General
-
Target
a707a64de1846b90fdf608d7f24338e913440c260a579211089861f26932ebf0.exe
-
Size
152KB
-
Sample
240627-bw7ncayblm
-
MD5
099120c6a053ee7608db0b2f576e8086
-
SHA1
a08f60b86dfa532cc515a43ebe477b67871db1fa
-
SHA256
a707a64de1846b90fdf608d7f24338e913440c260a579211089861f26932ebf0
-
SHA512
81cb1a55771e4dc2d31330a79932338fd099cf62e36657c97374382a6fd9734584af2f198fcbd69fd354e06619398f608002fc83ea75e89df23a58f5e2976a07
-
SSDEEP
3072:4NLOpnhTdOw9YAJOzIY9gVl01T2ENipdDg0z5:4NLYdT97JSIFl0QENqF
Behavioral task
behavioral1
Sample
a707a64de1846b90fdf608d7f24338e913440c260a579211089861f26932ebf0.exe
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
a707a64de1846b90fdf608d7f24338e913440c260a579211089861f26932ebf0.exe
Resource
win10v2004-20240226-en
Malware Config
Extracted
warzonerat
109.248.151.231:52048
Targets
-
-
Target
a707a64de1846b90fdf608d7f24338e913440c260a579211089861f26932ebf0.exe
-
Size
152KB
-
MD5
099120c6a053ee7608db0b2f576e8086
-
SHA1
a08f60b86dfa532cc515a43ebe477b67871db1fa
-
SHA256
a707a64de1846b90fdf608d7f24338e913440c260a579211089861f26932ebf0
-
SHA512
81cb1a55771e4dc2d31330a79932338fd099cf62e36657c97374382a6fd9734584af2f198fcbd69fd354e06619398f608002fc83ea75e89df23a58f5e2976a07
-
SSDEEP
3072:4NLOpnhTdOw9YAJOzIY9gVl01T2ENipdDg0z5:4NLYdT97JSIFl0QENqF
Score10/10-
WarzoneRat, AveMaria
WarzoneRat is a native RAT developed in C++ with multiple plugins sold as a MaaS.
-
Loads dropped DLL
-
Accesses Microsoft Outlook profiles
-