PULSE NAME
Analysis of VioletRAT malware carried in Italy
WHITE PetrP.73 2026-03-08 Modified: 2026-04-07
14
IOCs
MEDIUM VOLUME
The analysis of the VioletRAT malware suggests an evolution within its operational infrastructure, particularly in a campaign targeting users in Italy. While earlier assessments left some ambiguity regarding the malware's identity, recent indications point to it being VioletRAT version 4.7. This version appears to operate over a different command-and-control (C2) setup than previously identified, potentially indicating a segmentation of campaigns utilizing similar techniques and resources.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Violet_rat
Indicators of Compromise (14)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0d28eb747209210bcc86be5baf9ae2e0 MD5 of 8b2f8f5ec21f82d5925f77734a6ef8b48156a729ff55e1deb49277985610d34c 2026-03-08
FileHash-SHA1 d2f41c41b50f5d113a7470bd543773a3f9f532c5 SHA1 of 8b2f8f5ec21f82d5925f77734a6ef8b48156a729ff55e1deb49277985610d34c 2026-03-08
FileHash-SHA256 1d68572db63a01f71ed9cc0dd75e87ca89bce40016ba5ee9d3f980d961287f60 2026-03-08
FileHash-SHA256 2e7a6d2383339e917b40d32cfad70fe020dcaa93c14df334bd829836074e90c4 2026-03-08
FileHash-SHA256 4e14320102eb7951fad6b6bad5252aeffd74c2a9849ced1f9749c1f13de6251c 2026-03-08
FileHash-SHA256 6fa02b8693ef9169a3055fbed9904800485500cedbe10b460e5ff1ee1b2e7301 2026-03-08
FileHash-SHA256 8b2f8f5ec21f82d5925f77734a6ef8b48156a729ff55e1deb49277985610d34c 2026-03-08
FileHash-SHA256 b37b013ac20a63feee49028f1b336e3160558d1ec6c602ba4444ba0bdd8488cd 2026-03-08
FileHash-SHA256 b8e617bd9d6558cf10dc34f7b6bbe3e1b3a792ee1f2658722d6842704d9f8c51 2026-03-08
FileHash-SHA256 f30d5a5aa1f21d04f51d1d125cdfe08f6d8c288479de1fd2dc78e66694b87ad2 2026-03-08
URL http://176.65.132.10:7000 2026-03-08
URL https://seq-caught-publicity-big.trycloudflare.com 2026-03-08
hostname seq-caught-publicity-big.trycloudflare.com 2026-03-08
URL http://85.11.167.119:7000 2026-03-08