General

  • Target

    cheatroblox.exe

  • Size

    3.3MB

  • MD5

    0c3e07265eded8fc455a638d5ec44f2c

  • SHA1

    cf71372d50bf58acfdaa8f7fc1854de0ca42deaf

  • SHA256

    50258d28e57d1470e34bcb97075ac5d97c236918d3cc1f728830fd9a5e70b25b

  • SHA512

    74dcff438fe87e65a6c28f24c8c55bd8dc7f1bd0ac413d24545559219f96e8f8cbf673d4ccf597ea82613d4584ed06f50861ffd18cac8c0dcbeecaa64fffbb0b

  • SSDEEP

    49152:1Djlabwz9JCTqIcN+hvbhMVAvEBjXFEwc7QNexKYFNa/ern/eXGbXwSF12Uz:ZqwfCTfrbhM+vEV7NeXKern/e2t1Zz

Score
10/10

Malware Config

Signatures

  • DCRat payload 1 IoCs

    Detects payload of DCRat, commonly dropped by NSIS installers.

  • Dcrat family
  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • cheatroblox.exe
    .exe windows:5 windows x64 arch:x64

    b1c5b1beabd90d9fdabd1df0779ea832


    Headers

    Imports

    Sections