MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d24cf525214c3b9a331d03c99693d22cfd5e1af5da5b3f310dce9814876d2fbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SheetRAT


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: d24cf525214c3b9a331d03c99693d22cfd5e1af5da5b3f310dce9814876d2fbb
SHA3-384 hash: 88417840e44310394bcecdd1e878c95c7f917626c67bc057323daa2f973cc9aa6d204bf82594e333140ce5a0f5e666fb
SHA1 hash: 8499538914ae3c9308dad097c3bc4ec9a5450692
MD5 hash: e9e49df6a0622c832e6331412b2729d8
humanhash: mango-carbon-seventeen-delaware
File name:SolaraFixNew.bat
Download: download sample
Signature SheetRAT
File size:825'614 bytes
First seen:2025-03-24 13:56:13 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 24576:Z4N9s+jga8kIZDBX8pSx9libYn8ey+1rcdSVO:w
TLSH T1FF056D107E5415F59FACD90A84599B1DE3A0421F66226CBEF603DB21AFBA1C041FF2DB
Magika batch
Reporter JAMESWT_WT
Tags:bat SheetRat

Intelligence


File Origin
# of uploads :
1
# of downloads :
103
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SolaraFixNew.bat
Verdict:
No threats detected
Analysis date:
2025-03-24 13:56:04 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
autorun crysan
Result
Verdict:
Clean
Maliciousness:

Behaviour
Running batch commands
Launching a process
Searching for the window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
certutil cmd evasive lolbin wmic
Result
Verdict:
MALICIOUS
Result
Threat name:
SheetRat
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-03-23 02:49:43 UTC
File Type:
Text (Batch)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
balkanrat
Similar samples:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments