B5
TLSH T17FB617652BE64E14E895193D827A2614D732A0F22362B7873B4AF3B14D189CDFD2C7D2
TrID 30.0% (.EXE) Win64 Executable (generic) (6522/11/2)
23.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
9.5% (.EXE) Win16/32 Executable Delphi generic (2072/23)
9.4% (.ICL) Windows Icons Library (generic) (2059/9)
9.3% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter abuse_ch
Tags:exe SheetRat

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
SE SE
Vendor Threat Intelligence
Malware configuration found for:
PostExploitTool SheetRat
Details
Verdict:
Malicious
Score:
99.1%
Tags:
asyncrat virus sage msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Using the Windows Management Instrumentation requests
Сreating synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Creating a file in the Windows directory
Launching cmd.exe command interpreter
Running batch commands
Launching a process
Launching a service
Creating a service
Creating a process from a recently created file
Searching for synchronization primitives
Enabling the 'hidden' option for recently created files
Creating a file
Setting a global event handler
Loading a suspicious library
Creating a file in the system32 subdirectories
Setting browser functions hooks
Enabling autorun for a service
Unauthorized injection to a recently created process
Enabling autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context asyncrat base64 exploit obfuscated overlay reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-09T03:09:00Z UTC
Last seen:
2026-07-16T19:02:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Connects to a pastebin service (likely for C&C)
Contains functionality to capture screen (.Net source)
Creates an undocumented autostart registry key
Creates files in the system32 config directory
Drops executables to the windows directory (C:\Windows) and starts them
Drops large PE files
Hooks files or directories query functions (used to hide files and directories)
Hooks processes query functions (used to hide processes)
Installs a global get message hook
Joe Sandbox ML detected suspicious sample
Modifies the prolog of user mode functions (user mode inline hooks)
Modifies the windows firewall
Multi AV Scanner detection for submitted file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Uses schtasks.exe or at.exe to add and modify task schedules
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1942622 Sample: gxc15pH6mQ.exe Startdate: 15/07/2026 Architecture: WINDOWS Score: 100 85 pastebin.com 2->85 87 eip-terr-na.cdp1.digicert.com.akahost.net 2->87 89 api.ipify.org 2->89 97 Antivirus detection for dropped file 2->97 99 Antivirus / Scanner detection for submitted sample 2->99 101 Multi AV Scanner detection for submitted file 2->101 105 8 other signatures 2->105 11 gxc15pH6mQ.exe 17 7 2->11         started        16 xdwdMalwareDef32.exe 14 3 2->16         started        18 WmiApSrv.exe 18 10 2->18         started        signatures3 103 Connects to a pastebin service (likely for C&C) 85->103 process4 dnsIp5 91 pastebin.com 104.20.29.150, 443, 49701, 49704 CLOUDFLARENET-CloudflareIncUS Canada 11->91 93 api.ipify.org 172.67.74.152, 443, 49702, 49705 CLOUDFLARENET-CloudflareIncUS Canada 11->93 81 C:\Windows\xdwdMalwareDef32.exe, PE32+ 11->81 dropped 111 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 11->111 113 Creates an undocumented autostart registry key 11->113 115 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 11->115 123 4 other signatures 11->123 20 xdwdMalwareDef32.exe 11->20         started        23 cmd.exe 1 11->23         started        25 cmd.exe 1 11->25         started        27 4 other processes 11->27 95 31.77.144.86, 9469 PLUSNETPlusnetworkoperatorinPolandPL Hong Kong SAR China 16->95 83 C:\Windows\System32\...\xdwdMalwareDef64.exe, PE32+ 16->83 dropped 117 Antivirus detection for dropped file 16->117 119 Creates files in the system32 config directory 16->119 121 Queries sensitive Plug and Play Device Information (via WMI, Win32_PnPEntity, often done to detect virtual machines) 16->121 file6 signatures7 process8 signatures9 107 Installs a global get message hook 20->107 29 cmd.exe 20->29         started        31 cmd.exe 20->31         started        33 cmd.exe 20->33         started        41 58 other processes 20->41 109 Uses schtasks.exe or at.exe to add and modify task schedules 23->109 35 conhost.exe 23->35         started        37 conhost.exe 25->37         started        43 2 other processes 25->43 39 conhost.exe 27->39         started        45 2 other processes 27->45 process10 process11 57 5 other processes 29->57 47 conhost.exe 31->47         started        59 3 other processes 31->59 61 4 other processes 33->61 49 Conhost.exe 37->49         started        51 schtasks.exe 41->51         started        53 schtasks.exe 41->53         started        55 schtasks.exe 41->55         started        63 63 other processes 41->63 process12 65 Conhost.exe 51->65         started        67 Conhost.exe 53->67         started        69 Conhost.exe 55->69         started        71 Conhost.exe 63->71         started        73 Conhost.exe 63->73         started        75 Conhost.exe 63->75         started        77 2 other processes 63->77 process13 79 Conhost.exe 65->79         started       
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.91 Win 64 Exe x64
Threat name:
ByteCode-MSIL.Backdoor.AsyncRAT
Status:
Malicious
First seen:
2026-07-09 07:58:30 UTC
File Type:
PE+ (.Net Exe)
Extracted files:
1
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution persistence privilege_escalation
Behaviour
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
Drops file in Windows directory
Launches sc.exe
Drops file in System32 directory
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Checks computer location settings
Creates new service(s)
Event Triggered Execution: Component Object Model Hijacking
Executes dropped EXE
Loads dropped DLL
Modifies WinLogon for persistence
Unpacked files
SH256 hash:
d066c9129eaa023a8841cbca3cd3586e217abd3517d193fd432b4a8660cf02c4
MD5 hash:
36358fdd96f1dc6ec7f582e860eb2b84
SHA1 hash:
f2a647751fcea2ada8d454c2eef5193f8ae580d0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_SUSPICIOUS_EXE_RawPaste_URL
Author:ditekSHen
Description:Detects executables (downlaoders) containing URLs to raw contents of a paste
Rule name:NET
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments