Managed XDR

c-windows-33ctnf4cs.exe (DCRat) — malware analysis report

File info

Filename
c-windows-33ctnf4cs.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size
783 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
75ee625208083e6c88bf0935ebc32d8b348189a6
SHA256
a358304cce131061139cc616ae682ea8dd0bd6895342caa1f0e2012951536f81
MD5
19b4299e450d209ef1e1ecd8eb392fa9

Malwares

  • DCRat

Signatures

Other

yara_rules: Static rules
dotnet_suspicious_resources_names: Dotnet program has suspicious resources names
dotnet_suspicious_module_name: Dotnet program has suspicious module name
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
dotnet_obfuscated: Dotnet program is potentially obfuscated
suspicious_network_port: Performs TCP or UDP request to non-standard port
dotnet_downloader_possible_network_problem: Dotnet program possibly has network problem

Related reports

Managed XDR