MB-b78a29eab41dc72b66375a7d9a8fad8d5942bfe3be9bed26a8bc9a0287c446e0
high
📛 Threat Title
OverlordRAT: file
Description
File type: exe. Size: 6130792 bytes. Tags: exe, OverlordRAT, upx-dec. Reporter: abuse_ch. First seen: 2026-09-25 03:59:19.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
4e2bd2c481372f7ab13b83b63b424e97
IOC database
- Type
- hash_imphash
- Value
4e2bd2c481372f7ab13b83b63b424e97- First seen
- Last seen
- Attached to this threat
- Appears in
- 45 threats
- Description
- imphash of URLhaus payload bf3be9fc732d5b92…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
b78a29eab41dc72b66375a7d9a8fad8d5942bfe3be9bed26a8bc9a0287c446e0
IOC database
- Type
- hash_sha256
- Value
b78a29eab41dc72b66375a7d9a8fad8d5942bfe3be9bed26a8bc9a0287c446e0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- OverlordRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
2019934322a24c9aab8b30d0b630049985e4dfa1
IOC database
- Type
- hash_sha1
- Value
2019934322a24c9aab8b30d0b630049985e4dfa1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
012d9d5771dd02c4b81ff4d904e42483
IOC database
- Type
- hash_md5
- Value
012d9d5771dd02c4b81ff4d904e42483- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 6130792 bytes. Tags: exe, OverlordRAT, upx-dec. Reporter: abuse_ch. First seen: 2026-09-25 03:59:19.
Remediations (10)
-
web:detections.ai
Executive Summary A recently observed campaign, linked to the threat actor I_H8_KDot, impersonates the Inland Revenue Authority of Singapore (IRAS) to distribute Overlord RAT. The infection chain is notably complex, utilizing a Virtual Hard Disk (VHDX) image to bypass static analysis and deliver multiple malicious components. Once mounted, the victim executes a file that initiates DLL ...
-
web:github.com
Contribute to l6cv/ OverlordRAT development by creating an account on GitHub.
-
web:ismalicious.com
354 indicators of compromise attributed to the Overlord RAT malware family — domains, IPs, URLs and file hashes, from abuse.ch feeds.
-
web:mallory.ai
Overlord RAT is a Golang-based remote access trojan used in real-world intrusions and also seen in open-source-derived variants such as SpaceX1337. It has been observed as a follow-on payload after successful compromise, including post-exploitation activity against vulnerable WordPress environments and user-driven execution chains such as ClickFix-style social engineering. Reported delivery ...
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:securityarsenal.com
Fake Zoom installers drop Overlord/FlexibleFerret on macOS while UNC6671 vishing hits Okta/passkey SSO; urgent identity and endpoint hunt.
-
web:urlhaus.abuse.ch
URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as OverlordRAT .
-
web:www.iru.com
Overlord RAT is delivered through a two-stage infection chain initiated by a fake Zoom installer. The first stage, ZoomMeetings, is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single- file application. Its strings are base64-encoded and XOR'd with the key 0x94 to conceal Command and Control (C2) infrastructure and payload URLs.
-
web:www.linkedin.com
Tax-Themed Phishing Campaign Delivers Overlord RAT Using Malicious VHDX Images Our threat researchers have identified a tax-themed phishing campaign impersonating Singapore's Inland Revenue ...
-
web:www.microsoft.com
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.