🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f34ccaabd453d1a48109ea8f96b224c845ff03da08059db5ae5c63b3bf21bc15. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



OverlordRAT


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: f34ccaabd453d1a48109ea8f96b224c845ff03da08059db5ae5c63b3bf21bc15
SHA3-384 hash: 29120dfaa899ab5c44afff75fa01e46060b7ca876a937cf4a95475264f367884d5f33bf3b0f97e91cf5dce9a3b2eef2a
SHA1 hash: 96de64f7bad0a99047f8687eaaac7f012bc249c4
MD5 hash: 98b0409ff0ace3977e887cea396c8d21
humanhash: connecticut-charlie-fish-beryllium
File name:Prestige-Client.exe
Download: download sample
Signature OverlordRAT
File size:44'409'344 bytes
First seen:2026-07-08 09:02:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ed8b780a3ce7ca4aba78a21f6bc3d4e0 (9 x VeilStealer, 8 x OverlordRAT, 5 x WailsLoader)
ssdeep 196608:fmCOmpzWUe/pBi7aQGHUGFyKeFVWN20MKcPsi8QZiX33MyhdEjqp3heM6x+Ulf7U:ffOek/3n0Gfe0DCPsi/YX38QX6xbIBq
TLSH T192A72B53F8E22984D9EEC574C772417BBB613869077823D706A0F3201F3ABE09AB6755
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter burger
Tags:exe OverlordRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
177
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Prestige-Client.exe
Verdict:
Malicious activity
Analysis date:
2026-07-08 07:57:58 UTC
Tags:
overlord rat golang

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Сreating synchronization primitives
Connection attempt
Sending a custom TCP request
DNS request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
golang
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-07T08:51:00Z UTC
Last seen:
2026-07-09T12:58:00Z UTC
Hits:
~10
Detections:
Trojan-Spy.Win64.Xegumumune.oub
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.evad
Score:
96 / 100
Signature
Allocates memory in foreign processes
Creates a thread in another existing process (thread injection)
Early bird code injection technique detected
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Installs new ROOT certificates
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queues an APC in another process (thread injection)
Writes to foreign memory regions
Behaviour
Behavior Graph:
Gathering data
Verdict:
Malicious
Threat:
Trojan-Spy.Win64.Xegumumune
Threat name:
Win64.Trojan.Ravartar
Status:
Malicious
First seen:
2026-07-07 13:45:00 UTC
File Type:
PE+ (Exe)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Checks processor information in registry
Looks up external IP address via web service
Malware family:
OverlordRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

OverlordRAT

Executable exe f34ccaabd453d1a48109ea8f96b224c845ff03da08059db5ae5c63b3bf21bc15

(this sample)

  
Delivery method
Distributed via web download

Comments