🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54193af95cf82cdbcc2b331bfd7112915a54bfd872b4fce2e148777fff41a995. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



DCRat


Vendor detections: 16


Intelligence 16 IOCs 1 YARA 10 File information Comments

SHA256 hash: 54193af95cf82cdbcc2b331bfd7112915a54bfd872b4fce2e148777fff41a995
SHA3-384 hash: f577b1198790e51d836c402d268c7bc5ff34ec9423497e9bafcfe80711b5d52166d092cdb1aa78ae763d411b92fc14c2
SHA1 hash: af221e6609bb544787a5baca96f1a7faa620ef5e
MD5 hash: 9d18ee23e1c0f2575d1638502d753aec
humanhash: texas-saturn-pluto-cat
File name:nyashka.exe
Download: download sample
Signature DCRat
File size:850'432 bytes
First seen:2026-01-31 21:55:08 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'500 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 12288:Flz1dGWP2h6tKAAhiIniuwKI5wzuuGhP/Sknk7HtDHEre/OfGVapM61+:FlFvtzAhiI619qN4rpM61+
Threatray 234 similar samples on MalwareBazaar
TLSH T15D05D72429EB003AF177EFB459D1399E96AEF6F3B7079E8E305042C64712780DD9163A
TrID 66.5% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.5% (.EXE) Win64 Executable (generic) (10522/11/4)
5.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.5% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.0% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
Reporter abuse_ch
Tags:DCRat exe RAT


Avatar
abuse_ch
DCRat C2:
http://212.67.17.63/Javascriptapiwindowsgeneratorwptemp.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://212.67.17.63/Javascriptapiwindowsgeneratorwptemp.php https://threatfox.abuse.ch/ioc/1739434/

Intelligence


File Origin
# of uploads :
1
# of downloads :
206
Origin country :
NL NL
Vendor Threat Intelligence
Malware configuration found for:
DarkCrystal
Details
DarkCrystal
a version, a mutex, c2 urls, and extracted plugins
Malware family:
n/a
ID:
1
File name:
nyashka.exe
Verdict:
Malicious activity
Analysis date:
2026-01-31 19:50:19 UTC
Tags:
auto-sch

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
97.4%
Tags:
autorun shell micro sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 cmd dcrat fingerprint lolbin obfuscated reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-01-31T16:55:00Z UTC
Last seen:
2026-01-31T20:48:00Z UTC
Hits:
~10
Detections:
Backdoor.Agent.HTTP.C&C Trojan.Win32.Agent.sb HEUR:Trojan-PSW.MSIL.Coins.gen HEUR:Trojan.Win32.Generic Backdoor.MSIL.DCRat.sb
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
Adds a directory exclusion to Windows Defender
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
Creates processes via WMI
Drops executable to a common third party application directory
Drops executables to the windows directory (C:\Windows) and starts them
Drops PE files with benign system names
Found malware configuration
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: System File Execution Location Anomaly
Sigma detected: Windows Binaries Write Suspicious Extensions
Suricata IDS alerts for network traffic
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Yara detected DCRat
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1861036 Sample: nyashka.exe Startdate: 31/01/2026 Architecture: WINDOWS Score: 100 110 Suricata IDS alerts for network traffic 2->110 112 Found malware configuration 2->112 114 Antivirus detection for URL or domain 2->114 116 16 other signatures 2->116 9 nyashka.exe 4 27 2->9         started        13 lsass.exe 2->13         started        15 RuntimeBroker.exe 2->15         started        17 6 other processes 2->17 process3 file4 92 C:\Windows\...\RuntimeBroker.exe, PE32 9->92 dropped 94 C:\Users\user\Desktop\yYfkdtSf.log, PE32 9->94 dropped 96 C:\Users\user\Desktop\iESNuTjO.log, PE32 9->96 dropped 104 12 other malicious files 9->104 dropped 128 Adds a directory exclusion to Windows Defender 9->128 130 Creates processes via WMI 9->130 132 Drops PE files with benign system names 9->132 134 Drops executable to a common third party application directory 9->134 19 cmd.exe 9->19         started        22 powershell.exe 23 9->22         started        24 powershell.exe 24 9->24         started        32 10 other processes 9->32 98 C:\Users\user\Desktop\uzAUWdRx.log, PE32 13->98 dropped 100 C:\Users\user\Desktop\tjeMgEQI.log, PE32 13->100 dropped 102 C:\Users\user\Desktop\fffNrnIi.log, PE32 13->102 dropped 106 4 other malicious files 13->106 dropped 26 cmd.exe 13->26         started        28 powershell.exe 13->28         started        30 powershell.exe 13->30         started        34 11 other processes 13->34 136 Multi AV Scanner detection for dropped file 15->136 signatures5 process6 signatures7 118 Uses ping.exe to sleep 19->118 120 Uses ping.exe to check the status of other devices and networks 19->120 36 fontdrvhost.exe 19->36         started        49 3 other processes 19->49 122 Loading BitLocker PowerShell Module 22->122 41 conhost.exe 22->41         started        43 conhost.exe 24->43         started        51 2 other processes 26->51 45 conhost.exe 28->45         started        47 conhost.exe 30->47         started        53 10 other processes 32->53 55 10 other processes 34->55 process8 dnsIp9 108 212.67.17.63, 49724, 49728, 49729 MEGAMAX-ASNizhnyNovgorodRU Russian Federation 36->108 84 C:\Users\user\Desktop\ukadnBcp.log, PE32 36->84 dropped 86 C:\Users\user\Desktop\rddURjiu.log, PE32 36->86 dropped 88 C:\Users\user\Desktop\qgCMwjTz.log, PE32 36->88 dropped 90 4 other malicious files 36->90 dropped 124 Adds a directory exclusion to Windows Defender 36->124 57 cmd.exe 36->57         started        60 powershell.exe 36->60         started        62 powershell.exe 36->62         started        64 10 other processes 36->64 file10 signatures11 process12 signatures13 126 Uses ping.exe to sleep 57->126 66 conhost.exe 57->66         started        68 chcp.com 57->68         started        80 2 other processes 57->80 70 conhost.exe 60->70         started        72 conhost.exe 62->72         started        74 conhost.exe 64->74         started        76 conhost.exe 64->76         started        78 conhost.exe 64->78         started        82 7 other processes 64->82 process14
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.DCRat
Status:
Malicious
First seen:
2026-01-31 19:50:22 UTC
File Type:
PE (.Net Exe)
AV detection:
22 of 36 (61.11%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:dcrat discovery execution infostealer persistence rat
Behaviour
Modifies registry class
Runs ping.exe
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
System Network Configuration Discovery: Internet Connection Discovery
Drops file in Program Files directory
Drops file in Windows directory
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
DCRat payload
DcRat
Dcrat family
Process spawned unexpected child process
Unpacked files
SH256 hash:
cccd73fd69a9ac8c81ed8fe0861487908f34d6332e8934e8474afb4f98c7eaba
MD5 hash:
36aa31a229707d08b2d9b44310ed7837
SHA1 hash:
01abe408a0feac1c554c9b20bc3677aa248147ba
SH256 hash:
2b93377ea087225820a9f8e4f331005a0c600d557242366f06e0c1eae003d669
MD5 hash:
d8bf2a0481c0a17a634d066a711c12e9
SHA1 hash:
7cc01a58831ed109f85b64fe4920278cedf3e38d
SH256 hash:
54193af95cf82cdbcc2b331bfd7112915a54bfd872b4fce2e148777fff41a995
MD5 hash:
9d18ee23e1c0f2575d1638502d753aec
SHA1 hash:
af221e6609bb544787a5baca96f1a7faa620ef5e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DCRat
Author:Nikolaos 'n0t' Totosis
Description:DCRat Payload
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:INDICATOR_SUSPICIOUS_EXE_Embedded_Gzip_B64Encoded_File
Author:ditekSHen
Description:Detects executables containing bas64 encoded gzip files
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:RSharedStrings
Author:Katie Kleemola
Description:identifiers for remote and gmremote
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments