🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1abfe186555b7b0b6dec754412e73f29f2dfae9042e7966b505a9ae10e0d099. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WSHRAT


Vendor detections: 6


Intelligence 6 IOCs 2 YARA File information Comments

SHA256 hash: d1abfe186555b7b0b6dec754412e73f29f2dfae9042e7966b505a9ae10e0d099
SHA3-384 hash: 27ce9e1ca08d74a3af4ef8a8b64778df067a2cdf7d55fe14aef77cdced6ab95239d5cf1ca4fbf9cdf0f1fdee58cd181f
SHA1 hash: 4015d8d6c804b252b3f4b8046c9cadca68e8da87
MD5 hash: d928ee9998f8bf95eee928b64b1cc88a
humanhash: papa-beryllium-mountain-autumn
File name:statement.hta
Download: download sample
Signature WSHRAT
File size:17'921 bytes
First seen:2022-07-27 09:16:09 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 96:J36yE628jnfC7+5xlgkEDJv4YVOrkDJv4/+8eAMr6vj/fYY/DWhmhH5SJCCCg/DI:0y48u7KlEuIV2cCWrw40O95IjF6k
TLSH T15D820604572972E132735D8824995192281F3EAACDF09BDA3AC19BF6EC334DE6C57B70
Reporter JAMESWT_WT
Tags:hta ngrok wshrat

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://1.tcp.au.ngrok.io:25993/is-ready https://threatfox.abuse.ch/ioc/839799/
3.24.145.55:25993 https://threatfox.abuse.ch/ioc/839800/

Intelligence


File Origin
# of uploads :
1
# of downloads :
209
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
May check the online IP address of the machine
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Execute DLL with spoofed extension
Snort IDS alert for network traffic
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Uses known network protocols on non-standard ports
Very long command line found
Yara detected WSHRAT
Behaviour
Behavior Graph:
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2022-07-27 04:35:55 UTC
File Type:
Text (VBS)
AV detection:
11 of 26 (42.31%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:wshrat trojan
Behaviour
Modifies Internet Explorer settings
Modifies registry class
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Looks up external IP address via web service
Checks computer location settings
Blocklisted process makes network request
WSHRAT
Malware Config
C2 Extraction:
http://1.tcp.au.ngrok.io:25993
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments