MB-a85a685e8753319479922d6098726906804dca6a518205ed70fd555c5289d743
high
📛 Threat Title
DCRat: 0a3e2c2bd38771605cb2eeae9c8cbc62.exe
Description
File type: exe. Size: 3160576 bytes. Tags: DCRat, exe, RAT. Reporter: abuse_ch. First seen: 2026-08-04 21:45:17.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 638 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
a85a685e8753319479922d6098726906804dca6a518205ed70fd555c5289d743
IOC database
- Type
- hash_sha256
- Value
a85a685e8753319479922d6098726906804dca6a518205ed70fd555c5289d743- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- DCRat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
9a271677e5d66df8d0b7d0677893d69ce9ab72f1
IOC database
- Type
- hash_sha1
- Value
9a271677e5d66df8d0b7d0677893d69ce9ab72f1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
0a3e2c2bd38771605cb2eeae9c8cbc62
IOC database
- Type
- hash_md5
- Value
0a3e2c2bd38771605cb2eeae9c8cbc62- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3160576 bytes. Tags: DCRat, exe, RAT. Reporter: abuse_ch. First seen: 2026-08-04 21:45:17.
Remediations (10)
-
web:any.run
DCrat is a modular remote access trojan that is capable of stealing passwords, crypto wallet information, taking screenshots, and hijacking accounts.
-
web:blog.netmanageit.com
Description This article provides a step-by-step analysis of the DCRat malware using ANY.RUN. It covers the distribution, ecosystem, surface analysis, dynamic analysis, and static analysis of DCRat . The analysis aims to understand DCRat's capabilities and how it operates.
-
web:boteraser.com
🛡️ Mitigation Defenders should enforce application whitelisting, block suspicious PowerShell and cmd executions, and deploy network detection rules for anomalous TLS handshakes to unknown domains. Endpoint detection and response (EDR) solutions with behavioral analysis (e.g., MITRE ATT&CK techniques T1055, T1059, T1547) can identify DCRat activity. Regular patching of Microsoft Office ...
-
web:cybersecuritynews.com
DCRAT RAT targets Colombian orgs via phishing emails posing as govt, using ZIPs with batch files to evade detection and gain control.
-
web:github.com
A simple remote tool in C#. Contribute to qwqdanchun/ DcRat development by creating an account on GitHub.
-
web:hunt.io
DCRat , also known as DarkCrystal RAT, is a Remote Access Trojan (RAT) that emerged in 2018. Notably, it operates as Malware-as-a-Service (MaaS), allowing cybercriminals to purchase and deploy it with ease. Its modular design enables a wide range of malicious activities, including data theft, espionage, and remote surveillance.
-
web:malpedia.caad.fkie.fraunhofer.de
DCRat is a typical RAT that has been around since at least June 2019.
-
web:muha2xmad.github.io
A deep dive into DCRAT /DarkCrystalRAT malware 20 minute read On this page Introduction Technical summary Commands Power options Enumerate operations Enumerate Processes and their executable Enumerate Drives Enumerate folders Enumerate screens Enumerate Cameras Enumerate Microphones Clipboard grabber Show notifications Execute CS, VB, VBS, PS Take screenshots Download File Run a specific file ...
-
web:ntapinsight.com
EDR telemetry: high-alert on powershell.exe -enc, rundll32.exe calling from temp folders; detect .NET assembly loading with AMSI bypass strings (\x00\x00). User awareness: run quarterly tabletop on fake cracked-game emails; mandate MFA for corporate mailboxes. 2. Removal - Step-by-Step Scope: one endpoint noted encrypting files.
-
web:offensive-panda.github.io
The people behind DCRat have even released a special tool called " DCRat Studio" that helps them create new features for the malware. This constant evolution and the malware's ability to evade detection make it a significant threat to computer users and organizations. Staying cautious and using advanced security measures is crucial to protect against DCRat and similar threats.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.