s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-32aaa1d07dc07217223009ad404925c5b518907e3b6c8aad1c2250e9f9dc54aa high

📛 Threat Title

OverlordRAT: file

Category: OverlordRAT Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2505832 bytes. Tags: dropped-by-GCleaner, exe, G, upx, US0.file. Reporter: Bitsight. First seen: 2026-09-25 03:58:42.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 6ed4f5f04d62b18d96b26d6db7c18840

IOC database

Type
hash_imphash
Value
6ed4f5f04d62b18d96b26d6db7c18840
First seen
Last seen
Attached to this threat
Appears in
87 threats
Description
imphash of URLhaus payload f36467769f8a9e79…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 32aaa1d07dc07217223009ad404925c5b518907e3b6c8aad1c2250e9f9dc54aa

IOC database

Type
hash_sha256
Value
32aaa1d07dc07217223009ad404925c5b518907e3b6c8aad1c2250e9f9dc54aa
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
OverlordRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 344d41f14532c587ccffc1cdcb8b938bac76c5fc

IOC database

Type
hash_sha1
Value
344d41f14532c587ccffc1cdcb8b938bac76c5fc
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 fed8e2acb3f9a1876f11f759f155a200

IOC database

Type
hash_md5
Value
fed8e2acb3f9a1876f11f759f155a200
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2505832 bytes. Tags: dropped-by-GCleaner, exe, G, upx, US0.file. Reporter: Bitsight. First seen: 2026-09-25 03:58:42.

Remediations (10)

  • web:bazaar.abuse.ch

    OverlordRAT malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as OverlordRAT . Database Entry

  • web:d2ul67h78igv2v.cloudfront.net

    Overlord is a Remote Access Trojan (RAT) developed in the Go programming language, designed to target both Windows and macOS environments. Initial detections were recorded in South Korea, raising concerns about its potential deployment in real-world attacks. On macOS systems, the malware is capable of establishing persistent communication with attacker-controlled infrastructure, capturing user ...

  • web:github.com

    Contribute to l6cv/ OverlordRAT development by creating an account on GitHub.

  • web:github.com

    Contribute to l6cv/ OverlordRAT development by creating an account on GitHub.

  • web:socprime.com

    Simulation Execution Attack Narrative & Commands: The adversary aims to deploy the Overlord RAT on a macOS workstation by masquerading as a Zoom update. After tricking the user into running a fake installer, the installer drops a stage-2 payload into a hidden-looking directory in the temporary folder: /tmp/ZoomMeetings.

  • web:urlhaus.abuse.ch

    URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as OverlordRAT .

  • web:www.hazetec.com

    The first-stage downloader is a .NET 10 single- file application using a base64-plus-XOR scheme with key 0x94 to hide attacker infrastructure. Overlord RAT provides extensive surveillance, including keylogging, webcam capture, and a WebSocket-based C2 hardcoded to hub.zoom.com [.]kg on port 5173.

  • web:www.iru.com

    Overlord RAT is delivered through a two-stage infection chain initiated by a fake Zoom installer. The first stage, ZoomMeetings, is a macOS ARM64 Mach-O binary built as a self-contained .NET 10 single- file application. Its strings are base64-encoded and XOR'd with the key 0x94 to conceal Command and Control (C2) infrastructure and payload URLs.

  • web:www.microsoft.com

    Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...

  • web:www.pcrisk.com

    In many cases, simply opening an infected file or installer is enough to trigger the infection. Other common distribution methods include drive-by downloads, fake software installers from third-party sites, peer-to-peer sharing platforms, software cracks, and malicious links sent through email or messaging apps.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.