MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ed6431935ae84d73d60b464ecf7963e58cb0b332ef8a137a7263a9fecf8e2a96. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



LxBaseRAT


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: ed6431935ae84d73d60b464ecf7963e58cb0b332ef8a137a7263a9fecf8e2a96
SHA3-384 hash: af41b4a7c1fffbd3a6af4c4facbe047e8af32514b8eaa91182a8b58367cfbb903da523f31eb7785dc08f4821fbcfb5bd
SHA1 hash: 9075a96fa0a461d92be8e1b0e46f2ddcb512555d
MD5 hash: 10727dc060bcc4c7e549ac8d23c7d6ca
humanhash: oregon-uncle-pluto-robin
File name:Заказ_17954103024072026_Azotny_Zavod_LLP.tar.rar
Download: download sample
Signature LxBaseRAT
File size:1'062'303 bytes
First seen:2026-07-24 12:47:50 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:4dTaLY/Su8WP0j5mzxwS1M1n6MfFERKb9lwGjH/WwYT5lUk0:4YLY/Su8WPQUKtt6MfS6l7jewYFr0
TLSH T19C3533C78895D70987135A2B8CF60B9F89179CB6FCCB0E4E802CB5076DEF924997C0A5
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:LxBaseRAT rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Заказ_17954103024072026_Azotny Zavod LLP.js
File size:1'916'389 bytes
SHA256 hash: 3e120cc23a568678151b2bc258291511e3fa0b5983f7cf301aac95e4c0d2a44c
MD5 hash: 44ab116032e2cfc02a7a30ff23480556
MIME type:text/plain
Signature LxBaseRAT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
encrypted evasive lolbin obfuscated persistence repaired wscript
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-24T07:47:00Z UTC
Last seen:
2026-07-24T09:29:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
lxbaserat
Score:
  10/10
Tags:
family:lxbaserat botnet:july-24-2026 campaign:f3b65f6eafa54b53a38fb207ea5d6a92 collection execution persistence rat upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
UPX packed file
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Loads dropped DLL
Command and Scripting Interpreter: PowerShell
Family: LxBaseRAT
Malware Config
C2 Extraction:
lxrrxl.ydns.eu:4521
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_obfuscated_JS_obfuscatorio
Author:@imp0rtp3
Description:Detect JS obfuscation done by the js obfuscator (often malicious)
Reference:https://obfuscator.io
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

LxBaseRAT

rar ed6431935ae84d73d60b464ecf7963e58cb0b332ef8a137a7263a9fecf8e2a96

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments