MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc48314e9b051ed39d848004bd73f3fe42fa00c121c868134af71b96e24c651b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PureRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 3 File information Comments

SHA256 hash: dc48314e9b051ed39d848004bd73f3fe42fa00c121c868134af71b96e24c651b
SHA3-384 hash: 35b5b83a3b5bf63a8d40dcaf89f4a8bd4de2755b06f40d08e129f1c534af4b3783478134e3092fd34ef3fc0259628ea4
SHA1 hash: 31322e19cb24cc87a9dc27b357812ad44ba63d1c
MD5 hash: fade308fbb50fd51b26462387eb36b39
humanhash: red-hot-venus-timing
File name:photov_532524973609.zip
Download: download sample
Signature PureRAT
File size:1'057 bytes
First seen:2026-07-27 06:17:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24:9RaEqD3HA4SG7yM37EH39HymSubdWqpUFNDcaE1ByHtn:9YrD3gXGeX9HyPOW4kumtn
TLSH T1D611B5E1115C0C70CC3BC1F518DFCFFA35B3919130424211420D1AB93D21D4A3C08EA3
Magika zip
Reporter JAMESWT_WT
Tags:PureRAT zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
IT IT
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:videoa_558129975434.mp4
File size:1'011 bytes
SHA256 hash: b7bde5f19cac9a1a67b9d17cd5cafa08172da5f9d70931799662c84b82739c81
MD5 hash: 2f9c13ba1eb0efbd108b2d5ce2ebd097
MIME type:application/octet-stream
Signature PureRAT
File name:photov_532524973609.lnk
File size:1'715 bytes
SHA256 hash: 4dd705ba0578eae26a1938619314c212c098c4f86f7498422313b4ea2f343f8a
MD5 hash: a5b67775dc9d542467f372ceccd73c3d
MIME type:application/octet-stream
Signature PureRAT
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
LNK File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive powershell
Verdict:
Unknown
File Type:
zip
First seen:
2026-07-28T20:34:00Z UTC
Last seen:
2026-07-29T02:26:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
3 match(es)
Tags:
Batch Command DeObfuscated Execution: CMD in LNK Execution: PowerShell in LNK LNK LOLBin LOLBin:%COMSPEC% Malicious PowerShell PowerShell Call T1027 T1059.001 T1059.003 T1202: Indirect Command Execution T1204.002 Zip Archive
Threat name:
Shortcut.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-27 06:33:43 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
adware execution spyware
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Execution_in_LNK
Author:@bartblaze
Description:Identifies execution artefacts in shortcut (LNK) files.
Rule name:SUSP_ZIP_LNK_PhishAttachment
Author:ignacior
Description:Detects suspicius tiny ZIP files with malicious lnk files
Reference:Internal Research
Rule name:SUSP_ZIP_LNK_PhishAttachment_Pattern_Jun22_1
Author:Florian Roth (Nextron Systems)
Description:Detects suspicious tiny ZIP files with phishing attachment characteristics
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments