MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ddda81a419fc2faa8c4e2eaca8dd1b65fb53196eb475b5bfd218ff9b84888ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 10


Intelligence 10 IOCs YARA 22 File information Comments

SHA256 hash: 4ddda81a419fc2faa8c4e2eaca8dd1b65fb53196eb475b5bfd218ff9b84888ad
SHA3-384 hash: d060c388bf1085f550b15dfd9bb01a5dc39c64753a1c6d2ef9ceec240f2101f5c7608eaf3abc9ed33c105b459bf59f69
SHA1 hash: f26606a9b9c7da830323874f0b3c888244d9b633
MD5 hash: 6113cd8fa388d849218800b12d35b7d6
humanhash: shade-fillet-triple-magazine
File name:startupPPAB.js
Download: download sample
Signature AsyncRAT
File size:998'517 bytes
First seen:2026-08-26 07:50:39 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:+4xdr6R53meNigen3L2HZ8WI74oB7Qpc9O5C0gfX1HWxQdN9MZCY+o/KaAAZcvS7:+kmR52eNUnbUGXnMZCY+e1AYQo9
TLSH T1CB252BD312FD36444551FA45A50F7A28C72ED2354DC3A5C4B0DE1FC0DB0B49BAAE8AAE
Magika javascript
Reporter abuse_ch
Tags:AsyncRAT js RAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-25T22:29:00Z UTC
Last seen:
2026-08-26T00:25:00Z UTC
Hits:
~10
Result
Threat name:
AsyncRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Bypasses PowerShell execution policy
Creates autostart registry keys with suspicious values (likely registry only malware)
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
JavaScript file contains suspicious strings
JavaScript source code contains functionality to generate code involving a shell, file or stream
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses dynamic DNS services
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected AsyncRAT
Yara detected Generic Downloader
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1963913 Sample: startupPPAB.js Startdate: 26/08/2026 Architecture: WINDOWS Score: 100 36 office0011.duckdns.org 2->36 48 Malicious sample detected (through community Yara rule) 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Yara detected Powershell decode and execute 2->52 56 10 other signatures 2->56 8 wscript.exe 2 4 2->8         started        11 powershell.exe 19 2->11         started        13 powershell.exe 17 2->13         started        15 powershell.exe 2->15         started        signatures3 54 Uses dynamic DNS services 36->54 process4 signatures5 58 JScript performs obfuscated calls to suspicious functions 8->58 60 Suspicious powershell command line found 8->60 62 Wscript starts Powershell (via cmd or directly) 8->62 64 4 other signatures 8->64 17 powershell.exe 16 8->17         started        20 conhost.exe 11->20         started        22 conhost.exe 1 13->22         started        24 conhost.exe 15->24         started        process6 signatures7 42 Writes to foreign memory regions 17->42 44 Found suspicious powershell code related to unpacking or dynamic code loading 17->44 46 Injects a PE file into a foreign processes 17->46 26 aspnet_compiler.exe 2 17->26         started        30 conhost.exe 17->30         started        32 aspnet_compiler.exe 17->32         started        34 4 other processes 17->34 process8 dnsIp9 38 office0011.duckdns.org 192.169.69.25, 49716, 49717, 49718 SERVERSTADIUM-WowrackcomUS Canada 26->38 40 192.168.2.4, 138, 443, 49698 unknown unknown 26->40 66 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 26->66 signatures10
Gathering data
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Creates a file in the Startup directory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla
Author:Harish Kumar P
Description:Yara Rule to Detect AgentTesla
Rule name:AsyncRat
Author:kevoreilly, JPCERT/CC Incident Response Group
Description:AsyncRat Payload
Rule name:Base64_Encoded_Powershell_Directives
Rule name:BAZT_B5_NOCEXInvalidStream
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DotNet_Reactor
Author:@bartblaze
Description:Identifies .NET Reactor, which offers .NET code protection such as obfuscation, encryption and so on.
Rule name:malware_asyncrat
Author:JPCERT/CC Incident Response Group
Description:detect AsyncRat in memory
Reference:internal research
Rule name:MAL_AsnycRAT
Author:SECUINFRA Falcon Team
Description:Detects AsnycRAT based on it's config decryption routine
Rule name:MAL_AsyncRAT_Config_Decryption
Author:SECUINFRA Falcon Team
Description:Detects AsnycRAT based on it's config decryption routine
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:msil_suspicious_use_of_strreverse
Author:dr4k0nia
Description:Detects mixed use of Microsoft.CSharp and VisualBasic to use StrReverse
Rule name:NET
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:pe_imphash
Rule name:PureCrypter
Author:@bartblaze
Description:Identifies PureCrypter, .NET loader and obfuscator.
Reference:https://malpedia.caad.fkie.fraunhofer.de/details/win.purecrypter
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:SUSP_NET_Msil_Suspicious_Use_StrReverse
Author:dr4k0nia, modified by Florian Roth
Description:Detects mixed use of Microsoft.CSharp and VisualBasic to use StrReverse
Reference:https://github.com/dr4k0nia/yara-rules
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Generic_Threat_ce98c4bc
Author:Elastic Security
Rule name:win_asyncrat_unobfuscated
Author:Matthew @ Embee_Research
Description:Detects strings present in unobfuscated AsyncRat Samples. Rule may also pick up on other Asyncrat-derived malware (Dcrat/venom etc)
Rule name:win_asyncrat_w0
Author:JPCERT/CC Incident Response Group
Description:detect AsyncRat in memory
Reference:internal research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments