MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e595ec10457cdf21163ff26541ba26fecc8988321c747b02c42b58cdc3f6b556. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 10


Intelligence 10 IOCs YARA 22 File information Comments

SHA256 hash: e595ec10457cdf21163ff26541ba26fecc8988321c747b02c42b58cdc3f6b556
SHA3-384 hash: 4e60f9f171dc945032f7c07a7de0af0394a2194a98db12276e49a652335b5418b60facc7114a5d8d0243d240b587c348
SHA1 hash: d1021c9319576455657a8c5cb5d4b316f8f73768
MD5 hash: 6c5941e95e3aad06ad968853b343c5a2
humanhash: football-nitrogen-video-paris
File name:startuppaaaa.js
Download: download sample
Signature AsyncRAT
File size:1'115'363 bytes
First seen:2026-08-07 10:17:32 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 12288:3k2xZET//THHk7mzrlnjaPE67EYsw+eLOBIwj:3mLkIrlj+X7uj
TLSH T10435E7E1778E64891A053B26E40E59568F29C4210743BD9578EF1EC84B2F89FE9C1CBF
Magika javascript
Reporter abuse_ch
Tags:AsyncRAT js RAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
150
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
agenttesla obfuscated repaired
Verdict:
Malicious
File Type:
text
First seen:
2026-08-07T00:33:00Z UTC
Last seen:
2026-08-07T09:40:00Z UTC
Hits:
~100
Result
Threat name:
AsyncRAT
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Creates autostart registry keys with suspicious values (likely registry only malware)
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
JavaScript file contains suspicious strings
JavaScript source code contains functionality to generate code involving a shell, file or stream
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses dynamic DNS services
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected AsyncRAT
Yara detected Generic Downloader
Yara detected MSILLoadEncryptedAssembly
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1953921 Sample: startuppaaaa.js Startdate: 07/08/2026 Architecture: WINDOWS Score: 100 36 office0011.duckdns.org 2->36 48 Found malware configuration 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 Multi AV Scanner detection for submitted file 2->52 56 14 other signatures 2->56 8 wscript.exe 2 4 2->8         started        11 powershell.exe 19 2->11         started        13 powershell.exe 17 2->13         started        15 powershell.exe 2->15         started        signatures3 54 Uses dynamic DNS services 36->54 process4 signatures5 58 JScript performs obfuscated calls to suspicious functions 8->58 60 Suspicious powershell command line found 8->60 62 Wscript starts Powershell (via cmd or directly) 8->62 64 4 other signatures 8->64 17 powershell.exe 16 8->17         started        20 conhost.exe 11->20         started        22 conhost.exe 1 13->22         started        24 conhost.exe 15->24         started        process6 signatures7 42 Writes to foreign memory regions 17->42 44 Found suspicious powershell code related to unpacking or dynamic code loading 17->44 46 Injects a PE file into a foreign processes 17->46 26 aspnet_compiler.exe 2 17->26         started        30 conhost.exe 17->30         started        32 aspnet_compiler.exe 17->32         started        34 4 other processes 17->34 process8 dnsIp9 38 office0011.duckdns.org 192.169.69.25, 49718, 49721, 49727 SERVERSTADIUM-WowrackcomUS Canada 26->38 40 192.168.2.8, 138, 443, 49710 unknown unknown 26->40 66 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 26->66 signatures10
Gathering data
Threat name:
Script-JS.Trojan.AgentTesla
Status:
Malicious
First seen:
2026-08-07 10:22:39 UTC
File Type:
Text (JavaScript)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
ConfuserEx .NET packer
Suspicious use of SetThreadContext
Adds Run key to start application
Creates a file in the Startup directory
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla
Author:Harish Kumar P
Description:Yara Rule to Detect AgentTesla
Rule name:AsyncRat
Author:kevoreilly, JPCERT/CC Incident Response Group
Description:AsyncRat Payload
Rule name:BAZT_B5_NOCEXInvalidStream
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DotNet_Reactor
Author:@bartblaze
Description:Identifies .NET Reactor, which offers .NET code protection such as obfuscation, encryption and so on.
Rule name:malware_asyncrat
Author:JPCERT/CC Incident Response Group
Description:detect AsyncRat in memory
Reference:internal research
Rule name:MAL_AsnycRAT
Author:SECUINFRA Falcon Team
Description:Detects AsnycRAT based on it's config decryption routine
Rule name:MAL_AsyncRAT_Config_Decryption
Author:SECUINFRA Falcon Team
Description:Detects AsnycRAT based on it's config decryption routine
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:msil_suspicious_use_of_strreverse
Author:dr4k0nia
Description:Detects mixed use of Microsoft.CSharp and VisualBasic to use StrReverse
Rule name:NET
Author:malware-lu
Rule name:Njrat
Author:botherder https://github.com/botherder
Description:Njrat
Rule name:pe_imphash
Rule name:PureCrypter
Author:@bartblaze
Description:Identifies PureCrypter, .NET loader and obfuscator.
Reference:https://malpedia.caad.fkie.fraunhofer.de/details/win.purecrypter
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:SUSP_NET_Msil_Suspicious_Use_StrReverse
Author:dr4k0nia, modified by Florian Roth
Description:Detects mixed use of Microsoft.CSharp and VisualBasic to use StrReverse
Reference:https://github.com/dr4k0nia/yara-rules
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Generic_Threat_ce98c4bc
Author:Elastic Security
Rule name:win_asyncrat_unobfuscated
Author:Matthew @ Embee_Research
Description:Detects strings present in unobfuscated AsyncRat Samples. Rule may also pick up on other Asyncrat-derived malware (Dcrat/venom etc)
Rule name:win_asyncrat_w0
Author:JPCERT/CC Incident Response Group
Description:detect AsyncRat in memory
Reference:internal research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments