s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-a85a685e8753319479922d6098726906804dca6a518205ed70fd555c5289d743 high

📛 Threat Title

DCRat: 0a3e2c2bd38771605cb2eeae9c8cbc62.exe

Category: DCRat Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3160576 bytes. Tags: DCRat, exe, RAT. Reporter: abuse_ch. First seen: 2026-08-04 21:45:17.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
638 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 a85a685e8753319479922d6098726906804dca6a518205ed70fd555c5289d743

IOC database

Type
hash_sha256
Value
a85a685e8753319479922d6098726906804dca6a518205ed70fd555c5289d743
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
DCRat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 9a271677e5d66df8d0b7d0677893d69ce9ab72f1

IOC database

Type
hash_sha1
Value
9a271677e5d66df8d0b7d0677893d69ce9ab72f1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 0a3e2c2bd38771605cb2eeae9c8cbc62

IOC database

Type
hash_md5
Value
0a3e2c2bd38771605cb2eeae9c8cbc62
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3160576 bytes. Tags: DCRat, exe, RAT. Reporter: abuse_ch. First seen: 2026-08-04 21:45:17.

Remediations (10)

  • web:any.run

    DCrat is a modular remote access trojan that is capable of stealing passwords, crypto wallet information, taking screenshots, and hijacking accounts.

  • web:blog.netmanageit.com

    Description This article provides a step-by-step analysis of the DCRat malware using ANY.RUN. It covers the distribution, ecosystem, surface analysis, dynamic analysis, and static analysis of DCRat . The analysis aims to understand DCRat's capabilities and how it operates.

  • web:boteraser.com

    🛡️ Mitigation Defenders should enforce application whitelisting, block suspicious PowerShell and cmd executions, and deploy network detection rules for anomalous TLS handshakes to unknown domains. Endpoint detection and response (EDR) solutions with behavioral analysis (e.g., MITRE ATT&CK techniques T1055, T1059, T1547) can identify DCRat activity. Regular patching of Microsoft Office ...

  • web:cybersecuritynews.com

    DCRAT RAT targets Colombian orgs via phishing emails posing as govt, using ZIPs with batch files to evade detection and gain control.

  • web:github.com

    A simple remote tool in C#. Contribute to qwqdanchun/ DcRat development by creating an account on GitHub.

  • web:hunt.io

    DCRat , also known as DarkCrystal RAT, is a Remote Access Trojan (RAT) that emerged in 2018. Notably, it operates as Malware-as-a-Service (MaaS), allowing cybercriminals to purchase and deploy it with ease. Its modular design enables a wide range of malicious activities, including data theft, espionage, and remote surveillance.

  • web:malpedia.caad.fkie.fraunhofer.de

    DCRat is a typical RAT that has been around since at least June 2019.

  • web:muha2xmad.github.io

    A deep dive into DCRAT /DarkCrystalRAT malware 20 minute read On this page Introduction Technical summary Commands Power options Enumerate operations Enumerate Processes and their executable Enumerate Drives Enumerate folders Enumerate screens Enumerate Cameras Enumerate Microphones Clipboard grabber Show notifications Execute CS, VB, VBS, PS Take screenshots Download File Run a specific file ...

  • web:ntapinsight.com

    EDR telemetry: high-alert on powershell.exe -enc, rundll32.exe calling from temp folders; detect .NET assembly loading with AMSI bypass strings (\x00\x00). User awareness: run quarterly tabletop on fake cracked-game emails; mandate MFA for corporate mailboxes. 2. Removal - Step-by-Step Scope: one endpoint noted encrypting files.

  • web:offensive-panda.github.io

    The people behind DCRat have even released a special tool called " DCRat Studio" that helps them create new features for the malware. This constant evolution and the malware's ability to evade detection make it a significant threat to computer users and organizations. Staying cautious and using advanced security measures is crucial to protect against DCRat and similar threats.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.