MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fdf62cca7e7b7b73486321b0b29260cde2de3b283d87febec10f88c87a31f646. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ValleyRAT


Vendor detections: 8


Intelligence 8 IOCs YARA 39 File information Comments

SHA256 hash: fdf62cca7e7b7b73486321b0b29260cde2de3b283d87febec10f88c87a31f646
SHA3-384 hash: c0bcdc118d0b71c57e3941c80f5345c8c007bf297eed8a54b3a481aa64a2f3f4b6c8f894b262926cb261d5c76b801e56
SHA1 hash: 32f90dd064f0fe47e783e6dae00e9c2ab2063be7
MD5 hash: 268188701cfd8c256b1fd50aefc904ca
humanhash: timing-earth-stream-lake
File name:MCWinMailAll.zip
Download: download sample
Signature ValleyRAT
File size:12'870'263 bytes
First seen:2026-06-22 15:49:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:VUqSGQxjPEbajDclAZRV0yVG2b22crYVlX:WqSGQxjPxcKVLjX
TLSH T111D633773AF58E8797A66234A26CB543490091C5834CD5A1F3A180E7DB458BC3FAECDB
Magika zip
Reporter GDHJDSYDH1
Tags:backdoor dllHijack injector SilverFox ValleyRAT zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
TW TW
File Archive Information

This file archive contains 18 file(s), sorted by their relevance:

File name:vcruntime140_1.dll
File size:50'640 bytes
SHA256 hash: fd1cc0c1287caf736c7e1e4d9aee80fd74cfdfa52563ddd126c03f45542d45b6
MD5 hash: f498619721756332ef731f1b72b7f29e
MIME type:application/x-dosexec
Signature ValleyRAT
File name:curlnet64.dll
File size:2'379'744 bytes
SHA256 hash: 32575a73822ce645d9a26a3db009286f5a3d7d85099d5c5e3189ef939954bb07
MD5 hash: c5237a3a64ad5fe3d118ac7f066bff1c
MIME type:application/x-dosexec
Signature ValleyRAT
File name:vtksqlite-9.6.dll
File size:1'180'160 bytes
SHA256 hash: 1859950b3f410ae37bf115ab107917f6af6313a598f76ddbb0225d9cc85518a5
MD5 hash: c3d6b73e54ff4efd29651e46f751fe5b
MIME type:application/x-dosexec
Signature ValleyRAT
File name:msvcr110.dll
File size:849'360 bytes
SHA256 hash: ae996edb9b050677c4f82d56092efdc75f0addc97a14e2c46753e2db3f6bd732
MD5 hash: 7c3b449f661d99a9b1033a14033d2987
MIME type:application/x-dosexec
Signature ValleyRAT
File name:DefaultSkin.uiz
File size:1'649 bytes
SHA256 hash: 7606e5f9155223a58476f50fa1c401d609da5dc778c55c0e64518cb08b7774b7
MD5 hash: c521c134c0382470f5b306a0882e3448
MIME type:application/zip
Signature ValleyRAT
File name:CommonLogin.zip
File size:124'051 bytes
SHA256 hash: 258a523e38579fe8be4e61f321435201e9d37630386c4d6cd507d13ee15dfca6
MD5 hash: a1670c51116ecf249d8d2ed69f245d7e
MIME type:application/zip
Signature ValleyRAT
File name:YXCalendar.exe
File size:3'218'400 bytes
SHA256 hash: c7df57c6addf8aa38a619ac38c782733d5bc594d079e88ba5aec8cad148388c4
MD5 hash: ffa4b02695700d8dfe861944bc9894a1
MIME type:application/x-dosexec
Signature ValleyRAT
File name:LsfSdk.dll
File size:6'575'136 bytes
SHA256 hash: aa68dac66a9c0d815bbe44644cbd60ec0c5a1d3ecdc56b7d8b1a2a9855398026
MD5 hash: f05116adc796497512385c8475ae4a8c
MIME type:application/x-dosexec
Signature ValleyRAT
File name:vcruntime140.dll
File size:110'528 bytes
SHA256 hash: 2aebc4e4ca7645188d12950ca68b39f71ebd86da4228419800c1b1a3754f3130
MD5 hash: ded0fb624c202e3595551256e3bc0ba2
MIME type:application/x-dosexec
Signature ValleyRAT
File name:CommonLogin64.dll
File size:2'206'176 bytes
SHA256 hash: bc7da6350d5a5d98ce29623409c5dc24bc467c1406a19f8909ca2213ed1fe1d8
MD5 hash: fe380f33acd98dd4c7267e454e80880a
MIME type:application/x-dosexec
Signature ValleyRAT
File name:msvcp110.dll
File size:661'456 bytes
SHA256 hash: 27f394ae01d12f851f1dee3632dee3c5afa1d267f7a96321d35fd43105b035ad
MD5 hash: 7caa1b97a3311eb5a695e3c9028616e7
MIME type:application/x-dosexec
Signature ValleyRAT
File name:desktop.uiz
File size:3'268'982 bytes
SHA256 hash: d40c51ba011d24c3391cc5608e282aca86b158e8616918b96cc80c4759040ec0
MD5 hash: ad1f88ecd8fa4ffbf31c2548d1f386d3
MIME type:application/zip
Signature ValleyRAT
File name:api-ms-win-crt-runtime-l1-1-0.dll
File size:24'888 bytes
SHA256 hash: d0bde181dea08ab14d97ac3cec64eb6237ffbf158f8f8ef4f0ccb713546c0159
MD5 hash: db21b81f63c7e6a653e7436f999a102c
MIME type:application/x-dosexec
Signature ValleyRAT
File name:ExtDefaultSkin.uiz
File size:718'214 bytes
SHA256 hash: cb0c068be1ec5c31c0e6b82082b79118ceeeefbec14d31e3378af6783b9fcbf8
MD5 hash: 2f1cdba93afc8a7e097872ff38ff79b4
MIME type:application/zip
Signature ValleyRAT
File name:dkcinst.ini
File size:193'108 bytes
SHA256 hash: 52fa0d0fad715b68fb14d7b56a9002d55d57c41ca786bb9eeafbcda3e068657d
MD5 hash: 504930990b3e34b1db226675b9d56380
MIME type:text/plain
Signature ValleyRAT
File name:msvcp140.dll
File size:573'008 bytes
SHA256 hash: 1e57a6df9e3742e31a1c6d9bff81ebeeae8a7de3b45a26e5079d5e1cce54cd98
MD5 hash: c3d497b0afef4bd7e09c7559e1c75b05
MIME type:application/x-dosexec
Signature ValleyRAT
File name:WebView2Loader.dll
File size:138'272 bytes
SHA256 hash: ede42f3392c3573ac8660263072c7fd50c0e1605bf9fabed05c10b9d35e214bc
MD5 hash: cb57ee3dacb20c34ae3296aaad8f128b
MIME type:application/x-dosexec
Signature ValleyRAT
File name:LYSDK2.dll
File size:3'198'976 bytes
SHA256 hash: a30f0643c7c07a9e014cc5de5d5cf9c03489b61660bd3783efb030f7c52dfe6a
MD5 hash: 91e9b61aeb427f56a870f7b1d781fc9a
MIME type:application/x-dosexec
Signature ValleyRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70.0%
Tags:
virus
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-22T12:34:00Z UTC
Last seen:
2026-06-23T23:46:00Z UTC
Hits:
~10
Detections:
Trojan.Win64.DLLhijack.fgp
Gathering data
Threat name:
Win32.Trojan.Yomal
Status:
Malicious
First seen:
2026-06-22 14:49:55 UTC
File Type:
Binary (Archive)
Extracted files:
1318
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
adware bootkit link persistence qr ransomware spyware
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:CMD_Shutdown
Author:adm1n_usa32
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:IronTiger_GetUserInfo
Author:Cyber Safety Solutions, Trend Micro
Description:Iron Tiger Malware - GetUserInfo
Reference:http://goo.gl/T5fSJC
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:skip20_sqllang_hook
Author:Mathieu Tartare <mathieu.tartare@eset.com>
Description:YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference:https://www.welivesecurity.com/
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TH_Generic_MassHunt_Win_Malware_2025_CYFARE
Author:CYFARE
Description:Generic Windows malware mass-hunt rule - 2025
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ValleyRAT

zip fdf62cca7e7b7b73486321b0b29260cde2de3b283d87febec10f88c87a31f646

(this sample)

Comments