🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 61ad42d4854e0e9b8c6e15da2006cce40330e74b2fc0eb725766e515a0e26988.

Database Entry


IOC ID:1777472
IOC: 61ad42d4854e0e9b8c6e15da2006cce40330e74b2fc0eb725766e515a0e26988
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown RAT
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
First seen:2026-03-27 17:44:19 UTC
Last seen:never
UUID:70734e38-2a04-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:CTRL FRP RAT RDP
Reference: https://www.virustotal.com/gui/file/b1688ccbe7d422328ca6e97b8da8f5652c16eafc083da07ebdd8fbd3b23f6be9

Avatar
Lenny_3BO
CTRL Framework RAT components. LNK dropper, PS1 stage 2, .NET loader, ctrl.exe main agent, FRPWrapper.exe (FRP relay), RDPWrapper.exe (RDP enabler).