• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    BabylonRAT XOR-obfuscated capability strings

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•1

    Detects executable files containing XOR-obfuscated strings associated with BabylonRAT capabilities, including browser credential theft, keylogging, HOSTS file manipulation, DDoS, and remote dynamic API resolution. This rule identifies patterns commonly used to evade static analysis.

    YARA

    Tags

    T1056.001 - KeyloggingT1498 - Network Denial of ServiceT1005 - Data from Local SystemTA0009 - CollectionTA0040 - ImpactMalware DetectedWindows

    Found in

    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?