s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-b78a29eab41dc72b66375a7d9a8fad8d5942bfe3be9bed26a8bc9a0287c446e0 high

📛 Threat Title

OverlordRAT: file

Category: OverlordRAT Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 6130792 bytes. Tags: exe, OverlordRAT, upx-dec. Reporter: abuse_ch. First seen: 2026-09-25 03:59:19.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 4e2bd2c481372f7ab13b83b63b424e97

IOC database

Type
hash_imphash
Value
4e2bd2c481372f7ab13b83b63b424e97
First seen
Last seen
Attached to this threat
Appears in
45 threats
Description
imphash of URLhaus payload bf3be9fc732d5b92…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 b78a29eab41dc72b66375a7d9a8fad8d5942bfe3be9bed26a8bc9a0287c446e0

IOC database

Type
hash_sha256
Value
b78a29eab41dc72b66375a7d9a8fad8d5942bfe3be9bed26a8bc9a0287c446e0
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
OverlordRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 2019934322a24c9aab8b30d0b630049985e4dfa1

IOC database

Type
hash_sha1
Value
2019934322a24c9aab8b30d0b630049985e4dfa1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 012d9d5771dd02c4b81ff4d904e42483

IOC database

Type
hash_md5
Value
012d9d5771dd02c4b81ff4d904e42483
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 6130792 bytes. Tags: exe, OverlordRAT, upx-dec. Reporter: abuse_ch. First seen: 2026-09-25 03:59:19.

Remediations (10)

  • web:detections.ai

    Executive Summary A recently observed campaign, linked to the threat actor I_H8_KDot, impersonates the Inland Revenue Authority of Singapore (IRAS) to distribute Overlord RAT. The infection chain is notably complex, utilizing a Virtual Hard Disk (VHDX) image to bypass static analysis and deliver multiple malicious components. Once mounted, the victim executes a file that initiates DLL ...

  • web:github.com

    Contribute to l6cv/ OverlordRAT development by creating an account on GitHub.

  • web:ismalicious.com

    354 indicators of compromise attributed to the Overlord RAT malware family — domains, IPs, URLs and file hashes, from abuse.ch feeds.

  • web:mallory.ai

    Overlord RAT is a Golang-based remote access trojan used in real-world intrusions and also seen in open-source-derived variants such as SpaceX1337. It has been observed as a follow-on payload after successful compromise, including post-exploitation activity against vulnerable WordPress environments and user-driven execution chains such as ClickFix-style social engineering. Reported delivery ...

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:securityarsenal.com

    Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.

  • web:urlhaus.abuse.ch

    URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as OverlordRAT .

  • web:www.iru.com

    Overlord RAT is delivered through a two-stage infection chain initiated by a fake Zoom installer. The first stage, ZoomMeetings, is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single- file application. Its strings are base64-encoded and XOR'd with the key 0x94 to conceal Command and Control (C2) infrastructure and payload URLs.

  • web:www.linkedin.com

    Tax-Themed Phishing Campaign Delivers Overlord RAT Using Malicious VHDX Images Our threat researchers have identified a tax-themed phishing campaign impersonating Singapore's Inland Revenue ...

  • web:www.microsoft.com

    Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.