General

  • Target

    Client.bat

  • Size

    88KB

  • Sample

    240630-zm8faavfkh

  • MD5

    a926f9d53905b37d2302f26c0b7b8513

  • SHA1

    c2ac13e22da81f41c8afa10caa97587c9b0c7955

  • SHA256

    54827271adc73e03abc8a39360562129bf55d8ad54c8cbd529457f2a1846fbd7

  • SHA512

    2914b2b06eaed7a2731b6582cab7b07b2fd885c325b7d8f2a1e286eaa9a495ff169ee17868814ba673f204cfb0e636f550b02f0ae217ac3080abdfcecf007898

  • SSDEEP

    1536:c4V/BQ3BS857j2ZBDyXNDCnxQ7W/ZMlFogoetTDwq7leA91Z2jpPkuxmNMpePN3w:xBQ4WpCnTZObPDwqFde3JWNA

Malware Config

Extracted

Family

asyncrat

Version

5.0.5

Botnet

Venom Clients

C2

94.156.79.107:4443

Mutex

Venom_RAT_HVNC_Mutex_Venom RAT_HVNC

Attributes
  • delay

    1

  • install

    false

  • install_folder

    %AppData%

aes.plain

Targets

    • Target

      Client.bat

    • Size

      88KB

    • MD5

      a926f9d53905b37d2302f26c0b7b8513

    • SHA1

      c2ac13e22da81f41c8afa10caa97587c9b0c7955

    • SHA256

      54827271adc73e03abc8a39360562129bf55d8ad54c8cbd529457f2a1846fbd7

    • SHA512

      2914b2b06eaed7a2731b6582cab7b07b2fd885c325b7d8f2a1e286eaa9a495ff169ee17868814ba673f204cfb0e636f550b02f0ae217ac3080abdfcecf007898

    • SSDEEP

      1536:c4V/BQ3BS857j2ZBDyXNDCnxQ7W/ZMlFogoetTDwq7leA91Z2jpPkuxmNMpePN3w:xBQ4WpCnTZObPDwqFde3JWNA

    • AsyncRat

      AsyncRAT is designed to remotely monitor and control other computers written in C#.

    • Async RAT payload

    • Command and Scripting Interpreter: PowerShell

      Run Powershell and hide display window.

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Tasks