Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
84
Global rank
69 infographic chevron month
Month rank
115 infographic chevron week
Week rank

WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.

RAT
Type
likely Algerian
Origin
24 September, 2013
First seen
4 October, 2026
Last seen
Also known as
Dunihi
Houdini
H-worm
Jenxcus
Kognito

How to analyze Wshrat with ANY.RUN

RAT
Type
likely Algerian
Origin
24 September, 2013
First seen
4 October, 2026
Last seen

IOCs

IP addresses
154.91.34.165
2.23.246.101
107.174.192.179
2.23.245.19
118.194.235.187
23.72.36.154
8.8.8.8
142.251.14.94
147.185.221.20
192.169.69.25
139.99.85.213
57.153.246.3
45.141.233.69
158.101.44.242
149.154.167.99
82.29.67.160
208.95.112.1
185.111.111.155
150.171.27.11
98.177.107.142
Hashes
df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
67401342192babc27e62d4c1e0940409cc3f2bd28f77399e71d245eae8d3f63c
704d28223a4320a853df4a19d48c7015cf79d56a5317cc3475b6305fa43dcc05
8f05bafd61f29998ca102b333f853628502d4e45d53cff41148d6dd15f011792
81970dbe581373d14fbd451ac4b3f96e5f69b79645f1ee1ca715cff3af0bf20d
d7446e2f307027c9bda2a92d1df1c13c376581372f6ae8708f4d5baccb2e6813
cd2c00ce027687ce4a8bdc967f26a8ab82f651c9becd703658ba282ec49702bd
9efa735bbf7b61c3f94281e925ee48ce4cc659d267c0255d54e4700f4404eec0
73526ddb1d23d595680badd6bd87f5dd82869606a7cf7e8707758d48d848257e
c5011367a4453096122fe72bb89f2940293cb61e973522ff140cdfe05227b1f3
f3a7e5e59e883a3ef6c99967766a546d55dd7a767fadb9f4d433cedf0555e992
11acf49eb9f3cb68fa7a3bb8568cef2eb0f125700c8edcbcd108b5810761770f
2487221a75a52b4f8aa6d2e62f1c0a55a5cd5240b1cb7aafa66fbb2042590b06
057784451e3442f381f6a8af931a7050f88d19bda6bc939d37607532a353da1c
e7f8eae310e8ace3b3b0be3bb145ec8c2bbcaa66c9337218dc4cbef633374f95
c13743567fcfc4fa77b66e79447edab2d1ecc97d4da32b655d92ae90968f2b0b
9d6ee11f048b734a4edf01acda39d1390b0e1e88756919991c242073723b9c21
5ac3e308c8bef5ed42463929a1be5f519f56a0785fd8c2aed6f85073cc5f98fc
917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2
17e098ffaf49f4eb7c98a94af360ed443bfe3bce0335b09e13778221919a007f
Domains
www.bing.com
bucket-cf-weur-a.uploadnow.io
gcc-prtnrs.top
fonts.gstatic.com
5kidontknowit.com
cloud-api.yandex.net
s3.timeweb.cloud
edge.microsoft.com
config.edge.skype.com
reallyfreegeoip.org
watson.events.data.microsoft.com
laminaflbx.shop
pagead2.googlesyndication.com
github.com
17.aa.4t.com
t.me
fundingchoicesmessages.google.com
api.edgeoffer.microsoft.com
ip-api.com
officeclient.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:cangek-cgm1fu_myvvzdlwf_djwsbxwwrevutyxtsmk&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://uploadnow.io/f/0bcds7g
https://copilot.microsoft.com/c/api/user/eligibility
https://uploadnow.io/en/share?utm_source=0bcds7g
https://cdn.uploadnow.io/_next/static/css/ae110469aab9e883.css
https://cdn.uploadnow.io/_next/static/css/cda03e3a1ab65c17.css
https://cdn.uploadnow.io/_next/static/css/df97d9751ec3abda.css
https://cdn.uploadnow.io/_next/static/css/5ded0d5ca9ecc5c1.css
https://cdn.uploadnow.io/_next/static/chunks/webpack-541c27ed8494cc3b.js
https://cdn.uploadnow.io/_next/static/chunks/framework-b6335179e7eea00c.js
https://cdn.uploadnow.io/_next/static/chunks/main-86f0684c1b20f38d.js
https://cdn.uploadnow.io/_next/static/chunks/pages/_app-a7a0c0b843b84887.js
https://cdn.uploadnow.io/_next/static/chunks/62867-950590631f5ceb03.js
https://cdn.uploadnow.io/_next/static/chunks/38993-a4121c3c0d1b9d33.js
Last Seen at
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 2351
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 4687
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 7155
comments 0

What is WSHRAT malware?

WSHRAT is a Remote Access Trojan — a type of malware that attackers use to gain remote control of machines and steal information. This particular RAT has seen several revisions, and depending on the version it’s also known as Dunihi, Houdini, H-worm, Jenxcus, and Kognito.

This RAT was first used in attacks against energy sector companies all around the world. With time, the malware became widely available and attackers used it in less coordinated attacks. The most recent version of WSHRAT changed target victims and now focuses on the banking sector.

The functionality of this RAT can vary by version, but they commonly include:

  • The ability to take screenshots.
  • The ability to modify files.
  • The ability to access email and web browser credentials.
  • The ability to manipulate and kill running system processes.

General description of WSHRAT malware

The malware surfaced for the first time in 2013 when it was known under the name H-worm. At the time, it was a RAT written in VBS (Visual Basic Script) programming language. Already, some samples featured code obfuscation and the malware packed with some advanced info-stealing functions.

The malware was developed by a user known in the underground community as Houdini. Houdini used to host a website, where people could learn about the capabilities of the RAT from an explanation video. Analysis of the content allowed researchers to conclude with a high degree of certainty, that Houdini is likely to be Algerian. This is mainly based on his fluent knowledge of French and Arabic languages.

It should be noted while analyzing the first samples of WSHRAT, researchers found out that it has similarities in command and control infrastructure with NjW0rm, njRat/LV, XtremeRAT, and PoisonIvy. These are all RATs operated by the njq8 cybergang. It is likely, that Houdini is collaborating with the gang, or he could even be a part of the njq8 syndicate.

The malware became relatively popular and VBS versions circulated in the wild for a while. In 2015, the author came out with an announcement of his plans to rewrite the malware in the Delphi programming language.

However, another version that researchers started investigating in 2016 still used VBS. This time, the RAT came in SFX files and exhibited new behavior. For example, it would launch a YouTube or open a browser URL as a decoy to hide its execution and infection happening in the background. Among others, the 2016 version of WSHRAT can be distinguished by its use of mixed binary and ASCII protocols over TCP.

The newest version of WSHRAT has popped up in 2019. This iteration of the malware targets the commercial banking sector. The RAT was completely rewritten in JavaScript from the original code of Visual basic. However, most aspects of the updated version remained identical to the older iterations. For example, it uses the same URL structure for C2 servers and exhibits similar behavior patterns.

This version is available to purchase for 50 USD and it is heavily marketed on the underground forums. In particular, the marketing campaign highlights such features of the RAT like WinXP-Win10 compatibility and a large number of information stealing and remote control functions.

Malware analysis of WSHRAT

The ANY.RUN malware hunting service provides a video, where researchers can see the execution process of WSHRAT or other RATs like njRAT or NanoCore.

Wshrat process graph

Figure 1: Shows the Wshrat graph of processes created by the ANY.RUN interactive malware analysis service.

WSHRAT execution process

Execution process of WSHRAT is straightforward — after the trojan makes its way into the system as a script file it either runs directly by wscript process or uses system processes such as powershell and regasm for persistence and defense evasion. After it gains persistence in the system, WSHRAT starts sending requests to the C2 server for further commands and fetches additional payloads such as its modules with different functionality.

Distribution of WSHRAT

Criminals commonly distribute WSHRAT with emails that contain infected attachments. There is evidence to believe that this RAT is used both in highly targeted attacks as well as in more broadly distributed email spam campaigns. Phishing is used to trick victims into installing the malware.

How to detect WSHRAT?

Sometimes valuable information about the malware family can be found in the network activity. Wshrat is not an exception. This malware sends HTTP requests to the Command & Control server using POST method and it names itself as a User-Agent. You can find details at "HTTP Requests" tab by clicking at "POST" method icon. In an opened window, take a look at the User-Agent and if it says WSHRAT, you know which malware family you are dealing with.

Wshrat request details

Conclusion

The danger of malware like WSH RAT lies not only in its robust feature set as a RAT but also in its morphing capability. Writing in VBS helped the attackers to push out an incredible number of versions. While security researchers were busy analyzing one sample, a new iteration could be released into the wild.

In cases like this, the ability to perform research fast is of crucial importance. This is especially true if we consider that certain samples of WSHRAT use code obfuscation and encryption that render static analysis ineffective. This means that a more complicated and time-consuming dynamic analysis is a must.

Thankfully, interactive analysis services like ANY.RUN help solve this problem. ANY.RUN allows launching samples in a secure, interactive online environment, where researchers can choose a variety of system parameters that influence the flow of execution. This vastly accelerates the research process and the results are presented in real-time.

HAVE A LOOK AT

Phobos screenshot
Phobos
phobos ransomware
Phobos is a ransomware that locks or encrypts files to demand a ransom. It uses AES encryption with different extensions, which leaves no chance to recover the infected files.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
JOMANGY screenshot
JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
TrustConnect screenshot
TrustConnect
trustconnect
TrustConnect is a MaaS platform that disguises a Remote Access Trojan (RAT) as a legitimate Remote Monitoring and Management (RMM) tool. The operators built an AI-generated business website, obtained a fraudulently acquired Extended Validation (EV) code-signing certificate, and created fake customer statistics and documentation to make TrustConnect appear to the world — and to security tools — as a legitimate software company.
Read More
DarkGate screenshot
DarkGate
darkgate
DarkGate is a loader, which possesses extensive functionality, ranging from keylogging to crypto mining. Written in Delphi, this malware is known for the use of AutoIT scripts in its infection process. Thanks to this malicious software’s versatile architecture, it is widely used by established threat actors.
Read More