MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db107694378358951d9f9c5b4bfe99761ef778f63531a10ee2fd4607e79d0c5e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RevengeRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: db107694378358951d9f9c5b4bfe99761ef778f63531a10ee2fd4607e79d0c5e
SHA3-384 hash: 0b9cd93774490ba57bc7f80cfe0b0aaec02569716eef642c9fbab16465dcf33a9ce71516c037a4383483e27171c220d9
SHA1 hash: 78dd72a9982c2adf0c862268fdf1ec45ecea2ee2
MD5 hash: fc73fd996ef3b665fb9aab971de920df
humanhash: friend-carbon-social-lamp
File name:ieRbC8ZH.exe
Download: download sample
Signature RevengeRAT
File size:14'848 bytes
First seen:2020-11-19 18:02:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'658 x AgentTesla, 19'469 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 384:4NVjYTDG8gpk2u5n3XAxvZ9q9vDNEnxcoN1x:4PSxHnAXWvhSL
Threatray 35 similar samples on MalwareBazaar
TLSH 88621A0577DC4739C1ED06BC0CB24226A375E5A7A563D71F1CD884BE8992BC45B21AE8
Reporter pmelson
Tags:exe Revenge RevengeRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'299
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a custom TCP request
Sending a UDP request
DNS request
Using the Windows Management Instrumentation requests
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2020-11-19 18:03:04 UTC
AV detection:
25 of 28 (89.29%)
Threat level:
  5/5
Result
Malware family:
revengerat
Score:
  10/10
Tags:
family:revengerat botnet:clay-root-stub-v1
Behaviour
Checks processor information in registry
Malware Config
C2 Extraction:
clayroot2016.linkpc.net:5555
Unpacked files
SH256 hash:
db107694378358951d9f9c5b4bfe99761ef778f63531a10ee2fd4607e79d0c5e
MD5 hash:
fc73fd996ef3b665fb9aab971de920df
SHA1 hash:
78dd72a9982c2adf0c862268fdf1ec45ecea2ee2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RevengeRAT

Executable exe db107694378358951d9f9c5b4bfe99761ef778f63531a10ee2fd4607e79d0c5e

(this sample)

Comments