🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash eaf98b4b08982bc19385a501e3afc3ad52e711ca48f3fc5f5b63719937cf1a64.

Database Entry


IOC ID:1771246
IOC: eaf98b4b08982bc19385a501e3afc3ad52e711ca48f3fc5f5b63719937cf1a64
IOC Type :sha256_hash
Threat Type :payload
Malware: EtherRAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-03-19 06:25:27 UTC
Last seen:never
UUID:205293a0-2349-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:EtherRat msi trojanized-Kusto-Explorer
Reference: https://www.virustotal.com/gui/file/eaf98b4b08982bc19385a501e3afc3ad52e711ca48f3fc5f5b63719937cf1a64

Avatar
Lenny_3BO
Trojanized Kusto Explorer MSI. 4-stage: WiX MSI -> batch downloads Node.js 18.17.0 -> double AES-256-CBC decryption -> EtherRAT JS client. Ethereum blockchain C2 (contract 0xe26c57b7). Registry Run persistence.