Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DBatLoader

102
Global rank
86 infographic chevron month
Month rank
82 infographic chevron week
Week rank
0
IOCs

DBatLoader is a loader malware used for distributing payloads of different types, including WarzoneRAT and Formbook. It is employed in multi-stage attacks that usually start with a phishing email carrying a malicious attachment.

Loader
Type
Unknown
Origin
1 June, 2020
First seen
18 August, 2026
Last seen

How to analyze DBatLoader with ANY.RUN

Type
Unknown
Origin
1 June, 2020
First seen
18 August, 2026
Last seen

IOCs

IP addresses
139.99.85.213
107.174.192.179
149.154.167.99
48.192.1.64
135.233.95.144
82.29.67.160
104.85.1.163
154.23.184.57
75.119.193.253
118.194.235.187
217.78.234.145
104.85.0.214
193.122.130.0
149.154.166.110
154.91.34.165
48.209.138.168
96.16.53.165
23.220.113.159
135.234.160.246
2.19.195.64
Hashes
704d28223a4320a853df4a19d48c7015cf79d56a5317cc3475b6305fa43dcc05
8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
81970dbe581373d14fbd451ac4b3f96e5f69b79645f1ee1ca715cff3af0bf20d
d7446e2f307027c9bda2a92d1df1c13c376581372f6ae8708f4d5baccb2e6813
cd2c00ce027687ce4a8bdc967f26a8ab82f651c9becd703658ba282ec49702bd
9efa735bbf7b61c3f94281e925ee48ce4cc659d267c0255d54e4700f4404eec0
73526ddb1d23d595680badd6bd87f5dd82869606a7cf7e8707758d48d848257e
c5011367a4453096122fe72bb89f2940293cb61e973522ff140cdfe05227b1f3
f3a7e5e59e883a3ef6c99967766a546d55dd7a767fadb9f4d433cedf0555e992
11acf49eb9f3cb68fa7a3bb8568cef2eb0f125700c8edcbcd108b5810761770f
2487221a75a52b4f8aa6d2e62f1c0a55a5cd5240b1cb7aafa66fbb2042590b06
057784451e3442f381f6a8af931a7050f88d19bda6bc939d37607532a353da1c
e7f8eae310e8ace3b3b0be3bb145ec8c2bbcaa66c9337218dc4cbef633374f95
c13743567fcfc4fa77b66e79447edab2d1ecc97d4da32b655d92ae90968f2b0b
7c0719b9b312a531cf41cd08affacceef6de084619808238fec0f0247955f26e
bffbebedccb4bfd8e849bb3b577eaf0bc821bd45be29905017e667034e5b25be
9d6ee11f048b734a4edf01acda39d1390b0e1e88756919991c242073723b9c21
5ac3e308c8bef5ed42463929a1be5f519f56a0785fd8c2aed6f85073cc5f98fc
17e098ffaf49f4eb7c98a94af360ed443bfe3bce0335b09e13778221919a007f
b82d5dad784762f378c3aff27426f3e27c1dc987f72640eebf6d4b541761258e
Domains
cloud-api.yandex.net
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
narrathfpt.top
watson.events.data.microsoft.com
c.pki.goog
steamcommunity.com
grabify.link
www.bing.com
slscr.update.microsoft.com
login.live.com
ocsp.digicert.com
crl.microsoft.com
gstatic.com
katt.gdn
api.ipify.org
go.microsoft.com
t.me
checkip.dyndns.org
self.events.data.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://gateway.discord.gg/?v=9&encording=json
https://t.me/m00f3r
http://176.65.144.23/brain/xllll.txt
https://gstatic.com/generate_204
http://154.91.34.165:64951/
https://steamcommunity.com/profiles/76561199851454339
https://api.pcloud.com/listfolder?path=/
http://107.174.192.179/data/003
http://checkip.dyndns.org/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://ip-api.com/line/?fields=hosting
https://t.me/asdawfq
https://api.ipify.org/
http://ip-api.com/json/192.42.116.19
https://grabify.link/zatfqo
https://narrathfpt.top/tekq
http://ip-api.com/json/
http://107.174.192.179/clean
Last Seen at
Last Seen at

Recent blog posts

post image
Hunt Malware & Phishing Threats with ANY....
watchers 907
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 6031
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 12649
comments 0

What is DBatLoader malware?

DBatLoader is a loader written in Delphi that has been in extensive use among attackers since 2020. One of the key features of the malware is its reliance on legitimate cloud-based platforms such as Discord for hosting its payloads. DBatLoader has been involved in numerous campaigns and leveraged to deploy stealers, trojans, and other threats.

In most cases, DBatLoader manages to infect machines via multi-stage attacks. For instance, victims may receive an email attachment in the form of a PDF file. Upon opening the attachment, users may be prompted to click on a seemingly genuine button embedded with a malicious link. Clicking this link will initiate the download of a Windows Cabinet file, which, in turn, will trigger the installation of DBatLoader on the unsuspecting user's computer.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Technical details of the DBatLoader malicious software

DBatLoader’s sole purpose is to distribute other malware on the devices it manages to infect. To do this, the developers behind DBatLoader have equipped their malicious software with several advanced capabilities.

For example, DBatLoader can avoid User Account Control (UAC) to gain elevated privileges. It does this by exploiting the mock folder vulnerability. In Windows, executables launched from certain system directories can auto-elevate. DBatLoader exploits this by creating a mock folder with the same name as a trusted location, such as "C:\Windows\System32 ".

On top of that, DBatLoader copies a legitimate process to this fake folder and then injects it with its malicious DLL that allows the payload downloaded by DBatLoader to execute freely without any security notifications, achieving sustained persistence.

Another common vulnerability abused by DBatLoader in previous attacks was CVE-2018-0798, an exploit targeting Equation Editor in Microsoft Office. The malware has also been observed to utilize steganography.

As mentioned, DBatLoader is usually configured to pull malicious payloads from servers of popular cloud storage services, including Microsoft OneDrive and Google Drive. Some of the notable examples of malware dropped by DBatLoader are Formbook, Warzone, and Remcos.

Execution process of DBatLoader

In order to detect DBatLoader, it is vital to analyze the latest samples of this malware and collect up-to-date information on it. To this end, we can use ANY.RUN, a malware analysis sandbox that lets us quickly analyze any suspicious file or link to spot threats.

Let’s upload a sample of DBatLoader to ANY.RUN and study its behavior.

In this task, DBatLoader was distributed as an executable file with a name mimicking the title of a document, attempting to trick users into opening the file and executing the malicious code. Upon execution, DBatLoader downloads and injects the Formbook malware into the Control and Explorer system processes, enabling its malicious activity.

Analyze malware for free in a fully interactive cloud sandbox – sign up now!

DBatLoader process tree shown in ANY.RUN DBatLoader's process tree demonstrated in ANY.RUN

In addition, this loader can be used in more sophisticated attacks, such as exploiting vulnerabilities to penetrate the system. These can be familiar vulnerabilities like CVE-2017-11882, as well as lesser known ones. On top of that, DBatLoader can also make use of system utilities in its attacks. In this task, a whole arsenal of system utilities is actively used, such as cmd, ping, and xcopy, including for the purpose of lateral movement. Eventually, DBatLoader drops Remcos that instantly begins its operation.

Distribution methods of the DBatLoader malware

Phishing campaigns constitute the most common vector of attack involving DBatLoader. Emails sent by the operators of the malware target different organizations and are masqueraded as genuine messages. In many cases, criminals even use legitimate email addresses they manage to hijack or gain access to.

The subject of such emails concerns different business-related matters, such as payments and other arrangements. For example, attackers may send fake invoices as Microsoft Office or PDF files. These files usually contain a link that, once clicked, can trigger the infection leading to DBatLoader being dropped on the computer and the eventual deployment of the final payload.

Conclusion

DBatLoader remains an active threat commonly used by criminals in their attacks on various types of organizations. To keep your infrastructure safe, it is essential that you have strong security measures in place, especially when it comes to software for detecting and inspecting threats.

Use the ANY.RUN sandbox as a reliable tool for analyzing emails you receive to safely determine if they pose any danger. ANY.RUN’s interactive cloud environment makes it easy to investigate the most advanced phishing campaigns and uncover multi-stage attacks in minutes. The service provides you with convenient text reports containing all the relevant information on the files and links you submit, including fresh IOCs.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
HijackLoader screenshot
HijackLoader
hijackloader
HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
Salvador Stealer screenshot
Salvador Stealer
salvador
Salvador Stealer is a powerful, information-stealing Android malware designed to silently infiltrate systems, extract sensitive data, and exfiltrate it to cybercriminals. Often sold on underground forums, it is part of the growing ecosystem of “stealers-as-a-service” (SaaS) tools that target individuals and organizations alike.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More