Tracking an evolving Discord-based RAT family
A family of four new remote access trojans (RATs) operated by the STD Group has been identified, leveraging Discord as their command and control (C2) channel. These RATs—Minecraft RAT, UwUdisRAT, STD RAT, and Propionanilide RAT—are written in C++ and use a ROT23 cipher to obfuscate Discord bot tokens for C2 communication. The malware has evolved from single payloads to using packers, complicating detection efforts. The RATs enable attackers to perform reconnaissance, execute commands, and maintain persistence on infected systems. Detection is supported by YARA rules and file indicators provided in the analysis. While no known exploits in the wild have been reported yet, the use of Discord for C2 is notable for evading traditional network defenses. European organizations, especially those with high Discord usage or gaming-related sectors, could be targeted. Mitigation requires enhanced monitoring of Discord traffic, endpoint detection tuned for these RAT behaviors, and restricting unauthorized Discord bot usage within corporate environments.
AI Analysis
Technical Summary
ReversingLabs has uncovered a set of four remote access trojans (RATs) linked to the STD Group that utilize Discord as their command and control (C2) infrastructure. These RATs—Minecraft RAT, UwUdisRAT, STD RAT, and Propionanilide RAT—are developed in C++ and employ a ROT23 cipher to encode Discord bot tokens, which facilitates stealthy communication with their C2 servers hosted on Discord. The evolution of this malware family shows a progression from simple single payloads to more sophisticated variants that use packers, such as the Propionanilide RAT, to evade detection by antivirus and endpoint security solutions. The RATs leverage Discord’s legitimate API and infrastructure, making network-based detection challenging because Discord traffic is typically allowed in corporate environments. The malware supports a range of tactics including system reconnaissance (T1082, T1083, T1057), credential access (T1056), command execution (T1059.003), and persistence mechanisms (T1543.003). The use of ROT23 cipher for token obfuscation and the reliance on Discord bots for C2 communication are key technical features. The report includes YARA rules and file indicators to aid defenders in identifying infections. Although no active exploits have been reported, the threat is medium severity due to the potential for stealthy, persistent access and control over compromised systems. The malware’s use of a popular communication platform for C2 highlights the need for organizations to monitor and control Discord usage within their networks.
Potential Impact
For European organizations, this RAT family poses a significant risk due to its stealthy use of Discord for command and control, which can bypass traditional network security controls that do not inspect or restrict Discord traffic. Organizations in sectors with high Discord adoption—such as gaming, software development, and youth-oriented services—are particularly vulnerable. The RATs enable attackers to perform reconnaissance, steal credentials, execute arbitrary commands, and maintain persistence, potentially leading to data breaches, intellectual property theft, or disruption of services. The evolution to packed payloads increases the difficulty of detection by signature-based antivirus solutions. Additionally, the use of Discord, a widely trusted platform, complicates incident response and network monitoring. European entities with lax controls on third-party communication platforms or insufficient endpoint detection capabilities may face prolonged undetected intrusions. This threat could also be leveraged for espionage or sabotage, especially in organizations involved in technology, media, or critical infrastructure sectors.
Mitigation Recommendations
European organizations should implement the following specific mitigations: 1) Enforce strict network segmentation and monitoring of Discord traffic, including the use of SSL/TLS inspection where legally permissible, to detect anomalous bot communication patterns. 2) Deploy endpoint detection and response (EDR) solutions configured to detect behaviors associated with these RATs, such as unusual process creation, use of packers, and suspicious API calls related to Discord bots. 3) Apply YARA rules and file indicators provided by ReversingLabs to enhance malware detection capabilities. 4) Restrict the installation and use of unauthorized Discord bots and clients within corporate environments through application whitelisting and group policies. 5) Educate users about the risks of executing unknown payloads, especially those related to gaming or Discord communities. 6) Regularly update and patch endpoint security tools to recognize new packing techniques and obfuscation methods. 7) Conduct threat hunting exercises focusing on Discord-based C2 traffic and related artifacts. 8) Collaborate with Discord platform providers to report suspicious bot activity and seek assistance in mitigating abuse. These measures go beyond generic advice by focusing on the unique use of Discord as a C2 channel and the malware’s evolving packing techniques.
Affected Countries
United Kingdom, Germany, France, Netherlands, Sweden, Poland, Italy, Spain
Indicators of Compromise
- hash: 16f62ac70fce821c4dc6e178d7ff0ce4
- hash: 1bb55cc26dc0904ddf0c2c0f6c56de20
- hash: 25283b97624e5a25b8d45be7cec0edcb
- hash: 25c095a512e9b58f07c8174c47a82535
- hash: 275ef20b19ce085ad9a6f4555bc45947
- hash: 2b0c0af9956928604aeb5884d888cb89
- hash: 2b17e069dc77ec1ec65cac43cab37dde
- hash: 2e0fc51860d7a2b72bc34410b956b303
- hash: 310b0d940edd2fb9761e20ec08472c6d
- hash: 326d523fd53f5d3b72fecdc1a6fb7574
- hash: 330871792be237fb02d23114ae9be52e
- hash: 37892e769d50536aaed53841c6453a78
- hash: 38525d335798bb934c7ed0027cda4adb
- hash: 385a04f1c5ea4d843c15576c082b4561
- hash: 388b71dbb9c4bd25a1e757d21900cc61
- hash: 3e05ed5f590ddb2ba45a1c213b96a990
- hash: 3f3dbf91aa19a8e2b1e4c1c603f64ac1
- hash: 4293afb0df2bd4f0507c76d918a5f262
- hash: 4419d4b641e1cae10e61aa95fa8dc3bc
- hash: 49db7426b665fa482e91c30d7623b151
- hash: 4e37f91f700b038da2ab7545b0c19e60
- hash: 5965ec0c37d5b3b05c6ed5b967f45008
- hash: 5a0cb54e42395579a8db3a1f302e4aac
- hash: 5c6284b9d15895373fb05aef32f369db
- hash: 6883238db0555c1b085545322127e892
- hash: 7246e26cf2fe62899538f44cd737689e
- hash: 72bc4606848e068683fa077a9eecf7da
- hash: 746b9227c53a0448a29698155ce884e4
- hash: 753324fedfd7e77327d964e3bbe4d0f3
- hash: 7a91c9ab7282b395d89b8b5cb97645ee
- hash: 81356d2861bcf015bff0a9a5b02d2af9
- hash: 81a69c28e46c22e144bac98d6d2a5e0f
- hash: 83b6e8689922d7665594bf95442e761a
- hash: 848692fd2389ca9c7ec26d25e32c3ec6
- hash: 84a6c269b690b567aa465d52cc653959
- hash: 8784f906bda125082f7384b58766f7ea
- hash: 8841e83e6c759a89f7cbe03280ff52db
- hash: 8bbfe6fc40ecfddb3bb27d26b40a7423
- hash: 8ebcb94e7cc8c969cad76beaa132f08e
- hash: 8ed2624f2db2e85c6f4bec0182bad13a
- hash: 95a07a5529b2425e279ca7b8b0e92e0d
- hash: 96643baaf6b27a9cbe9161c68faabda8
- hash: 9b4f27e3e19e8e39d3d0599ca901fb80
- hash: 9ce0c12c334d50ade8b84f572323ba4d
- hash: a466df72d1a9c149ca0a97893346092b
- hash: a8559547cdf9fb49ae4f1f743b80d09a
- hash: ac69eac215fdba0401591c1458cd9f46
- hash: ac729fd7dc97b754ac3bb750ca986e4c
- hash: b80d696e433b17af3724df0ea5e3934f
- hash: c22306bdcafe16caf171fd314906ef75
- hash: c705eb0cf8aee3fb29f4b75d290ff255
- hash: c804423ac19cd0305fcee8ce57b3aefe
- hash: ce9d35f37f1e719493db56df6bcbdf80
- hash: d886b719c1de39f5da04bc872f6fd003
- hash: dac6dd07867124c4bd8da78d1f3086f5
- hash: dad463abb2e45c806568b7b23028f355
- hash: fb57b32d1cb4431d8a628cff2ba9f55c
- hash: fe6a372458fe26aace5f37ad2ede3cad
- hash: 002688f6733d0cbc0b8998b58661594d4ab0e4b3
- hash: 06f29ce71ab3757c62e34de2874f89ab80b512a4
- hash: 09f96961a0b82a2df10e04ff0edcff67d6cd54e1
- hash: 0c326bc2f94ad8ef3cf4c59184d50a6cd90e239f
- hash: 0cfe02dcb368c44294d96c2b7f598566eba0d78e
- hash: 17e2c880c28b56ddcf744ea3f9c32d3be18749aa
- hash: 1b531cc6a22093b0cb7a4ec8d4de79401cdeba37
- hash: 1c15184e2711fa8789ffb4fb02e22f79d324a1ab
- hash: 219dd0a82cf8e7e07c5e583ad0c1836b8e2b61e9
- hash: 23dcc294e938e13604f8bb5963fc3b415950da7c
- hash: 29249d7c3d9fdb7b51dbcb187988be5e0329a704
- hash: 2d71b06086b3b6c5a2476813878c273d97b8b27f
- hash: 2e0c188eeba59d952eee34d5a5a487cc2a31fa1d
- hash: 35096132bb821f4a0968067c22c571c285079db9
- hash: 358b1422c4dacb0a3482b6004ad19c252cb020f9
- hash: 3b60a47a4b7bf9ef01b172e18c336272118772b5
- hash: 3f72b3ec01dc2ae9e64d262c03586fb16e8eb7cf
- hash: 494041c60f589e8a07f365f3d474c9f4af86485d
- hash: 4a1cde90cde3b7f12fb5eec8e975ee95ac5bf13f
- hash: 5891af6fbabe0e1f14fe7f4a02e08f050690afc5
- hash: 5bf3edeb0be696217b7b19da7aedd9feae77848e
- hash: 5ffacad5a9e8e4e7e081ccd38ad0ebcacb7f62d3
- hash: 6232be28ceb6758386fe8b9184412a3ee2b5e886
- hash: 65a7f80365a3e53b14ac3788fd4b0a7dba0b9436
- hash: 6a0766aed2eb98697e79f8c089a7cccc2eb55f16
- hash: 6ab68498f86f6e643bd719307b7d510c59a4198d
- hash: 709d1692c5c847146a3c8fbc56b0b88bb671a56c
- hash: 70bec731d3dd1041e7241a5a2d4b206eb32fe9b6
- hash: 712ba10945e498691ad38a921089fd581eae7999
- hash: 7a63d0343062698b2c13fcad5c15a6b1181e559f
- hash: 7dc09a0716af7b39917ac0e772cf943888b8927b
- hash: 86801041d33e568f00c2fa7ed2db3ca4a46ee18d
- hash: 87962a26443e54e35df655f90cef58326818c99d
- hash: 8eb4ff7c59b978eeed378c2f97da12e258ff1b20
- hash: 935a891f38e21e35ae757e06193ea0c5932a5582
- hash: 95c3094b7a6982ed933ba4146583176a91c41f2e
- hash: 974b28d0ace6c2500af37076240ff27ba358d32b
- hash: 9ab90ceb97f0bccb9ce1651b8bed5ea7acedead2
- hash: 9acd2aa0ade17d154f81f550f5a9c648b9f16c46
- hash: 9b407a4858b83898e46292f1fc64be9dcee47eb3
- hash: a214c224320c2c06d35b4124b48b2da68974b391
- hash: a55dd3011f53b6e0e656d7d659982c9965f501f8
- hash: a9474fff7357e6e09c08305a1a1cf96085ae5403
- hash: adde86cf6a8ecf0a5b3a32584c6e435cbff6386c
- hash: b073567de4885aad3e758cbe80cacfd186d5e2fb
- hash: b2534d7688c6a2c984b02ba28038af0b7a106808
- hash: b3cd563cfa231a5b5d63bac3af796f1c66e2a165
- hash: bca08c0595783adfe389604df30e81605b6d8d52
- hash: c34a6c519823ecb89289e56a026613c807d5eb23
- hash: cf875fbeefd3b96f881aa1d1993debec09d3b06f
- hash: d4585f5d61adef3a8e2652569ec63924153c50c0
- hash: d6725531b2a0fd923fe4fb8d699f4c9ed5b974d3
- hash: d7d9ea74bef47c5bf5f9cfed2a23991a98134f21
- hash: da7c67cd74f7d33e0974f7d7b4e8dd65ae09e58f
- hash: dd19c315af10dbfb8485e2bb00519b7062c5701c
- hash: e525d70edb2cb8f6e0ce5218391960e52cba5d61
- hash: e5df3b8512175ee06694a49fe28165608cb748a1
- hash: f60720781f081c784ede5d8823b42906e90bd179
- hash: 000eed382ebec21a1f27a860cc52613cdd98fc36dd12d37bad15caeb36846d7f
- hash: 04589839ac2f6bd9ed2e958a6085c9070c6844e2c9abe15641f8befa70a65a98
- hash: 061799cfc23d3689870ea6abed1f8cb5f595f63bb810ef7c829376c9c5cea921
- hash: 0774e3488e6b762dc68c59c07576c6623f9066e38e4b0845e3b3a0fba8041958
- hash: 09959d473a1b842bb3d953a71ed0e7230ae32f16036805b09806dd626fbef580
- hash: 0a54750e93f9e716b3ce206933b0c8d0d4b2771696ae0104478fe009879b0ea8
- hash: 0cde3036878b3f0fc3dfe44a281769823948bc7bcff22f9c2fced9d5406ddf50
- hash: 0d0671b0da75b1730a3095d51b5f3f107ddbbbf1bac4369378cba083c414b886
- hash: 116d35b441fab38e6d72a58ec113535620a7c13e36f7e11d3f36cabeb71d3032
- hash: 12507941a6f3742efa8fc866112524217ee7f906ac19f3e20a0bda5bc28397c1
- hash: 12a01041764caa20c4f12f21531865ab73eac5539561f597adcb871b56e444de
- hash: 12c9cca4b13fb5fa772ef2991afe06c25a3f7dca89dc2faf15b0bf6a22c15c92
- hash: 13ea8800215e75c1427ffcbb1ab475d3cfdde7227d95688203f80fcd957ec817
- hash: 142fb1ce5ee9b8ed3145caca2021da717ab546435f0303c63531a45522cf668e
- hash: 1582a8f6c5bd486192de99a286566d09bf11a47cf3d3fd55fae0a3ee646b1f28
- hash: 1a1d3d897d0b6eb8836e15359fc600b3790a3c621a3cf0d0cbd23c88e9e8af69
- hash: 1a4382141f9d4910a172089048157052a053d3ae81fd2ae660632b849d606f2c
- hash: 1a6c4df56b01b53d31f5f263d96faa7c534c183ec59e6dcd14d7481ac1acc09f
- hash: 1ca659cfe2f40695a250ca3c6287ed3691a268d6f7fbffbf83a5b0bb0ed0a528
- hash: 1cb3e126db89fa922616d5bee319775b366eb850948a14f29d1a6cb96866b63c
- hash: 1e4856791ff06948959bce04f815ed6bb58a5e220e3abaee5b7d50d6b9a1d65c
- hash: 1eabcc4e360b855521f0d3c5d3830daa169e81357dc8a109302ae9f76ffd45a4
- hash: 202083aae976ab71a75d2d185e918430128bd845d125e55395617bddcc1d01e7
- hash: 20ec15898814ac2bb574b526a7070c7044e33b6f87575206677ba3ea5cf2a24c
- hash: 2232a2ec8a45c25ac04afbc38e3fd41bc9024033e1b3ed93f0422cfc6a84344a
- hash: 28b6c2afff094e05a68c2ecd05b0507a4bd290a74410a89e0c35fa30f78c788c
- hash: 28fd5a8e4d69285724858b8d8fdaef0f9af65deca01c6a0b335c544b7b51eb90
- hash: 2932b243514af400307955985d58dcaeae200b9d7c959146b60c93e2f2f1c485
- hash: 2c105c535af48b11d568fb1e718ab172c0346937fd96b3b8039aaaf617edcf8d
- hash: 2d90575dadcfebfb6599b17d70c8f9494819276629b116b4bb43515f90e827f5
- hash: 30501b866ca2f0c9a8db01ee842bd5a9527e413bf1fb52a39c70f21d74d337b8
- hash: 307c6c77cb0c50ae427fb316ab8f2c1362715b6cabf43391d36cedc3f1a3e846
- hash: 30fe2f72e06a5d1cb966e868196bde5547e586ba8f09bb8152fa8d2086372d0a
- hash: 3391c12d268cc10419bf6a48bf235fab1006d2e61ac91cf039a30ccfac6649e2
- hash: 33d6cbdcc208875a1e83b4fe215ca0d902ee3860165fb9b94b3d2a00025f925c
- hash: 340228a3396e378880837445c46bf2636d3973848a9513b877fb2bf1c5f4ffa3
- hash: 35f24e9c2b1f349c42495b0b5f4d9d77c1fb9ef0a5bcd8a30e85966262e3b00c
- hash: 3636ab2e6bd670b933378e844159bf3600250f0441f14160cb83859c30c7c4ee
- hash: 36a6e50c5fef6ec99151969ff90fbeb6dde974a37a0d3eb5ec4df5ffe3ca260f
- hash: 36fcd429f3053afd1a3d80682b56216c0d24b4ec8b99fc943aadf36a64d4f35e
- hash: 3867ee71602b654d1f127901670003f06c699ab84edb8b1c63f8211045388d74
- hash: 39866c5378fb9a7fcd22b8fdecc475e2cc7a2c91b57a953e514213a22fb5f194
- hash: 39b73542cd04fb0e74d788256653406a60830078a794b13bbab22aee111161d5
- hash: 3ae2fd48b95b8de8dbbbe1c3bbf80b89bd8885fa9a9a27e690eb808770338c0d
- hash: 3b693725c879a30291408e01a82e6d8a433b4578206c84493b4898fc0ee49e72
- hash: 3d3be605ba3d6532040023aca9461acc4b711889fc4411fa5ecb661cbf0ff5d6
- hash: 3e8435ac3726315d21afb12a8e47bdb347c2af362be4ccb1e05df5a33874c962
- hash: 3fc319e3edd19c962179e8ed21bef5a9d2a32edd4f1b17677600505010a49611
- hash: 400a9207d39e3eeb4256902a82ada6b78cfe43db5c53fe7e068c86b30e7d4461
- hash: 40802de4630cfb94f9a458ae678559680d6a459152bd96fb565e2a45a85531b3
- hash: 41fcba17e81df0c852d70e6e2b13a8d3b163d70410dc05f737dcceab15fd4f2d
- hash: 44122eb155dfb5a81f3d27999ff6f2a6bcba2bb8d4041a61c8553743871a1f89
- hash: 44623c837caf40341d187b5b5e1486eaec2528d0af715310ddf6c1c4b7b9ccee
- hash: 4609455dfa0d1957c970bcfccbfbeeba78688f4b42ae6cf27aa6b3e43d3f08a6
- hash: 4739dc5f11c309e520825b71054e83cbe0d5477fb69ded411162993da67b1211
- hash: 481dfd997779ebadc3b9390c97a267db3d5b61cb8275c2ca1c55561efa49a220
- hash: 48f10195a2d4dab6121f1dd2792e5958aeb2db454cf3276d90acc24fe74edc23
- hash: 49ff98529404bf03fd88341e6e9bc6eac54fb5f9c1bbfe46c3ea891533166de1
- hash: 4aeeb684566572bf0b7f045c8a7b1a98d273767f6e0a8b76b9098ddc7a5301e3
- hash: 4c682ee5f1646c4821e3ac88c570d3f65f1e34e13b139459bd8b165dca36c49b
- hash: 4cce2b038ddd73ea8d6ee059bd8bc2a814829823f69647d7f87c9f5af75ea1b4
- hash: 5036e245217e91db237ba428be1e0ddeff71859a55a3cdc42db6e35be38661d8
- hash: 510cd3b9de265e44ca4467833dc17336f2afdfd4df203e43bc51e85767e88702
- hash: 5180c17fd25d52422d1246ccff4961e44d7932fadf8633b03668953fa3f3a664
- hash: 58b0b01514ff9da571c18b0b8f91a7840884424811e21e4b19b8860d83b50a4f
- hash: 5a1df5702683628aac4657bfd80ed7571a746fa5242dc6a353a2f6830d027d53
- hash: 5d16e3b5930da291790c6ba70caf4a88067b1e11aecfd1f7ea3a88eb9e06dfb7
- hash: 5eb04ef949abaf560eba8d235aa00c8eba2e349c6201571961c904a23a778f1c
- hash: 5f30c71b5b83b3924cded96151a621b0292d6682d580861c95a916038aad9485
- hash: 60b14a10d81a0253694003a2294f93ffb6d2c1efd32b644cd450fd0a8d8b6f5e
- hash: 62652633076dd5e5a8ff6ef730bf6d0dfe01ffaf869395a5e3836f7b728b7602
- hash: 62a10917e3da538fe4d482f37b7939b54a08396665f484fe13accb3db9e64427
- hash: 64251424d1417e14d4a220d2cb30500961f659cd8f7969209a9bbe45d4cd312a
- hash: 646fa42f3f05133345c9fc9cc7f8d4b4b1188af73415140604d9eb95e4ec905a
- hash: 6603e7a118494282fa684be85dabec4c085492cacbd95c78cc45c30d4abc1d97
- hash: 667e4d67acff2b8e60e3ca14075d33e51cb5269512b9208241d9381b25192f17
- hash: 679cc9ff7ed27407e37a028d945ab0895becccea18f7ca70ea8bfbb79e2d82de
- hash: 683453d1b92f8b3db65ec7de31036b248ea04fe8f250a4c0e3a8596f1236d1a0
- hash: 68dd4aa92850fab76a6a23df41166f0f706da811aeb340710459c21b357794ea
- hash: 69e2ff214cd59ffe3d58a07f53e6cb03cb7e610fc90b01635077a1612436e75c
- hash: 6a201fc8696dc8ceff68c9829984b16e9994bc7c0a774bdd1859efec60f4d69b
- hash: 6a987d918f400dd3c0840917845743f8eedc0c83efc5a9e7089bcb09169dc606
- hash: 6c87c3b522b1d84aef3f78a9d8099ecbdc8352e1b35ffc32436c90f228f825be
- hash: 6de6fd9270dfd007f375782b76854b7cdd21b48994def97457265d3c047fb092
- hash: 6eba18e9a1f0354d81fd124da7a716a587678821e855155a2bb1e2bb93713758
- hash: 6ebc9ae70ca7c605acf342c7bccad069fe4dac95b850812c7585ccf2bc28e24c
- hash: 6f19308935915ff4b6b7d231f477cb90a31800671f2407a152d8547ffcfc9c9e
- hash: 70fc6bed8574c2c2d0bc8f753d8d62430224b08bdaa26b8152d7756961c03a09
- hash: 73f310328bc78edaa86e4d6519e192af6bbabbf80591a57eab30dbd0d4a9002e
- hash: 74537b0bebc09b7de8dcfaa72a2dcd28fc2a3d95a31f2f3f2671a18aab88e093
- hash: 7464fa2a457d001dc7a3080391dfd1c9e33a8f43bdbcb8403b60b5e3d1c10229
- hash: 751ee3e15fd9454298bb0c3db714bd32b92b0e4e109e8218389d20de8bd935e2
- hash: 772cba090376101576015e269f60cf50b2de1180aca84686307945b661ebc665
- hash: 7a594591ece534e74299e4660ac0e2c458fca1136920f68904b6408c7e7e1071
- hash: 7d796e90c7b01e44220812e5a3e3ba32b0b3707b75491b3c81a23264616e5e70
- hash: 7ed399614e5e234d32eadcc9513ce2001e4e09a81e8fa1f45fe9a93610a37225
- hash: 81d6b086ba1f84cc146011300b7787b5586c4d85f04d9b10ba1685ca2c5836ac
- hash: 82906c572d6bb9f511183a4c18fdff6d399bbad646c0d47394c8329f0d9dd47a
- hash: 8437f50e7fc6491d96ef41431f967fd9fde63525219f7fd0d9c9ff93b1fad3e3
- hash: 84a01c5607791856c849e0db4b15e29dc21f7a04fc8540c085b86a820d687a15
- hash: 85f8ccf69bed672d92b40c45f9571378a7d00c80b86004a76018d9e120eeaa01
- hash: 89b0ffa674c8a2bb7636079a0c9b8505105bfdf4e0c76422aaeb5720423798e1
- hash: 8afaad8f3657e978790860174412ff82a7673543fc23228012fa13a894ea1e72
- hash: 8be83c870b040890638e29798e7a7e2f77b2e298222785fb04653fd4d1943c95
- hash: 8ca78f2eb59302102de3b8e471cd307513e655cfd0f872f27d2640eed0e3b4eb
- hash: 8d47a214344c1af6da38772556c3b9e1dec27c53ea23360e3219845c67cda5b2
- hash: 8e949697effe4c46daf0c7e0d00a5f2081f9e457fc8053826677d83ca769e363
- hash: 90260da07172586c4e8a8653077edb8be7f846cc9fd5db2e18bce1aa521e565d
- hash: 92ab1a93499aae4c8b0c47476b24af5f1cf209f39857f654dc7e567e40f84c30
- hash: 9437005de21d45f9ffa4d4a1f0989f42d1b513fa745213d76993c721b7f59667
- hash: 94e2fe3928c4d3243a526a58bf3c854969d75dec7179adee967efa6b7f424d22
- hash: 97a05771adc063f3223354ef4ea2956abce095a9ed56ecd40761abea322250c4
- hash: 97aab6ebd8fac8a2ec7c48c06b886103ab8cf98a9760f60c8071a485c77c1fc8
- hash: 98b4c878d93fbed658aa05f518e610506cd78f3e0d871c92eeb84ee781dcbf24
- hash: 99a56910caace53fd223710a10825683772d730ab11b41c0dbdf8ea50007edc3
- hash: 9a1d86487fd9eb3d36aaaa05afb382a1c37420491d61b3492c02a68eb50b709e
- hash: 9a4a2b8720cb6cbc16c6450a9d4f7e78b12406690ad77f72300029b5c0f852e4
- hash: 9ac5bc1bc05457941d96bc5be8ad4c1dd5258fe337e5bdfa27c649ea4bbc49ae
- hash: 9b60635bf858d1f432e726a029c7386ec6d17b2cc2e77845dc647200c7802312
- hash: 9d524c8444ee8d6d66976c22456e7ebf54395e53be35c5aa69e180f6f5dce74c
- hash: 9fb33b4a7acdd44c6d440560c8280024e72dfd0a6f8c8b1c83bcb4b7555b3c87
- hash: a57025157be76361ec8fc1dce54b8964538f32f620cb22d5c8848e24978eaec6
- hash: a5fbdc052a07a2ea2f13891596001e9ec1d8fac940ea0a3599597a7c48d67a77
- hash: a618a75488fb3e0031fa15b89da4f118db452257b18907436ae3e64aa03f6877
- hash: a6287162def3932558debccc288f2a2a1f04eba7dca9e2a2d64de8146808466b
- hash: ac5a5a5f76815b9d61f7ce83d555b237b3ffe5dc92ec3719e0990ce4ed85fe3b
- hash: adbf546702820ead085f4f3b786993cf6e8a1f21fa55d9655bffccc70eec93c3
- hash: aeef6087b0d022bf8b103c5813c0bc0a5e964189583f03cfe55defc0c3bf2374
- hash: af03448c80d22769103fb0025943eb0b0ef6f7c0acb3df170c78fe1de08bcb41
- hash: b0512b00c39de877b82417bb1aadaade779c1fb409284eb84da2ba8ebb2931a7
- hash: b2a5b626583786c84d7ebea403700b2785907e1766233c5a49d485ed46dface9
- hash: b3f7dee0b69c1f0fd8512cfcd673fa5d928e8415f356de7d2a598b9fdc0a31e6
- hash: b44f58b17096abf899f48a1703ca0564950634d90acb7ceded6d372642dec346
- hash: b4ec5581a655597ce432b1a4a161fc89cad73bad2c0bd2a09f155412e511b546
- hash: b536d4655560395df4eb3d8f9b46590f31023a1b96a75e32cd8d20192435a1e2
- hash: b71a133ae09604f17fbebaea4512e251e9404c865b619d18f07ec3008d1f2f6d
- hash: b8a13d7758cdf9d8b80fc2504866e9a26ca348f4a940ca6a451754fa61564f73
- hash: b8b4021fb3083a2feadcf5cb755f2e66561a1f20949cefcf83c21b508ff8dbec
- hash: b8b68aef7ae26a5aae1e9d35a1cf2fb54b77307b48b596424683eeaed2343627
- hash: bc800e5252da33803ce2cf6ffc06c899703735ad72240b54f34b0ea7389cfd47
- hash: bc9f0bec077a6f406191b035e5ae35246c12ffa7f36c3424002dbf0e01e49820
- hash: bd60d56fc8cd50b403f3171a2bd5ff540d9e741d9967297af132448b5dafbbf5
- hash: bed69afbdc147c31728bd79708c6056499c95edf731250493ca064de9c5f513c
- hash: c0d98ae50837044d61ecc88f2f1d9b74a35ba8e0898d3bdd80517323ba5fbfe4
- hash: c3141c72e98fd48da3546217ada5e31b6786041bd0b24373ae91c9e36ee7a67d
- hash: c3abd4e97d004df3094d44888dc19360333f5981afe2d0b85b80fff47c4628ce
- hash: c5863bdec64be0cb662efce9a8bbe2bde0b96132717d89c74ff0e566903143eb
- hash: c78d8f99b69fc5c7ceb6d0d0755cb7b8aa818a77ec4ef574a25e8d79734aa0dd
- hash: c901285252c58d1bbb0020a9def9bdb9a62a70df9a933199daeb694d21038b6d
- hash: ca54d10d45fcc04f8581f7c0c5a53b41f47858bd9ee6c224ee709b162cecdc05
- hash: ced35c008c4d1d774d2fdc493f66ac4bcc623ada7f7008ff5b12f895848f7e31
- hash: cf37a6e873bcbf22841e27aa466cbf3e356bb389b862dcd55453097d79beadf8
- hash: d00b71ed37cd2c62f762b31b3f77a0f5791ea29931de317915682b1e967785d0
- hash: d3346bddc69913ec98838fdbd63cb75a29fa9353e27be8ede9d8dc4fb9f40b42
- hash: d3446ac50fcdddb11c3b1d334e905b5823a43cf7bee690e666f0d0f624de5f08
- hash: d582c6bc50fa4f6c5a3f1e07ea33f61d4bd5276f76a66e65c68f5a57c3c1f511
- hash: d5c6e3ac4e471641995aa15c108d962f68e371caa5ad20d45d7f78e3732932d0
- hash: d6f6947b56d4b1d6dc524b7940c7eac7f13930371d37347b77534c038c20140d
- hash: db7e53791455769db95e95e15c9a9ffc77ec1c4724b0c46e020478949996d097
- hash: df299e3f32f08298c90f322491204079d888422fe0e73e87566e43583a3c534c
- hash: e18519525f442b8e6e97b5b503c041c0f548d4bc9b1538881f31dc5bb72d6f18
- hash: e3a8ad4428b9aa93ab4c3bd83e5f7aebca9a70a1f7043b022411691a3aae3715
- hash: e4eb15c56cb3711b83a6dabc7cb9489e209205aeea7b4a92b1039ddc069f6e69
- hash: e545da3a7624d5c8c7fef362194619e39d215385991a79978a518d5be4212691
- hash: e6353eb093a2ca1dd4bf336a5ea80bef7306be0c1d2848e59ed8f87e5df825bc
- hash: e6689e14ec941295ff2b33ac484999239504ebcb6e9daf803b11d2652eaecdda
- hash: e6fa6f2b014ea80b19fe14ed20aaadc8ff7b7505efa326833c96fe3ff37b9261
- hash: e89a30a0a7c387d74b274566557a1b45a62dd8dd9842181a0dc082d626657c69
- hash: e8c4e84db1ccecb62499548e40393979f23ef3356b22a61bee08ebe8f5ef03c1
- hash: e8ec993c0ab37471ddd3a6a7e117147dc2d404817cab5845a6eb5def60c5d0c4
- hash: ea950729734765ece6fb230a65b110e4fb0d60b108a52459e2fc3854fd5547ff
- hash: ecac78dc376b08a004d056ad29d57ddd96905b94675695e4d5fa78d81c02dbc4
- hash: edb9be32ce811b0d51bc871b5ad75036f7750f5d46587855e01d167532486b6a
- hash: ef2043b996d7ca0f5dc56c26e1b9299dbc732f879379e1b9845d523b683b3a86
- hash: f3ea2e40da7c674312ef379275b36777db95da21564d9bbb868f919802a58609
- hash: f411482e1e187d0b85c4be62459159ef83874b6bb19d88de38e70e530c6178b6
- hash: f63fea79d76b97ff0e7c484c05739261c6beaef5cfd9eb93ad9e4fe5afc16aea
- hash: f6504c62569cd83f18f2cf50d7d7ae260ba0da38e86fa055d2892591f0544560
- hash: f98916ba5138dd6f233023a3b9fe5e969a50bee3d7cfffb69900f4d1d39e02b6
- hash: fa72c468e57411f896b71852621e5778a7dbaecc9f70119c0898dff8ba4247e8
- hash: faf0556d746a0161f149db0ae8eb74a1dff4a114502360ca547920aad4cc9f3c
- hash: fb4c58ff61d8e43a744e3928ac0e0823ab1d106d8ef1f5171495c46eb3570780
- hash: fc213a5f50b671e5b0914b2cea4354a3394aaafbf7a4a99ecccb2db31b78c76a
- hash: fcfbe3559b24a0468785f0d84880c9371b41bb9893fa74f69e130908dc6dd562
- hash: ff70fcaf5bf42d19f9eb15bcf7a8227f6af22c19eee1b034b427109960b52e37
- yara: 3a11738952f549db5316f7f1c56f44977160496b
- yara: 7020511e5c03b9203600175a9cf2829fa3e871f7
Tracking an evolving Discord-based RAT family
Description
A family of four new remote access trojans (RATs) operated by the STD Group has been identified, leveraging Discord as their command and control (C2) channel. These RATs—Minecraft RAT, UwUdisRAT, STD RAT, and Propionanilide RAT—are written in C++ and use a ROT23 cipher to obfuscate Discord bot tokens for C2 communication. The malware has evolved from single payloads to using packers, complicating detection efforts. The RATs enable attackers to perform reconnaissance, execute commands, and maintain persistence on infected systems. Detection is supported by YARA rules and file indicators provided in the analysis. While no known exploits in the wild have been reported yet, the use of Discord for C2 is notable for evading traditional network defenses. European organizations, especially those with high Discord usage or gaming-related sectors, could be targeted. Mitigation requires enhanced monitoring of Discord traffic, endpoint detection tuned for these RAT behaviors, and restricting unauthorized Discord bot usage within corporate environments.
AI-Powered Analysis
Technical Analysis
ReversingLabs has uncovered a set of four remote access trojans (RATs) linked to the STD Group that utilize Discord as their command and control (C2) infrastructure. These RATs—Minecraft RAT, UwUdisRAT, STD RAT, and Propionanilide RAT—are developed in C++ and employ a ROT23 cipher to encode Discord bot tokens, which facilitates stealthy communication with their C2 servers hosted on Discord. The evolution of this malware family shows a progression from simple single payloads to more sophisticated variants that use packers, such as the Propionanilide RAT, to evade detection by antivirus and endpoint security solutions. The RATs leverage Discord’s legitimate API and infrastructure, making network-based detection challenging because Discord traffic is typically allowed in corporate environments. The malware supports a range of tactics including system reconnaissance (T1082, T1083, T1057), credential access (T1056), command execution (T1059.003), and persistence mechanisms (T1543.003). The use of ROT23 cipher for token obfuscation and the reliance on Discord bots for C2 communication are key technical features. The report includes YARA rules and file indicators to aid defenders in identifying infections. Although no active exploits have been reported, the threat is medium severity due to the potential for stealthy, persistent access and control over compromised systems. The malware’s use of a popular communication platform for C2 highlights the need for organizations to monitor and control Discord usage within their networks.
Potential Impact
For European organizations, this RAT family poses a significant risk due to its stealthy use of Discord for command and control, which can bypass traditional network security controls that do not inspect or restrict Discord traffic. Organizations in sectors with high Discord adoption—such as gaming, software development, and youth-oriented services—are particularly vulnerable. The RATs enable attackers to perform reconnaissance, steal credentials, execute arbitrary commands, and maintain persistence, potentially leading to data breaches, intellectual property theft, or disruption of services. The evolution to packed payloads increases the difficulty of detection by signature-based antivirus solutions. Additionally, the use of Discord, a widely trusted platform, complicates incident response and network monitoring. European entities with lax controls on third-party communication platforms or insufficient endpoint detection capabilities may face prolonged undetected intrusions. This threat could also be leveraged for espionage or sabotage, especially in organizations involved in technology, media, or critical infrastructure sectors.
Mitigation Recommendations
European organizations should implement the following specific mitigations: 1) Enforce strict network segmentation and monitoring of Discord traffic, including the use of SSL/TLS inspection where legally permissible, to detect anomalous bot communication patterns. 2) Deploy endpoint detection and response (EDR) solutions configured to detect behaviors associated with these RATs, such as unusual process creation, use of packers, and suspicious API calls related to Discord bots. 3) Apply YARA rules and file indicators provided by ReversingLabs to enhance malware detection capabilities. 4) Restrict the installation and use of unauthorized Discord bots and clients within corporate environments through application whitelisting and group policies. 5) Educate users about the risks of executing unknown payloads, especially those related to gaming or Discord communities. 6) Regularly update and patch endpoint security tools to recognize new packing techniques and obfuscation methods. 7) Conduct threat hunting exercises focusing on Discord-based C2 traffic and related artifacts. 8) Collaborate with Discord platform providers to report suspicious bot activity and seek assistance in mitigating abuse. These measures go beyond generic advice by focusing on the unique use of Discord as a C2 channel and the malware’s evolving packing techniques.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.reversinglabs.com/blog/tracking-discord-rat-family"]
- Adversary
- STD Group
- Pulse Id
- 6904823ed648a76ab78fcf7d
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash16f62ac70fce821c4dc6e178d7ff0ce4 | — | |
hash1bb55cc26dc0904ddf0c2c0f6c56de20 | — | |
hash25283b97624e5a25b8d45be7cec0edcb | — | |
hash25c095a512e9b58f07c8174c47a82535 | — | |
hash275ef20b19ce085ad9a6f4555bc45947 | — | |
hash2b0c0af9956928604aeb5884d888cb89 | — | |
hash2b17e069dc77ec1ec65cac43cab37dde | — | |
hash2e0fc51860d7a2b72bc34410b956b303 | — | |
hash310b0d940edd2fb9761e20ec08472c6d | — | |
hash326d523fd53f5d3b72fecdc1a6fb7574 | — | |
hash330871792be237fb02d23114ae9be52e | — | |
hash37892e769d50536aaed53841c6453a78 | — | |
hash38525d335798bb934c7ed0027cda4adb | — | |
hash385a04f1c5ea4d843c15576c082b4561 | — | |
hash388b71dbb9c4bd25a1e757d21900cc61 | — | |
hash3e05ed5f590ddb2ba45a1c213b96a990 | — | |
hash3f3dbf91aa19a8e2b1e4c1c603f64ac1 | — | |
hash4293afb0df2bd4f0507c76d918a5f262 | — | |
hash4419d4b641e1cae10e61aa95fa8dc3bc | — | |
hash49db7426b665fa482e91c30d7623b151 | — | |
hash4e37f91f700b038da2ab7545b0c19e60 | — | |
hash5965ec0c37d5b3b05c6ed5b967f45008 | — | |
hash5a0cb54e42395579a8db3a1f302e4aac | — | |
hash5c6284b9d15895373fb05aef32f369db | — | |
hash6883238db0555c1b085545322127e892 | — | |
hash7246e26cf2fe62899538f44cd737689e | — | |
hash72bc4606848e068683fa077a9eecf7da | — | |
hash746b9227c53a0448a29698155ce884e4 | — | |
hash753324fedfd7e77327d964e3bbe4d0f3 | — | |
hash7a91c9ab7282b395d89b8b5cb97645ee | — | |
hash81356d2861bcf015bff0a9a5b02d2af9 | — | |
hash81a69c28e46c22e144bac98d6d2a5e0f | — | |
hash83b6e8689922d7665594bf95442e761a | — | |
hash848692fd2389ca9c7ec26d25e32c3ec6 | — | |
hash84a6c269b690b567aa465d52cc653959 | — | |
hash8784f906bda125082f7384b58766f7ea | — | |
hash8841e83e6c759a89f7cbe03280ff52db | — | |
hash8bbfe6fc40ecfddb3bb27d26b40a7423 | — | |
hash8ebcb94e7cc8c969cad76beaa132f08e | — | |
hash8ed2624f2db2e85c6f4bec0182bad13a | — | |
hash95a07a5529b2425e279ca7b8b0e92e0d | — | |
hash96643baaf6b27a9cbe9161c68faabda8 | — | |
hash9b4f27e3e19e8e39d3d0599ca901fb80 | — | |
hash9ce0c12c334d50ade8b84f572323ba4d | — | |
hasha466df72d1a9c149ca0a97893346092b | — | |
hasha8559547cdf9fb49ae4f1f743b80d09a | — | |
hashac69eac215fdba0401591c1458cd9f46 | — | |
hashac729fd7dc97b754ac3bb750ca986e4c | — | |
hashb80d696e433b17af3724df0ea5e3934f | — | |
hashc22306bdcafe16caf171fd314906ef75 | — | |
hashc705eb0cf8aee3fb29f4b75d290ff255 | — | |
hashc804423ac19cd0305fcee8ce57b3aefe | — | |
hashce9d35f37f1e719493db56df6bcbdf80 | — | |
hashd886b719c1de39f5da04bc872f6fd003 | — | |
hashdac6dd07867124c4bd8da78d1f3086f5 | — | |
hashdad463abb2e45c806568b7b23028f355 | — | |
hashfb57b32d1cb4431d8a628cff2ba9f55c | — | |
hashfe6a372458fe26aace5f37ad2ede3cad | — | |
hash002688f6733d0cbc0b8998b58661594d4ab0e4b3 | — | |
hash06f29ce71ab3757c62e34de2874f89ab80b512a4 | — | |
hash09f96961a0b82a2df10e04ff0edcff67d6cd54e1 | — | |
hash0c326bc2f94ad8ef3cf4c59184d50a6cd90e239f | — | |
hash0cfe02dcb368c44294d96c2b7f598566eba0d78e | — | |
hash17e2c880c28b56ddcf744ea3f9c32d3be18749aa | — | |
hash1b531cc6a22093b0cb7a4ec8d4de79401cdeba37 | — | |
hash1c15184e2711fa8789ffb4fb02e22f79d324a1ab | — | |
hash219dd0a82cf8e7e07c5e583ad0c1836b8e2b61e9 | — | |
hash23dcc294e938e13604f8bb5963fc3b415950da7c | — | |
hash29249d7c3d9fdb7b51dbcb187988be5e0329a704 | — | |
hash2d71b06086b3b6c5a2476813878c273d97b8b27f | — | |
hash2e0c188eeba59d952eee34d5a5a487cc2a31fa1d | — | |
hash35096132bb821f4a0968067c22c571c285079db9 | — | |
hash358b1422c4dacb0a3482b6004ad19c252cb020f9 | — | |
hash3b60a47a4b7bf9ef01b172e18c336272118772b5 | — | |
hash3f72b3ec01dc2ae9e64d262c03586fb16e8eb7cf | — | |
hash494041c60f589e8a07f365f3d474c9f4af86485d | — | |
hash4a1cde90cde3b7f12fb5eec8e975ee95ac5bf13f | — | |
hash5891af6fbabe0e1f14fe7f4a02e08f050690afc5 | — | |
hash5bf3edeb0be696217b7b19da7aedd9feae77848e | — | |
hash5ffacad5a9e8e4e7e081ccd38ad0ebcacb7f62d3 | — | |
hash6232be28ceb6758386fe8b9184412a3ee2b5e886 | — | |
hash65a7f80365a3e53b14ac3788fd4b0a7dba0b9436 | — | |
hash6a0766aed2eb98697e79f8c089a7cccc2eb55f16 | — | |
hash6ab68498f86f6e643bd719307b7d510c59a4198d | — | |
hash709d1692c5c847146a3c8fbc56b0b88bb671a56c | — | |
hash70bec731d3dd1041e7241a5a2d4b206eb32fe9b6 | — | |
hash712ba10945e498691ad38a921089fd581eae7999 | — | |
hash7a63d0343062698b2c13fcad5c15a6b1181e559f | — | |
hash7dc09a0716af7b39917ac0e772cf943888b8927b | — | |
hash86801041d33e568f00c2fa7ed2db3ca4a46ee18d | — | |
hash87962a26443e54e35df655f90cef58326818c99d | — | |
hash8eb4ff7c59b978eeed378c2f97da12e258ff1b20 | — | |
hash935a891f38e21e35ae757e06193ea0c5932a5582 | — | |
hash95c3094b7a6982ed933ba4146583176a91c41f2e | — | |
hash974b28d0ace6c2500af37076240ff27ba358d32b | — | |
hash9ab90ceb97f0bccb9ce1651b8bed5ea7acedead2 | — | |
hash9acd2aa0ade17d154f81f550f5a9c648b9f16c46 | — | |
hash9b407a4858b83898e46292f1fc64be9dcee47eb3 | — | |
hasha214c224320c2c06d35b4124b48b2da68974b391 | — | |
hasha55dd3011f53b6e0e656d7d659982c9965f501f8 | — | |
hasha9474fff7357e6e09c08305a1a1cf96085ae5403 | — | |
hashadde86cf6a8ecf0a5b3a32584c6e435cbff6386c | — | |
hashb073567de4885aad3e758cbe80cacfd186d5e2fb | — | |
hashb2534d7688c6a2c984b02ba28038af0b7a106808 | — | |
hashb3cd563cfa231a5b5d63bac3af796f1c66e2a165 | — | |
hashbca08c0595783adfe389604df30e81605b6d8d52 | — | |
hashc34a6c519823ecb89289e56a026613c807d5eb23 | — | |
hashcf875fbeefd3b96f881aa1d1993debec09d3b06f | — | |
hashd4585f5d61adef3a8e2652569ec63924153c50c0 | — | |
hashd6725531b2a0fd923fe4fb8d699f4c9ed5b974d3 | — | |
hashd7d9ea74bef47c5bf5f9cfed2a23991a98134f21 | — | |
hashda7c67cd74f7d33e0974f7d7b4e8dd65ae09e58f | — | |
hashdd19c315af10dbfb8485e2bb00519b7062c5701c | — | |
hashe525d70edb2cb8f6e0ce5218391960e52cba5d61 | — | |
hashe5df3b8512175ee06694a49fe28165608cb748a1 | — | |
hashf60720781f081c784ede5d8823b42906e90bd179 | — | |
hash000eed382ebec21a1f27a860cc52613cdd98fc36dd12d37bad15caeb36846d7f | — | |
hash04589839ac2f6bd9ed2e958a6085c9070c6844e2c9abe15641f8befa70a65a98 | — | |
hash061799cfc23d3689870ea6abed1f8cb5f595f63bb810ef7c829376c9c5cea921 | — | |
hash0774e3488e6b762dc68c59c07576c6623f9066e38e4b0845e3b3a0fba8041958 | — | |
hash09959d473a1b842bb3d953a71ed0e7230ae32f16036805b09806dd626fbef580 | — | |
hash0a54750e93f9e716b3ce206933b0c8d0d4b2771696ae0104478fe009879b0ea8 | — | |
hash0cde3036878b3f0fc3dfe44a281769823948bc7bcff22f9c2fced9d5406ddf50 | — | |
hash0d0671b0da75b1730a3095d51b5f3f107ddbbbf1bac4369378cba083c414b886 | — | |
hash116d35b441fab38e6d72a58ec113535620a7c13e36f7e11d3f36cabeb71d3032 | — | |
hash12507941a6f3742efa8fc866112524217ee7f906ac19f3e20a0bda5bc28397c1 | — | |
hash12a01041764caa20c4f12f21531865ab73eac5539561f597adcb871b56e444de | — | |
hash12c9cca4b13fb5fa772ef2991afe06c25a3f7dca89dc2faf15b0bf6a22c15c92 | — | |
hash13ea8800215e75c1427ffcbb1ab475d3cfdde7227d95688203f80fcd957ec817 | — | |
hash142fb1ce5ee9b8ed3145caca2021da717ab546435f0303c63531a45522cf668e | — | |
hash1582a8f6c5bd486192de99a286566d09bf11a47cf3d3fd55fae0a3ee646b1f28 | — | |
hash1a1d3d897d0b6eb8836e15359fc600b3790a3c621a3cf0d0cbd23c88e9e8af69 | — | |
hash1a4382141f9d4910a172089048157052a053d3ae81fd2ae660632b849d606f2c | — | |
hash1a6c4df56b01b53d31f5f263d96faa7c534c183ec59e6dcd14d7481ac1acc09f | — | |
hash1ca659cfe2f40695a250ca3c6287ed3691a268d6f7fbffbf83a5b0bb0ed0a528 | — | |
hash1cb3e126db89fa922616d5bee319775b366eb850948a14f29d1a6cb96866b63c | — | |
hash1e4856791ff06948959bce04f815ed6bb58a5e220e3abaee5b7d50d6b9a1d65c | — | |
hash1eabcc4e360b855521f0d3c5d3830daa169e81357dc8a109302ae9f76ffd45a4 | — | |
hash202083aae976ab71a75d2d185e918430128bd845d125e55395617bddcc1d01e7 | — | |
hash20ec15898814ac2bb574b526a7070c7044e33b6f87575206677ba3ea5cf2a24c | — | |
hash2232a2ec8a45c25ac04afbc38e3fd41bc9024033e1b3ed93f0422cfc6a84344a | — | |
hash28b6c2afff094e05a68c2ecd05b0507a4bd290a74410a89e0c35fa30f78c788c | — | |
hash28fd5a8e4d69285724858b8d8fdaef0f9af65deca01c6a0b335c544b7b51eb90 | — | |
hash2932b243514af400307955985d58dcaeae200b9d7c959146b60c93e2f2f1c485 | — | |
hash2c105c535af48b11d568fb1e718ab172c0346937fd96b3b8039aaaf617edcf8d | — | |
hash2d90575dadcfebfb6599b17d70c8f9494819276629b116b4bb43515f90e827f5 | — | |
hash30501b866ca2f0c9a8db01ee842bd5a9527e413bf1fb52a39c70f21d74d337b8 | — | |
hash307c6c77cb0c50ae427fb316ab8f2c1362715b6cabf43391d36cedc3f1a3e846 | — | |
hash30fe2f72e06a5d1cb966e868196bde5547e586ba8f09bb8152fa8d2086372d0a | — | |
hash3391c12d268cc10419bf6a48bf235fab1006d2e61ac91cf039a30ccfac6649e2 | — | |
hash33d6cbdcc208875a1e83b4fe215ca0d902ee3860165fb9b94b3d2a00025f925c | — | |
hash340228a3396e378880837445c46bf2636d3973848a9513b877fb2bf1c5f4ffa3 | — | |
hash35f24e9c2b1f349c42495b0b5f4d9d77c1fb9ef0a5bcd8a30e85966262e3b00c | — | |
hash3636ab2e6bd670b933378e844159bf3600250f0441f14160cb83859c30c7c4ee | — | |
hash36a6e50c5fef6ec99151969ff90fbeb6dde974a37a0d3eb5ec4df5ffe3ca260f | — | |
hash36fcd429f3053afd1a3d80682b56216c0d24b4ec8b99fc943aadf36a64d4f35e | — | |
hash3867ee71602b654d1f127901670003f06c699ab84edb8b1c63f8211045388d74 | — | |
hash39866c5378fb9a7fcd22b8fdecc475e2cc7a2c91b57a953e514213a22fb5f194 | — | |
hash39b73542cd04fb0e74d788256653406a60830078a794b13bbab22aee111161d5 | — | |
hash3ae2fd48b95b8de8dbbbe1c3bbf80b89bd8885fa9a9a27e690eb808770338c0d | — | |
hash3b693725c879a30291408e01a82e6d8a433b4578206c84493b4898fc0ee49e72 | — | |
hash3d3be605ba3d6532040023aca9461acc4b711889fc4411fa5ecb661cbf0ff5d6 | — | |
hash3e8435ac3726315d21afb12a8e47bdb347c2af362be4ccb1e05df5a33874c962 | — | |
hash3fc319e3edd19c962179e8ed21bef5a9d2a32edd4f1b17677600505010a49611 | — | |
hash400a9207d39e3eeb4256902a82ada6b78cfe43db5c53fe7e068c86b30e7d4461 | — | |
hash40802de4630cfb94f9a458ae678559680d6a459152bd96fb565e2a45a85531b3 | — | |
hash41fcba17e81df0c852d70e6e2b13a8d3b163d70410dc05f737dcceab15fd4f2d | — | |
hash44122eb155dfb5a81f3d27999ff6f2a6bcba2bb8d4041a61c8553743871a1f89 | — | |
hash44623c837caf40341d187b5b5e1486eaec2528d0af715310ddf6c1c4b7b9ccee | — | |
hash4609455dfa0d1957c970bcfccbfbeeba78688f4b42ae6cf27aa6b3e43d3f08a6 | — | |
hash4739dc5f11c309e520825b71054e83cbe0d5477fb69ded411162993da67b1211 | — | |
hash481dfd997779ebadc3b9390c97a267db3d5b61cb8275c2ca1c55561efa49a220 | — | |
hash48f10195a2d4dab6121f1dd2792e5958aeb2db454cf3276d90acc24fe74edc23 | — | |
hash49ff98529404bf03fd88341e6e9bc6eac54fb5f9c1bbfe46c3ea891533166de1 | — | |
hash4aeeb684566572bf0b7f045c8a7b1a98d273767f6e0a8b76b9098ddc7a5301e3 | — | |
hash4c682ee5f1646c4821e3ac88c570d3f65f1e34e13b139459bd8b165dca36c49b | — | |
hash4cce2b038ddd73ea8d6ee059bd8bc2a814829823f69647d7f87c9f5af75ea1b4 | — | |
hash5036e245217e91db237ba428be1e0ddeff71859a55a3cdc42db6e35be38661d8 | — | |
hash510cd3b9de265e44ca4467833dc17336f2afdfd4df203e43bc51e85767e88702 | — | |
hash5180c17fd25d52422d1246ccff4961e44d7932fadf8633b03668953fa3f3a664 | — | |
hash58b0b01514ff9da571c18b0b8f91a7840884424811e21e4b19b8860d83b50a4f | — | |
hash5a1df5702683628aac4657bfd80ed7571a746fa5242dc6a353a2f6830d027d53 | — | |
hash5d16e3b5930da291790c6ba70caf4a88067b1e11aecfd1f7ea3a88eb9e06dfb7 | — | |
hash5eb04ef949abaf560eba8d235aa00c8eba2e349c6201571961c904a23a778f1c | — | |
hash5f30c71b5b83b3924cded96151a621b0292d6682d580861c95a916038aad9485 | — | |
hash60b14a10d81a0253694003a2294f93ffb6d2c1efd32b644cd450fd0a8d8b6f5e | — | |
hash62652633076dd5e5a8ff6ef730bf6d0dfe01ffaf869395a5e3836f7b728b7602 | — | |
hash62a10917e3da538fe4d482f37b7939b54a08396665f484fe13accb3db9e64427 | — | |
hash64251424d1417e14d4a220d2cb30500961f659cd8f7969209a9bbe45d4cd312a | — | |
hash646fa42f3f05133345c9fc9cc7f8d4b4b1188af73415140604d9eb95e4ec905a | — | |
hash6603e7a118494282fa684be85dabec4c085492cacbd95c78cc45c30d4abc1d97 | — | |
hash667e4d67acff2b8e60e3ca14075d33e51cb5269512b9208241d9381b25192f17 | — | |
hash679cc9ff7ed27407e37a028d945ab0895becccea18f7ca70ea8bfbb79e2d82de | — | |
hash683453d1b92f8b3db65ec7de31036b248ea04fe8f250a4c0e3a8596f1236d1a0 | — | |
hash68dd4aa92850fab76a6a23df41166f0f706da811aeb340710459c21b357794ea | — | |
hash69e2ff214cd59ffe3d58a07f53e6cb03cb7e610fc90b01635077a1612436e75c | — | |
hash6a201fc8696dc8ceff68c9829984b16e9994bc7c0a774bdd1859efec60f4d69b | — | |
hash6a987d918f400dd3c0840917845743f8eedc0c83efc5a9e7089bcb09169dc606 | — | |
hash6c87c3b522b1d84aef3f78a9d8099ecbdc8352e1b35ffc32436c90f228f825be | — | |
hash6de6fd9270dfd007f375782b76854b7cdd21b48994def97457265d3c047fb092 | — | |
hash6eba18e9a1f0354d81fd124da7a716a587678821e855155a2bb1e2bb93713758 | — | |
hash6ebc9ae70ca7c605acf342c7bccad069fe4dac95b850812c7585ccf2bc28e24c | — | |
hash6f19308935915ff4b6b7d231f477cb90a31800671f2407a152d8547ffcfc9c9e | — | |
hash70fc6bed8574c2c2d0bc8f753d8d62430224b08bdaa26b8152d7756961c03a09 | — | |
hash73f310328bc78edaa86e4d6519e192af6bbabbf80591a57eab30dbd0d4a9002e | — | |
hash74537b0bebc09b7de8dcfaa72a2dcd28fc2a3d95a31f2f3f2671a18aab88e093 | — | |
hash7464fa2a457d001dc7a3080391dfd1c9e33a8f43bdbcb8403b60b5e3d1c10229 | — | |
hash751ee3e15fd9454298bb0c3db714bd32b92b0e4e109e8218389d20de8bd935e2 | — | |
hash772cba090376101576015e269f60cf50b2de1180aca84686307945b661ebc665 | — | |
hash7a594591ece534e74299e4660ac0e2c458fca1136920f68904b6408c7e7e1071 | — | |
hash7d796e90c7b01e44220812e5a3e3ba32b0b3707b75491b3c81a23264616e5e70 | — | |
hash7ed399614e5e234d32eadcc9513ce2001e4e09a81e8fa1f45fe9a93610a37225 | — | |
hash81d6b086ba1f84cc146011300b7787b5586c4d85f04d9b10ba1685ca2c5836ac | — | |
hash82906c572d6bb9f511183a4c18fdff6d399bbad646c0d47394c8329f0d9dd47a | — | |
hash8437f50e7fc6491d96ef41431f967fd9fde63525219f7fd0d9c9ff93b1fad3e3 | — | |
hash84a01c5607791856c849e0db4b15e29dc21f7a04fc8540c085b86a820d687a15 | — | |
hash85f8ccf69bed672d92b40c45f9571378a7d00c80b86004a76018d9e120eeaa01 | — | |
hash89b0ffa674c8a2bb7636079a0c9b8505105bfdf4e0c76422aaeb5720423798e1 | — | |
hash8afaad8f3657e978790860174412ff82a7673543fc23228012fa13a894ea1e72 | — | |
hash8be83c870b040890638e29798e7a7e2f77b2e298222785fb04653fd4d1943c95 | — | |
hash8ca78f2eb59302102de3b8e471cd307513e655cfd0f872f27d2640eed0e3b4eb | — | |
hash8d47a214344c1af6da38772556c3b9e1dec27c53ea23360e3219845c67cda5b2 | — | |
hash8e949697effe4c46daf0c7e0d00a5f2081f9e457fc8053826677d83ca769e363 | — | |
hash90260da07172586c4e8a8653077edb8be7f846cc9fd5db2e18bce1aa521e565d | — | |
hash92ab1a93499aae4c8b0c47476b24af5f1cf209f39857f654dc7e567e40f84c30 | — | |
hash9437005de21d45f9ffa4d4a1f0989f42d1b513fa745213d76993c721b7f59667 | — | |
hash94e2fe3928c4d3243a526a58bf3c854969d75dec7179adee967efa6b7f424d22 | — | |
hash97a05771adc063f3223354ef4ea2956abce095a9ed56ecd40761abea322250c4 | — | |
hash97aab6ebd8fac8a2ec7c48c06b886103ab8cf98a9760f60c8071a485c77c1fc8 | — | |
hash98b4c878d93fbed658aa05f518e610506cd78f3e0d871c92eeb84ee781dcbf24 | — | |
hash99a56910caace53fd223710a10825683772d730ab11b41c0dbdf8ea50007edc3 | — | |
hash9a1d86487fd9eb3d36aaaa05afb382a1c37420491d61b3492c02a68eb50b709e | — | |
hash9a4a2b8720cb6cbc16c6450a9d4f7e78b12406690ad77f72300029b5c0f852e4 | — | |
hash9ac5bc1bc05457941d96bc5be8ad4c1dd5258fe337e5bdfa27c649ea4bbc49ae | — | |
hash9b60635bf858d1f432e726a029c7386ec6d17b2cc2e77845dc647200c7802312 | — | |
hash9d524c8444ee8d6d66976c22456e7ebf54395e53be35c5aa69e180f6f5dce74c | — | |
hash9fb33b4a7acdd44c6d440560c8280024e72dfd0a6f8c8b1c83bcb4b7555b3c87 | — | |
hasha57025157be76361ec8fc1dce54b8964538f32f620cb22d5c8848e24978eaec6 | — | |
hasha5fbdc052a07a2ea2f13891596001e9ec1d8fac940ea0a3599597a7c48d67a77 | — | |
hasha618a75488fb3e0031fa15b89da4f118db452257b18907436ae3e64aa03f6877 | — | |
hasha6287162def3932558debccc288f2a2a1f04eba7dca9e2a2d64de8146808466b | — | |
hashac5a5a5f76815b9d61f7ce83d555b237b3ffe5dc92ec3719e0990ce4ed85fe3b | — | |
hashadbf546702820ead085f4f3b786993cf6e8a1f21fa55d9655bffccc70eec93c3 | — | |
hashaeef6087b0d022bf8b103c5813c0bc0a5e964189583f03cfe55defc0c3bf2374 | — | |
hashaf03448c80d22769103fb0025943eb0b0ef6f7c0acb3df170c78fe1de08bcb41 | — | |
hashb0512b00c39de877b82417bb1aadaade779c1fb409284eb84da2ba8ebb2931a7 | — | |
hashb2a5b626583786c84d7ebea403700b2785907e1766233c5a49d485ed46dface9 | — | |
hashb3f7dee0b69c1f0fd8512cfcd673fa5d928e8415f356de7d2a598b9fdc0a31e6 | — | |
hashb44f58b17096abf899f48a1703ca0564950634d90acb7ceded6d372642dec346 | — | |
hashb4ec5581a655597ce432b1a4a161fc89cad73bad2c0bd2a09f155412e511b546 | — | |
hashb536d4655560395df4eb3d8f9b46590f31023a1b96a75e32cd8d20192435a1e2 | — | |
hashb71a133ae09604f17fbebaea4512e251e9404c865b619d18f07ec3008d1f2f6d | — | |
hashb8a13d7758cdf9d8b80fc2504866e9a26ca348f4a940ca6a451754fa61564f73 | — | |
hashb8b4021fb3083a2feadcf5cb755f2e66561a1f20949cefcf83c21b508ff8dbec | — | |
hashb8b68aef7ae26a5aae1e9d35a1cf2fb54b77307b48b596424683eeaed2343627 | — | |
hashbc800e5252da33803ce2cf6ffc06c899703735ad72240b54f34b0ea7389cfd47 | — | |
hashbc9f0bec077a6f406191b035e5ae35246c12ffa7f36c3424002dbf0e01e49820 | — | |
hashbd60d56fc8cd50b403f3171a2bd5ff540d9e741d9967297af132448b5dafbbf5 | — | |
hashbed69afbdc147c31728bd79708c6056499c95edf731250493ca064de9c5f513c | — | |
hashc0d98ae50837044d61ecc88f2f1d9b74a35ba8e0898d3bdd80517323ba5fbfe4 | — | |
hashc3141c72e98fd48da3546217ada5e31b6786041bd0b24373ae91c9e36ee7a67d | — | |
hashc3abd4e97d004df3094d44888dc19360333f5981afe2d0b85b80fff47c4628ce | — | |
hashc5863bdec64be0cb662efce9a8bbe2bde0b96132717d89c74ff0e566903143eb | — | |
hashc78d8f99b69fc5c7ceb6d0d0755cb7b8aa818a77ec4ef574a25e8d79734aa0dd | — | |
hashc901285252c58d1bbb0020a9def9bdb9a62a70df9a933199daeb694d21038b6d | — | |
hashca54d10d45fcc04f8581f7c0c5a53b41f47858bd9ee6c224ee709b162cecdc05 | — | |
hashced35c008c4d1d774d2fdc493f66ac4bcc623ada7f7008ff5b12f895848f7e31 | — | |
hashcf37a6e873bcbf22841e27aa466cbf3e356bb389b862dcd55453097d79beadf8 | — | |
hashd00b71ed37cd2c62f762b31b3f77a0f5791ea29931de317915682b1e967785d0 | — | |
hashd3346bddc69913ec98838fdbd63cb75a29fa9353e27be8ede9d8dc4fb9f40b42 | — | |
hashd3446ac50fcdddb11c3b1d334e905b5823a43cf7bee690e666f0d0f624de5f08 | — | |
hashd582c6bc50fa4f6c5a3f1e07ea33f61d4bd5276f76a66e65c68f5a57c3c1f511 | — | |
hashd5c6e3ac4e471641995aa15c108d962f68e371caa5ad20d45d7f78e3732932d0 | — | |
hashd6f6947b56d4b1d6dc524b7940c7eac7f13930371d37347b77534c038c20140d | — | |
hashdb7e53791455769db95e95e15c9a9ffc77ec1c4724b0c46e020478949996d097 | — | |
hashdf299e3f32f08298c90f322491204079d888422fe0e73e87566e43583a3c534c | — | |
hashe18519525f442b8e6e97b5b503c041c0f548d4bc9b1538881f31dc5bb72d6f18 | — | |
hashe3a8ad4428b9aa93ab4c3bd83e5f7aebca9a70a1f7043b022411691a3aae3715 | — | |
hashe4eb15c56cb3711b83a6dabc7cb9489e209205aeea7b4a92b1039ddc069f6e69 | — | |
hashe545da3a7624d5c8c7fef362194619e39d215385991a79978a518d5be4212691 | — | |
hashe6353eb093a2ca1dd4bf336a5ea80bef7306be0c1d2848e59ed8f87e5df825bc | — | |
hashe6689e14ec941295ff2b33ac484999239504ebcb6e9daf803b11d2652eaecdda | — | |
hashe6fa6f2b014ea80b19fe14ed20aaadc8ff7b7505efa326833c96fe3ff37b9261 | — | |
hashe89a30a0a7c387d74b274566557a1b45a62dd8dd9842181a0dc082d626657c69 | — | |
hashe8c4e84db1ccecb62499548e40393979f23ef3356b22a61bee08ebe8f5ef03c1 | — | |
hashe8ec993c0ab37471ddd3a6a7e117147dc2d404817cab5845a6eb5def60c5d0c4 | — | |
hashea950729734765ece6fb230a65b110e4fb0d60b108a52459e2fc3854fd5547ff | — | |
hashecac78dc376b08a004d056ad29d57ddd96905b94675695e4d5fa78d81c02dbc4 | — | |
hashedb9be32ce811b0d51bc871b5ad75036f7750f5d46587855e01d167532486b6a | — | |
hashef2043b996d7ca0f5dc56c26e1b9299dbc732f879379e1b9845d523b683b3a86 | — | |
hashf3ea2e40da7c674312ef379275b36777db95da21564d9bbb868f919802a58609 | — | |
hashf411482e1e187d0b85c4be62459159ef83874b6bb19d88de38e70e530c6178b6 | — | |
hashf63fea79d76b97ff0e7c484c05739261c6beaef5cfd9eb93ad9e4fe5afc16aea | — | |
hashf6504c62569cd83f18f2cf50d7d7ae260ba0da38e86fa055d2892591f0544560 | — | |
hashf98916ba5138dd6f233023a3b9fe5e969a50bee3d7cfffb69900f4d1d39e02b6 | — | |
hashfa72c468e57411f896b71852621e5778a7dbaecc9f70119c0898dff8ba4247e8 | — | |
hashfaf0556d746a0161f149db0ae8eb74a1dff4a114502360ca547920aad4cc9f3c | — | |
hashfb4c58ff61d8e43a744e3928ac0e0823ab1d106d8ef1f5171495c46eb3570780 | — | |
hashfc213a5f50b671e5b0914b2cea4354a3394aaafbf7a4a99ecccb2db31b78c76a | — | |
hashfcfbe3559b24a0468785f0d84880c9371b41bb9893fa74f69e130908dc6dd562 | — | |
hashff70fcaf5bf42d19f9eb15bcf7a8227f6af22c19eee1b034b427109960b52e37 | — |
Yara
| Value | Description | Copy |
|---|---|---|
yara3a11738952f549db5316f7f1c56f44977160496b | — | |
yara7020511e5c03b9203600175a9cf2829fa3e871f7 | — |
Threat ID: 690498dc60041281bb1ceeb5
Added to database: 10/31/2025, 11:09:16 AM
Last enriched: 10/31/2025, 11:25:37 AM
Last updated: 11/1/2025, 1:24:40 PM
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
LotL Attack Hides Malware in Windows Native AI Stack
MediumPhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs
MediumNation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
MediumThreatFox IOCs for 2025-10-31
MediumRussia Arrests Meduza Stealer Developers After Government Hack
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.