MB-32aaa1d07dc07217223009ad404925c5b518907e3b6c8aad1c2250e9f9dc54aa
high
📛 Threat Title
OverlordRAT: file
Description
File type: exe. Size: 2505832 bytes. Tags: dropped-by-GCleaner, exe, G, upx, US0.file. Reporter: Bitsight. First seen: 2026-09-25 03:58:42.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
6ed4f5f04d62b18d96b26d6db7c18840
IOC database
- Type
- hash_imphash
- Value
6ed4f5f04d62b18d96b26d6db7c18840- First seen
- Last seen
- Attached to this threat
- Appears in
- 87 threats
- Description
- imphash of URLhaus payload f36467769f8a9e79…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
32aaa1d07dc07217223009ad404925c5b518907e3b6c8aad1c2250e9f9dc54aa
IOC database
- Type
- hash_sha256
- Value
32aaa1d07dc07217223009ad404925c5b518907e3b6c8aad1c2250e9f9dc54aa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- OverlordRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
344d41f14532c587ccffc1cdcb8b938bac76c5fc
IOC database
- Type
- hash_sha1
- Value
344d41f14532c587ccffc1cdcb8b938bac76c5fc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
fed8e2acb3f9a1876f11f759f155a200
IOC database
- Type
- hash_md5
- Value
fed8e2acb3f9a1876f11f759f155a200- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2505832 bytes. Tags: dropped-by-GCleaner, exe, G, upx, US0.file. Reporter: Bitsight. First seen: 2026-09-25 03:58:42.
Remediations (10)
-
web:bazaar.abuse.ch
OverlordRAT malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as OverlordRAT . Database Entry
-
web:d2ul67h78igv2v.cloudfront.net
Overlord is a Remote Access Trojan (RAT) developed in the Go programming language, designed to target both Windows and macOS environments. Initial detections were recorded in South Korea, raising concerns about its potential deployment in real-world attacks. On macOS systems, the malware is capable of establishing persistent communication with attacker-controlled infrastructure, capturing user ...
-
web:github.com
Contribute to l6cv/ OverlordRAT development by creating an account on GitHub.
-
web:github.com
Contribute to l6cv/ OverlordRAT development by creating an account on GitHub.
-
web:socprime.com
Simulation Execution Attack Narrative & Commands: The adversary aims to deploy the Overlord RAT on a macOS workstation by masquerading as a Zoom update. After tricking the user into running a fake installer, the installer drops a stage-2 payload into a hidden-looking directory in the temporary folder: /tmp/ZoomMeetings.
-
web:urlhaus.abuse.ch
URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as OverlordRAT .
-
web:www.hazetec.com
The first-stage downloader is a .NET 10 single- file application using a base64-plus-XOR scheme with key 0x94 to hide attacker infrastructure. Overlord RAT provides extensive surveillance, including keylogging, webcam capture, and a WebSocket-based C2 hardcoded to hub.zoom.com [.]kg on port 5173.
-
web:www.iru.com
Overlord RAT is delivered through a two-stage infection chain initiated by a fake Zoom installer. The first stage, ZoomMeetings, is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single- file application. Its strings are base64-encoded and XOR'd with the key 0x94 to conceal Command and Control (C2) infrastructure and payload URLs.
-
web:www.microsoft.com
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...
-
web:www.pcrisk.com
In many cases, simply opening an infected file or installer is enough to trigger the infection. Other common distribution methods include drive-by downloads, fake software installers from third-party sites, peer-to-peer sharing platforms, software cracks, and malicious links sent through email or messaging apps.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.