← Reports

Remote Access Trojan

VenomRAT - ClientAny.exe

Author
Moise Medici
Updated
15 Nov 2025 · Completed
Difficulty
Easy
Platform
Windows
Capabilities
Persistence MechanismsCommand Execution via Powershell Cmd BashData-Exfiltration
Tags
C#VenomRAT

Indicators of Compromise

Network

  • https://paste.ee/r/7467kw7n/0
  • 1ri7zwh3k.localto.net:8301

Persistence

  • dadada scheduled task
  • HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dadada.exe
  • OfflineKeylogger mutex

Files

  • C:\Users\REM\AppData\Roaming\MyData\DataLogs.conf
  • C:\Users\REM\AppData\Roaming\MyData\DataLogs_keylog_offline.txt
  • C:\Users\REM\AppData\Roaming\MyData\DataLogs_keylog_online.txt

Hash · SHA-256

  • 8f5bb49ef2c1178c113d477f70856b3d59a107a6f5a551199fb5ea0be911c496

Low confidence

  • C:\Users\REM\AppData\Local\Temp\tmp8A48.tmp.bat The file name is different on each execution.