🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e27467f7fdfa721e917384542ce10cc6108dfd78df14e23872cf8df916e0b8c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ROKRAT


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments

SHA256 hash: e27467f7fdfa721e917384542ce10cc6108dfd78df14e23872cf8df916e0b8c6
SHA3-384 hash: 757941c2a474f4a49c64a3ce249953341b1a817de120564dd647e3536016b49f10cfc90ef4482b2dbbf6ba3080d90f68
SHA1 hash: c53bdf6c05c13186a622ed9fd67f9edf2662bd47
MD5 hash: a2ee8d2aa9f79551eb5dd8f9610ad557
humanhash: july-double-arkansas-failed
File name:e27467f7fdfa721e917384542ce10cc6108dfd78df14e23872cf8df916e0b8c6
Download: download sample
Signature ROKRAT
File size:927'744 bytes
First seen:2025-08-06 06:23:04 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 12c108d3839179b797c5f5561d51c698 (2 x ROKRAT)
ssdeep 12288:4VYF1aOsXa8YQmCu154m2h6IqtkkiofjzJaVKwi0aK2avMeqxga79:dF1PsKXQmTC6IqtbiofjlYz8SM
Threatray 2 similar samples on MalwareBazaar
TLSH T10E159D41E720BDDFFF4155785D883B3D9A0A26DC0F7C34AD7D8A0845B9B34A9A601B8E
TrID 32.2% (.EXE) Win64 Executable (generic) (10522/11/4)
20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
15.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
13.7% (.EXE) Win32 Executable (generic) (4504/4/1)
6.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter KodaDr
Tags:APT37 dll RokRat

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
RU RU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
vmdetect
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file
Loading a suspicious library
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm anti-vm base64 crypto evasive fingerprint fingerprint microsoft_visual_cc obfuscated rokrat smb xor-pe
Malware family:
Magnitude EK
Verdict:
Malicious
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) Win 32 Exe x86
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2025-07-13 03:52:00 UTC
File Type:
PE (Dll)
Extracted files:
7
AV detection:
20 of 36 (55.56%)
Threat level:
  2/5
Verdict:
malicious
Label(s):
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Loads dropped DLL
Unpacked files
SH256 hash:
e27467f7fdfa721e917384542ce10cc6108dfd78df14e23872cf8df916e0b8c6
MD5 hash:
a2ee8d2aa9f79551eb5dd8f9610ad557
SHA1 hash:
c53bdf6c05c13186a622ed9fd67f9edf2662bd47
SH256 hash:
52e50406906337c925d558e1b3df8a563a6ffb283c36b90c84e22d78612e80b4
MD5 hash:
7b6a9a804eaa262b1346eb703dcee001
SHA1 hash:
9f97b81e02e38558af1bca5ec5804e3aeadb099c
Detections:
SUSP_XORed_Mozilla SUSP_XORed_MSDOS_Stub_Message
SH256 hash:
1aa68d65f2a80547abba20a2056e873f9a9c9106e9dee2d8ab992bba33075641
MD5 hash:
c6d01b024af78d9c819d07d757fe0a7f
SHA1 hash:
6efc07b01f997e99d15020b5e7bf55f6bb60609d
Detections:
win_rokrat_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:SUSP_XORed_MSDOS_Stub_Message
Author:Florian Roth
Description:Detects suspicious XORed MSDOS stub message
Reference:https://yara.readthedocs.io/en/latest/writingrules.html#xor-strings
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments