MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d56f2c5e247c360ae7cc2d2a942f2586edd7688f2de3f812c02fcd966abdc0e1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Xtrat


Vendor detections: 10


Intelligence 10 IOCs YARA 5 File information Comments

SHA256 hash: d56f2c5e247c360ae7cc2d2a942f2586edd7688f2de3f812c02fcd966abdc0e1
SHA3-384 hash: 38986701489c1647730971e32e50e797dd18657304ee762361308b0315082d4fce230fdd3142f19a29b283581ffd645a
SHA1 hash: 0d4412075c43f98e3dada67e2f74a8690a51b221
MD5 hash: f5ac07c85a5d2dba04e3cb7fcd63e793
humanhash: paris-don-wolfram-fanta
File name:Backdoor.Win32.Xtreme.aynt-d56f2c5e247c360ae7cc2d2a942f2586edd7688f2de3f812c02fcd966abdc0e1
Download: download sample
Signature Xtrat
File size:21'504 bytes
First seen:2022-08-31 02:16:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0cbfef437419d71a55a704236c98a733 (2 x Xtrat)
ssdeep 384:tIdmF+Ti213fEF9QZd/cBr5M/gOjkaS4s/1k5YiZNlvpQ4xR1nKGm5UpLR:tIsF81fG9QveLOYTe5YiJpQKR1nKt50
TLSH T183A2E12EBB0F0404E9C5677CC290F10AA77A3E72A52B66749E7D12571DBE4D02E7E01D
TrID 35.6% (.EXE) UPX compressed Win32 Executable (27066/9/6)
35.0% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
8.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
5.9% (.EXE) Win32 Executable (generic) (4505/5/1)
3.9% (.MZP) WinArchiver Mountable compressed Archive (3000/1)
Reporter OSimao
Tags:exe Xtrat

Intelligence


File Origin
# of uploads :
1
# of downloads :
223
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Launching a process
Unauthorized injection to a recently created process
Creating a process from a recently created file
Creating a process with a hidden window
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
packed rat shell32.dll xtreme
Result
Threat name:
Xtreme RAT
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Contains functionality to register a low level keyboard hook
Creates a thread in another existing process (thread injection)
Creates an undocumented autostart registry key
Creates autostart registry keys to launch java
Exploit detected, runtime environment starts unknown processes
Found evasive API chain (may stop execution after checking mutex)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Writes to foreign memory regions
Yara detected Xtreme RAT
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 693629 Sample: Bl185ylS4J.exe Startdate: 31/08/2022 Architecture: WINDOWS Score: 100 95 Malicious sample detected (through community Yara rule) 2->95 97 Antivirus / Scanner detection for submitted sample 2->97 99 Multi AV Scanner detection for submitted file 2->99 101 2 other signatures 2->101 10 Bl185ylS4J.exe 5 6 2->10         started        14 java.exe 3 2->14         started        16 java.exe 3 2->16         started        18 java.exe 3 2->18         started        process3 file4 89 C:\Users\user\AppData\Roaming\...\java.exe, PE32 10->89 dropped 91 C:\Users\user\...\java.exe:Zone.Identifier, ASCII 10->91 dropped 143 Creates an undocumented autostart registry key 10->143 145 Creates autostart registry keys to launch java 10->145 147 Writes to foreign memory regions 10->147 149 Creates a thread in another existing process (thread injection) 10->149 20 svchost.exe 1 10->20         started        23 java.exe 3 10->23         started        25 chrome.exe 10->25         started        35 7 other processes 10->35 151 Allocates memory in foreign processes 14->151 153 Injects a PE file into a foreign processes 14->153 37 7 other processes 14->37 27 chrome.exe 16->27         started        29 chrome.exe 16->29         started        31 chrome.exe 16->31         started        33 chrome.exe 18->33         started        signatures5 process6 signatures7 109 Found evasive API chain (may stop execution after checking mutex) 20->109 111 Contains functionality to inject threads in other processes 20->111 113 Contains functionality to inject code into remote processes 20->113 115 Contains functionality to register a low level keyboard hook 20->115 39 java.exe 20->39         started        42 java.exe 3 20->42         started        44 java.exe 20->44         started        48 13 other processes 20->48 117 Writes to foreign memory regions 23->117 119 Allocates memory in foreign processes 23->119 121 Injects a PE file into a foreign processes 23->121 46 chrome.exe 23->46         started        process8 dnsIp9 129 Writes to foreign memory regions 39->129 131 Allocates memory in foreign processes 39->131 133 Injects a PE file into a foreign processes 39->133 51 java.exe 39->51         started        64 8 other processes 39->64 135 Antivirus detection for dropped file 42->135 137 Multi AV Scanner detection for dropped file 42->137 139 Machine Learning detection for dropped file 42->139 141 Exploit detected, runtime environment starts unknown processes 42->141 54 chrome.exe 42->54         started        56 chrome.exe 42->56         started        58 java.exe 44->58         started        66 8 other processes 44->66 93 192.168.2.1 unknown unknown 48->93 60 chrome.exe 48->60         started        62 chrome.exe 48->62         started        68 59 other processes 48->68 signatures10 process11 signatures12 103 Writes to foreign memory regions 51->103 105 Allocates memory in foreign processes 51->105 107 Injects a PE file into a foreign processes 51->107 70 java.exe 51->70         started        73 chrome.exe 51->73         started        75 chrome.exe 51->75         started        79 6 other processes 51->79 77 chrome.exe 58->77         started        process13 signatures14 123 Writes to foreign memory regions 70->123 125 Allocates memory in foreign processes 70->125 127 Injects a PE file into a foreign processes 70->127 81 chrome.exe 70->81         started        83 chrome.exe 70->83         started        85 chrome.exe 70->85         started        87 6 other processes 70->87 process15
Threat name:
Win32.Backdoor.XtremeRAT
Status:
Malicious
First seen:
2013-11-12 18:17:00 UTC
File Type:
PE (Exe)
Extracted files:
1
AV detection:
25 of 25 (100.00%)
Threat level:
  5/5
Result
Malware family:
xtremerat
Score:
  10/10
Tags:
family:xtremerat persistence rat spyware upx
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Adds Run key to start application
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
Modifies Installed Components in the registry
UPX packed file
Detect XtremeRAT payload
XtremeRAT
Malware Config
C2 Extraction:
maxam.no-ip.org
Unpacked files
SH256 hash:
e71c4c90c689a9cc0f876285be7c9e690a72f623ab4d78998d818deaaebeac91
MD5 hash:
f0bd7eb5275b861c24a6edd2c05e9b98
SHA1 hash:
0666718062634fd3d689956d0526a9b6c275d08e
Detections:
win_extreme_rat_auto win_extreme_rat_w0
SH256 hash:
d56f2c5e247c360ae7cc2d2a942f2586edd7688f2de3f812c02fcd966abdc0e1
MD5 hash:
f5ac07c85a5d2dba04e3cb7fcd63e793
SHA1 hash:
0d4412075c43f98e3dada67e2f74a8690a51b221
Malware family:
XtremeRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:RAT_Xtreme
Author:Kevin Breen <kevin@techanarchy.net>
Description:Detects Xtreme RAT
Reference:http://malwareconfig.com/stats/Xtreme
Rule name:win_extreme_rat_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator
Rule name:win_extreme_rat_w0
Author:Jean-Philippe Teissier / @Jipe_
Description:Xtrem RAT v3.5
Rule name:Xtreme_Sep17_1
Author:Florian Roth
Description:Detects XTREME sample analyzed in September 2017
Reference:Internal Research
Rule name:Xtreme_Sep17_1_RID2C05
Author:Florian Roth
Description:Detects XTREME sample analyzed in September 2017
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments