MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f56b82ca76d007c76f59da95cd472afa6bb680069422d05383f9506461a1395b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 17


Intelligence 17 IOCs 1 YARA 19 File information Comments

SHA256 hash: f56b82ca76d007c76f59da95cd472afa6bb680069422d05383f9506461a1395b
SHA3-384 hash: 87888e084a13f573dd3a822f235e5aa0f9ce7f9b55d9f619f185cfe8586f2bb02ac4cf37e296e44cd1cd97426a77b28e
SHA1 hash: 350b41617f1c22706b632247ccaf589055d9c7cd
MD5 hash: 24dec43a4cc3b26d9eb58fdd05b57812
humanhash: pizza-cat-jupiter-vermont
File name:24DEC43A4CC3B26D9EB58FDD05B57812.exe
Download: download sample
Signature ValleyRAT
File size:3'419'359 bytes
First seen:2025-07-30 18:05:16 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash efd455830ba918de67076b7c65d86586 (99 x Gh0stRAT, 22 x ValleyRAT, 6 x OffLoader)
ssdeep 98304:4xHXMNqmmGHOIpduYWA6qGH5+S8PRpvFc8DPhe:AM8mmGuI+YW1+S0tFciPo
Threatray 153 similar samples on MalwareBazaar
TLSH T13FF50123B2CB613FF07A4A364A77D212593B7A2165128C679BE8486CCF261D11D3FB47
TrID 60.0% (.EXE) Inno Setup installer (107240/4/30)
23.2% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
5.8% (.EXE) Win64 Executable (generic) (10522/11/4)
3.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
2.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon c0c8d4cc64d4ccf8 (14 x ValleyRAT, 8 x Blackmoon, 3 x AsyncRAT)
Reporter abuse_ch
Tags:exe RAT ValleyRAT


Avatar
abuse_ch
ValleyRAT C2:
27.50.59.176:8880

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
27.50.59.176:8880 https://threatfox.abuse.ch/ioc/1562584/

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
24DEC43A4CC3B26D9EB58FDD05B57812.exe
Verdict:
Malicious activity
Analysis date:
2025-07-30 18:08:07 UTC
Tags:
silverfox backdoor valleyrat winos rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
farfli spoof
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Moving a recently created file
Using the Windows Management Instrumentation requests
Creating a process with a hidden window
Delayed reading of the file
Creating a service
Launching a service
Loading a system driver
Launching a process
DNS request
Connection attempt
Sending a custom TCP request
Adding an access-denied ACE
Running batch commands
Enabling autorun for a service
Unauthorized injection to a system process
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug embarcadero_delphi fingerprint installer overlay overlay packed zero
Result
Threat name:
ValleyRAT
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Bypasses PowerShell execution policy
Changes security center settings (notifications, updates, antivirus, firewall)
Creates a thread in another existing process (thread injection)
Drops password protected ZIP file
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sample is not signed and drops a device driver
Sigma detected: Execution from Suspicious Folder
Sigma detected: Parent in Public Folder Suspicious Process
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspect Svchost Activity
Sigma detected: Suspicious New Service Creation
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Writes to foreign memory regions
Yara detected ValleyRAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1747255 Sample: JzuBqf2fm8.exe Startdate: 30/07/2025 Architecture: WINDOWS Score: 100 107 xiaxzgg2025.com 2->107 111 Suricata IDS alerts for network traffic 2->111 113 Antivirus detection for dropped file 2->113 115 Multi AV Scanner detection for dropped file 2->115 117 12 other signatures 2->117 11 JzuBqf2fm8.exe 2 2->11         started        14 svchost.exe 2->14         started        17 SgrmBroker.exe 1 2->17         started        19 2 other processes 2->19 signatures3 process4 file5 105 C:\Users\user\AppData\...\JzuBqf2fm8.tmp, PE32 11->105 dropped 21 JzuBqf2fm8.tmp 5 7 11->21         started        141 Changes security center settings (notifications, updates, antivirus, firewall) 14->141 24 MpCmdRun.exe 14->24         started        signatures6 process7 file8 89 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 21->89 dropped 91 C:\Users\Public\Documents\unzip.exe (copy), PE32 21->91 dropped 93 C:\Users\Public\Documents\is-FT448.tmp, PE32 21->93 dropped 26 men.exe 12 21->26         started        30 unzip.exe 2 21->30         started        32 conhost.exe 24->32         started        process9 file10 95 C:\Users\Public\Documents\...\rwdriver.sys, PE32+ 26->95 dropped 97 C:\Users\Public\Documents\...\main.exe, PE32+ 26->97 dropped 99 C:\Users\Public\Documents\...\log.dll, PE32 26->99 dropped 103 5 other malicious files 26->103 dropped 133 Antivirus detection for dropped file 26->133 135 Multi AV Scanner detection for dropped file 26->135 137 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 26->137 139 Sample is not signed and drops a device driver 26->139 34 NtHandleCallback.exe 2 2 26->34         started        39 main.exe 26->39         started        41 powershell.exe 26->41         started        45 7 other processes 26->45 101 C:\Users\Public\Documents\men.exe, PE32+ 30->101 dropped 43 conhost.exe 30->43         started        signatures11 process12 dnsIp13 109 xiaxzgg2025.com 27.50.59.176, 49720, 49721, 8880 BCPL-SGBGPNETGlobalASNSG Singapore 34->109 85 C:\XiaoH.sys, PE32+ 34->85 dropped 87 C:\Cndom6.sys, PE32+ 34->87 dropped 119 Suspicious powershell command line found 34->119 121 Bypasses PowerShell execution policy 34->121 123 Writes to foreign memory regions 34->123 131 3 other signatures 34->131 47 tracerpt.exe 34->47         started        50 NVIDIA.exe 34->50         started        53 powershell.exe 23 34->53         started        61 71 other processes 34->61 125 Antivirus detection for dropped file 39->125 127 Multi AV Scanner detection for dropped file 39->127 55 conhost.exe 39->55         started        129 Loading BitLocker PowerShell Module 41->129 63 2 other processes 41->63 57 conhost.exe 45->57         started        59 conhost.exe 45->59         started        65 10 other processes 45->65 file14 signatures15 process16 file17 143 Writes to foreign memory regions 47->143 145 Allocates memory in foreign processes 47->145 147 Creates a thread in another existing process (thread injection) 47->147 67 conhost.exe 47->67         started        69 svchost.exe 47->69         started        83 C:\Users\user\AppData\Local\...\usriRGpGAUXm, PE32+ 50->83 dropped 149 Antivirus detection for dropped file 50->149 151 Multi AV Scanner detection for dropped file 50->151 153 Loading BitLocker PowerShell Module 53->153 71 conhost.exe 53->71         started        73 conhost.exe 57->73         started        75 conhost.exe 61->75         started        77 conhost.exe 61->77         started        79 conhost.exe 61->79         started        81 66 other processes 61->81 signatures18 process19
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) Win 32 Exe x86
Threat name:
Win32.Malware.Heuristic
Status:
Malicious
First seen:
2025-07-27 04:11:04 UTC
File Type:
PE (Exe)
AV detection:
16 of 38 (42.11%)
Threat level:
  2/5
Result
Malware family:
valleyrat_s2
Score:
  10/10
Tags:
family:valleyrat_s2 backdoor defense_evasion discovery execution exploit persistence
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
System Location Discovery: System Language Discovery
Launches sc.exe
Suspicious use of SetThreadContext
Enumerates connected drives
File and Directory Permissions Modification: Windows File and Directory Permissions Modification
Indicator Removal: File Deletion
Executes dropped EXE
Loads dropped DLL
Modifies file permissions
Command and Scripting Interpreter: PowerShell
Creates new service(s)
Possible privilege escalation attempt
Sets service image path in registry
Stops running service(s)
ValleyRat
Valleyrat_s2 family
Malware Config
C2 Extraction:
xiaxzgg2025.com:8880
127.0.0.1:80
Unpacked files
SH256 hash:
f56b82ca76d007c76f59da95cd472afa6bb680069422d05383f9506461a1395b
MD5 hash:
24dec43a4cc3b26d9eb58fdd05b57812
SHA1 hash:
350b41617f1c22706b632247ccaf589055d9c7cd
SH256 hash:
7844c6979c59ff0206deaabb0d05a4a66f4c01c8c14081366ab32409868cf5f4
MD5 hash:
885b14f44e6e855b97d6b667277c009b
SHA1 hash:
7a8d8a1a8ef82d154a6872b5716c4f5bfd714772
SH256 hash:
f5d66a8c0959706e343f52972c2094bf947b5009e2d40a0f124d9bdb03dbb957
MD5 hash:
4a99749f2651d9dcc0400ab7e56d5f38
SHA1 hash:
e0cbc49dc4414c09c3f75fb839b01a96e9fa6122
Malware family:
ValleyRAT
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:ICMLuaUtil_UACMe_M41
Author:Marius 'f0wL' Genheimer <hello@dissectingmalwa.re>
Description:A Yara rule for UACMe Method 41 -> ICMLuaUtil Elevated COM interface
Reference:https://github.com/hfiref0x/UACME
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_peb_parsing
Author:Willi Ballenthin
Rule name:pe_detect_tls_callbacks
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:Windows_Generic_Threat_4b0b73ce
Author:Elastic Security
Rule name:Windows_Trojan_Winos_464b8a2e
Author:Elastic Security
Rule name:win_valley_rat_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.valley_rat.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User Authorizationadvapi32.dll::AllocateAndInitializeSid
advapi32.dll::ConvertSidToStringSidW
advapi32.dll::ConvertStringSecurityDescriptorToSecurityDescriptorW
advapi32.dll::EqualSid
advapi32.dll::FreeSid
SECURITY_BASE_APIUses Security Base APIadvapi32.dll::AdjustTokenPrivileges
advapi32.dll::GetTokenInformation
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::CreateProcessW
advapi32.dll::OpenProcessToken
advapi32.dll::OpenThreadToken
kernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryA
kernel32.dll::LoadLibraryExW
kernel32.dll::LoadLibraryW
kernel32.dll::GetDriveTypeW
kernel32.dll::GetVolumeInformationW
kernel32.dll::GetSystemInfo
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateDirectoryW
kernel32.dll::CreateFileW
kernel32.dll::DeleteFileW
kernel32.dll::GetWindowsDirectoryW
kernel32.dll::GetSystemDirectoryW
kernel32.dll::GetFileAttributesW
WIN_BASE_USER_APIRetrieves Account Informationadvapi32.dll::LookupPrivilegeValueW
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExW
advapi32.dll::RegQueryValueExW
WIN_USER_APIPerforms GUI Actionsuser32.dll::PeekMessageW
user32.dll::CreateWindowExW

Comments