Avvo - Rate your Lawyer. Get Free Legal Advice.
top of page

Sc25667-impv10403.rar -

Scans for domain names, computer names, and local accounts.

The file is a malicious archive used in TrueBot (also known as Silence.Downloader) malware campaigns , typically attributed to the threat group Silence or linked to Clop ransomware operations. 🛡️ Threat Overview Malware Family: TrueBot (Silence.Downloader). sc25667-IMPv10403.rar

Uses "junk code" and obfuscation to bypass signature-based antivirus. Scans for domain names, computer names, and local accounts

Creates a Windows Scheduled Task or registry run key to ensure it survives a reboot. 3. Execution Flow Scans for domain names

Sends a POST request to a hardcoded C2 URL containing an encoded string of the victim's system data.

New entries in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run . ✅ Recommended Actions

Blacklist the specific file hash and any associated C2 IPs at your firewall.

© 2026 Vast Prism.Proudly created with Wix.com

FOLLOW US:

  • w-facebook
  • Twitter Clean
bottom of page