MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e2f034103fee432f5a0d6e79e56f06c9df5d9cb2c6b56ffe4eea85c7213eb4ac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: e2f034103fee432f5a0d6e79e56f06c9df5d9cb2c6b56ffe4eea85c7213eb4ac
SHA3-384 hash: bb4ffbf34325e7c380e42974ca38e4d779f0337695cc04911438111183a582691a3900393fef48f1a3fc3830b92096ec
SHA1 hash: abc3176c5abf5dc3cfc0c16d6f8b16125a7bdd74
MD5 hash: c2a0627fcaf9f749dcfd3bf06a9bdc43
humanhash: minnesota-angel-foxtrot-triple
File name:win32-quickq.exe
Download: download sample
Signature ValleyRAT
File size:102'398'930 bytes
First seen:2026-08-14 03:07:41 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2057790ae7855765d51bdc4142e62f9c (54 x RemusStealer, 5 x ValleyRAT, 5 x SalatStealer)
ssdeep 3145728:aB+Jekz2IV5764YhnE65oYDsLqfhSGDILhGXvF4uHw3:aXV8vLesuZSGDFvF43
TLSH T15D283346E2E9C8FBDA871878899A2B1DF6BB7CF10255ED3702A0339F4D3464A0D5C791
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon f0c896b28a9ec8f0 (4 x ValleyRAT)
Reporter aachum
Tags:203-91-74-4 CHN exe ValleyRAT


Avatar
iamaachum
https://quickqe.net/apps/?platform=windows => https://quickqe.net/api/download/4

ValleyRAT C2: 203.91.74.4:1231

Intelligence


File Origin
# of uploads :
1
# of downloads :
311
Origin country :
ES ES
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Launching the default Windows debugger (dwwin.exe)
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug crypto expired-cert fingerprint installer installer installer-heuristic microsoft_visual_cc overlay packed packed reconnaissance sfx
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
40 / 100
Signature
Allocates memory in foreign processes
Benign windows process drops PE files
Changes memory attributes in foreign processes to executable or writable
Found direct / indirect Syscall (likely to bypass EDR)
Multi AV Scanner detection for submitted file
Sample is not signed and drops a device driver
Unusual module load detection (module proxying)
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1958017 Sample: win32-quickq.exe Startdate: 14/08/2026 Architecture: WINDOWS Score: 40 89 Multi AV Scanner detection for submitted file 2->89 91 Unusual module load detection (module proxying) 2->91 10 win32-quickq.exe 19 2->10         started        13 explorer.exe 2->13         started        15 rundll32.exe 2->15         started        process3 file4 75 C:\Users\user\AppData\...\DualAppLauncher.exe, PE32 10->75 dropped 77 C:\Users\user\AppData\...\win32_quickq.exe, PE32+ 10->77 dropped 79 C:\Users\user\AppData\...\win32-quickq.exe, PE32 10->79 dropped 17 DualAppLauncher.exe 10->17         started        process5 process6 19 win32-quickq.exe 8 799 17->19         started        23 win32_quickq.exe 2 1 17->23         started        file7 67 C:\Users\user\AppData\Local\...\nsis7z.dll, PE32 19->67 dropped 69 C:\Users\user\AppData\Local\...\nsExec.dll, PE32 19->69 dropped 71 C:\Users\user\AppData\Local\...\System.dll, PE32 19->71 dropped 73 37 other malicious files 19->73 dropped 93 Sample is not signed and drops a device driver 19->93 25 taskkill.exe 19->25         started        27 taskkill.exe 19->27         started        29 taskkill.exe 19->29         started        38 6 other processes 19->38 95 Writes to foreign memory regions 23->95 97 Allocates memory in foreign processes 23->97 99 Found direct / indirect Syscall (likely to bypass EDR) 23->99 31 svchost.exe 12 6 23->31 injected 36 win32_quickq.exe 1 23->36         started        signatures8 process9 dnsIp10 40 conhost.exe 25->40         started        42 conhost.exe 27->42         started        44 conhost.exe 29->44         started        81 203.91.74.4, 1231, 49749 AROSS-AS-AROSSCLOUDINCUS Hong Kong SAR China 31->81 61 C:\Program Files\...\vulkaninfo-64.exe, PE32+ 31->61 dropped 63 C:\Program Files\Common Files\vulkan-1.dll, PE32+ 31->63 dropped 83 Benign windows process drops PE files 31->83 85 Unusual module load detection (module proxying) 31->85 46 vulkaninfo-64.exe 31->46         started        49 svchost.exe 31->49         started        65 C:\Users\user\AppData\...\tmp6D28.tmp (copy), PE32+ 36->65 dropped 87 Found direct / indirect Syscall (likely to bypass EDR) 36->87 51 conhost.exe 38->51         started        53 conhost.exe 38->53         started        55 conhost.exe 38->55         started        57 2 other processes 38->57 file11 signatures12 process13 signatures14 101 Changes memory attributes in foreign processes to executable or writable 46->101 103 Writes to foreign memory regions 46->103 105 Allocates memory in foreign processes 46->105 59 conhost.exe 46->59         started        process15
Gathering data
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-14 03:10:39 UTC
File Type:
PE+ (Exe)
Extracted files:
931
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
adware defense_evasion discovery execution spyware
Behaviour
Kills process with taskkill
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Checks installed software on the system
Drops desktop.ini file(s)
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

Executable exe e2f034103fee432f5a0d6e79e56f06c9df5d9cb2c6b56ffe4eea85c7213eb4ac

(this sample)

  
Delivery method
Distributed via web download

Comments