MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e6f4c46f2a72a4d8b1eda2c2c431c64d73eae7057221b35a6fc16138e4dc4d43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 13


Intelligence 13 IOCs 1 YARA 44 File information Comments

SHA256 hash: e6f4c46f2a72a4d8b1eda2c2c431c64d73eae7057221b35a6fc16138e4dc4d43
SHA3-384 hash: c97ae0708c750760959eb23c491268b69f940b5e862189307c8157380962d52b853e9b34480bee535399a4327b8b46d2
SHA1 hash: 602862693c2edba1df17afd61b4fcdc3a5ca139f
MD5 hash: 0561a3921c93fe5913454241362e80e2
humanhash: nitrogen-fanta-september-september
File name:DingTalkD_Setup2026.exe
Download: download sample
Signature ValleyRAT
File size:44'304'324 bytes
First seen:2026-07-19 23:10:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 40ab50289f7ef5fae60801f88d4541fc (77 x ValleyRAT, 58 x Gh0stRAT, 42 x OffLoader)
ssdeep 786432:LhGfMHhij2MOLPstwdk0dyRFsNBvkOPFkFFQB7msB/PZkl4h2r6HWeyZpy0bfiGs:LhGfMBijDO0rs0OPBysNxklDrvpy0bf6
TLSH T1F7A73323B3C7A13FF45E0B3B16B3A16094FB9A11B512BD678AC440ECDE264541E7E61B
TrID 63.8% (.EXE) Inno Setup installer (107240/4/30)
24.7% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.8% (.EXE) Win64 Executable (generic) (6522/11/2)
2.6% (.EXE) Win32 Executable (generic) (4504/4/1)
1.2% (.EXE) Win16/32 Executable Delphi generic (2072/23)
Magika pebin
dhash icon c488b8f0e2b692cc (4 x ValleyRAT, 3 x Gh0stRAT, 2 x CobaltStrike)
Reporter Ling
Tags:exe SilverFox ValleyRAT


Avatar
CNGaoLing
The sample is retrieved from "https://i-dingtalk.com.cn" / "https://pc.s-dingtalk.com.cn" / "https://o-dingtalk.com.cn" / "https://v-dingtalk.com.cn"
Note: The malicious redirection only triggers when the link is clicked directly from Bing search results.

SilverFox
IOC (IP 192.197.113.54:332)

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
192.197.113.54:332 https://threatfox.abuse.ch/ioc/1853967/

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
shellcode dropper emotet smtp
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
Deleting a recently created file
Connection attempt
Sending a custom TCP request
Replacing files
DNS request
Creating a file
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 crypto embarcadero_delphi evasive expired-cert fingerprint inno installer installer installer-heuristic lolbin msiexec packed packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-19T20:00:00Z UTC
Last seen:
2026-07-20T09:52:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan.Win32.DLLhijack.gen Backdoor.Win32.Xkcp.a PDM:Trojan.Win32.Generic Backdoor.Agent.TCP.C&C
Gathering data
Threat name:
Win32.Trojan.ValleyRAT
Status:
Malicious
First seen:
2026-07-19 23:11:35 UTC
File Type:
PE (Exe)
Extracted files:
3250
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
valleyrat_s2
Score:
  10/10
Tags:
family:valleyrat_s2 backdoor discovery installer persistence upx
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
UPX packed file
Adds Run key to start application
Checks installed software on the system
Enumerates connected drives
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Detects ValleyRAT payload
Family: ValleyRat
Malware Config
C2 Extraction:
192.197.113.54:332
127.0.0.1:80
Malware family:
ValleyRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Agent_BTZ
Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Borland
Author:malware-lu
Rule name:ComRAT
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FormhookB
Author:kevoreilly
Description:Formbook Anti-hook Bypass
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:GenericGh0st
Author:Still
Rule name:Gh0stKCP
Author:Netresec
Description:Detects HP-Socket ARQ and KCP implementations, which are used in Gh0stKCP. Forked from @stvemillertime's KCP catchall rule.
Reference:https://netresec.com/?b=259a5af
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MAL_packer_lb_was_detected
Author:0x0d4y
Description:Detect the packer used by Lockbit4.0
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:OpCloudHopper_Malware_3
Author:Florian Roth (Nextron Systems)
Description:Detects malware from Operation Cloud Hopper
Reference:https://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html
Rule name:OpCloudHopper_Malware_3_RID2FEF
Author:Florian Roth
Description:Detects Operation CloudHopper malware samples
Reference:https://www.pwc.co.uk/issues/cyber-security-data-privacy/insights/operation-cloud-hopper.html
Rule name:pe_detect_tls_callbacks
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:upx_largefile
Author:k3nr9
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:Windows_Generic_Threat_4b0b73ce
Author:Elastic Security
Rule name:WinosStager
Author:YungBinary
Description:https://www.esentire.com/blog/winos4-0-online-module-staging-component-used-in-cleversoar-campaign
Rule name:Win_FakeInstaller_PythonShellcodeLoader_Crepectl_2026
Author:SixHands
Description:Detects the analyzed fake installer sample using .key config, XOR key, and Python/fiber shellcode loader traits
Rule name:win_winos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.winos.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

Executable exe e6f4c46f2a72a4d8b1eda2c2c431c64d73eae7057221b35a6fc16138e4dc4d43

(this sample)

  
Delivery method
Distributed via web download

Comments