Submit an indicator to check against 70+ antivirus engines.
Recent security findings and community activity from the global intelligence network.
YARA Signature Match - THOR APT Scanner
RULE: MAL_NET_DCRat_Feb25
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_NET_DCRat_Feb25
DESCRIPTION: Detects DarkCrystalRAT (DCRat), a .NET-based remote access tool and credential stealer malware used for...
YARA Signature Match - THOR APT Scanner
RULE: MAL_DCRAT_Feb23
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_DCRAT_Feb23
DESCRIPTION: Detects DCRAT samples
REFERENCE: https://blogs.blackberry.com/en/2022/05/dirty-deeds-done-dirt-cheap-russian-ra...
YARA Signature Match - THOR APT Scanner
RULE: MAL_NET_DCRat_Feb25
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_NET_DCRat_Feb25
DESCRIPTION: Detects DarkCrystalRAT (DCRat), a .NET-based remote access tool and credential stealer malware used for...
YARA Signature Match - THOR APT Scanner
RULE: MAL_DCRAT_Feb23
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_DCRAT_Feb23
DESCRIPTION: Detects DCRAT samples
REFERENCE: https://blogs.blackberry.com/en/2022/05/dirty-deeds-done-dirt-cheap-russian-ra...
YARA Signature Match - THOR APT Scanner
RULE: MAL_Xred_Backdoor_Mar24
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Xred_Backdoor_Mar24
DESCRIPTION: Detects Xred backdoor
REFERENCE: https://www.esentire.com/blog/xred-backdoor-the-hidden-threat-...
YARA Signature Match - THOR APT Scanner
RULE: MAL_AVKiller_Jan20_2
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_AVKiller_Jan20_2
DESCRIPTION: Detects samples with many AV process names
REFERENCE: https://labsblog.f-secure.com/2015/09/17/the-du...
YARA Signature Match - THOR APT Scanner
RULE: MAL_Qakbot_Stealer_Mar23
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Qakbot_Stealer_Mar23
DESCRIPTION: Detects Qakbot stealer
REFERENCE: https://lab52.io/blog/bypassing-qakbot-anti-analysis-tactic...
#malware #asyncrat
[b]VT Collection:[/b] https://www.virustotal.com/gui/collection/5210884d2b3252071a08175a485fc294288cbb6abdbd25321c8fd043d85becf4
[b]Reported in:[/b]
Hatching Triage: https://tria.ge/260722-tkzgpscp6x
Intezer: https://analyze.intezer.com/analyses/d2098cab-e801-4555-a008-416c540797a...
YARA Signature Match - THOR APT Scanner
RULE: MAL_Salat_Stealer_Jan26
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Salat_Stealer_Jan26
DESCRIPTION: Detects SalatStealer, a golang based credential stealer targeting corporate credentials.
REFERE...
YARA Signature Match - THOR APT Scanner
RULE: MAL_Qakbot_Stealer_Mar23
RULE_TYPE: VALHALLA rule feed only ⚡
RULE_LINK: https://valhalla.nextron-systems.com/info/rule/MAL_Qakbot_Stealer_Mar23
DESCRIPTION: Detects Qakbot stealer
REFERENCE: https://lab52.io/blog/bypassing-qakbot-anti-analysis-tactic...