🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f41ff860abd5c8d4c742f063542b9014c53a9f926dedb130ce3b74cb2e0ffc21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WSHRAT


Vendor detections: 10


Intelligence 10 IOCs 3 YARA 1 File information Comments

SHA256 hash: f41ff860abd5c8d4c742f063542b9014c53a9f926dedb130ce3b74cb2e0ffc21
SHA3-384 hash: ca08550c29145391183222fc5d6002f20212cd917541677712e85cfc1b496c44ded9199993e5ab8b57ccd3fb7a7aebc9
SHA1 hash: eba3ec7f561eebbb1a9bd893b13b1c231b3b0ed2
MD5 hash: dc05be7b080a333a891ffb32fedd6300
humanhash: bakerloo-victor-whiskey-queen
File name:ORDER-26902-36548.PDF.vbs
Download: download sample
Signature WSHRAT
File size:1'198'531 bytes
First seen:2026-09-02 13:34:00 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 3072:EpyayanbEUWjt0HKHsD5kTUFOQ7pR3J1lggOw:EpyayanbEU5qiaTUbb35X
TLSH T14D455381D8D4453C47743F05D92AEF9AB2F45408F5AB3EADB80524C28BD5AB12D2EC7E
Magika vba
Reporter James_inthe_box
Tags:exe vbs wshrat

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://brain.dynip.se:32722/is-ready https://threatfox.abuse.ch/ioc/1893194/
46.246.6.66:7044 https://threatfox.abuse.ch/ioc/1893195/
46.246.6.66:32722 https://threatfox.abuse.ch/ioc/1893196/

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm cmd evasive explorer fingerprint lolbin masquerade obfuscated obfuscated persistence reconnaissance wscript
Verdict:
Malicious
File Type:
vbs
First seen:
2026-09-02T07:30:00Z UTC
Last seen:
2026-09-02T08:05:00Z UTC
Hits:
~100
Verdict:
Malware
YARA:
1 match(es)
Tags:
AdoDb.stream COM Behavior Trace DeObfuscated Microsoft.xmldom Obfuscated SCRipting.filesystemobject SOS: 0.98 T1027 T1059.005 VBScript WScript.Shell
Threat name:
Script-WScript.Trojan.Heuristic
Status:
Malicious
First seen:
2026-09-02 13:34:05 UTC
File Type:
Text (VBS)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:wshrat execution persistence privilege_escalation trojan
Behaviour
Modifies registry class
Script User-Agent
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a VBScript file via the Windows Script Host.
Adds Run key to start application
Checks computer location settings
Creates a file in the Startup directory
Badlisted process makes network request
Family: WSHRAT
Malware Config
C2 Extraction:
http://jamesmore02.work.gd:7044
http://brain.dynip.se:32722
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments