General

  • Target

    94c9d9b131a09d2da14127370bc041f46464754f907d38467c5c48ad20624add.exe

  • Size

    3.1MB

  • Sample

    240704-b7twmazcre

  • MD5

    e939fb9abcac14771583ac57e05d9b90

  • SHA1

    b09d0bc30a3d3cffb3583f796c4f363e635ed90a

  • SHA256

    94c9d9b131a09d2da14127370bc041f46464754f907d38467c5c48ad20624add

  • SHA512

    347134900144999b008e9650057144457b82d260569ab9276482d4be814c6efe542adf5fc276d5d344b0561118cc9a5ab61a718b5a972b29784b467edc7fd767

  • SSDEEP

    12288:a7hTrBnuvYkNa2VNYKbpeFy1eLq/FQW8uok7GCoShNZ5LG:a3UYkswNYgpwee+/F78u5yCoS9k

Score
10/10

Malware Config

Extracted

Family

asyncrat

Version

0.5.8

Botnet

Default

C2

betterdays4me.duckdns.org:6606

betterdays4me.duckdns.org:7707

betterdays4me.duckdns.org:8808

Mutex

fULNLY9PC39i

Attributes
  • delay

    3

  • install

    false

  • install_folder

    %AppData%

aes.plain

Targets

    • Target

      94c9d9b131a09d2da14127370bc041f46464754f907d38467c5c48ad20624add.exe

    • Size

      3.1MB

    • MD5

      e939fb9abcac14771583ac57e05d9b90

    • SHA1

      b09d0bc30a3d3cffb3583f796c4f363e635ed90a

    • SHA256

      94c9d9b131a09d2da14127370bc041f46464754f907d38467c5c48ad20624add

    • SHA512

      347134900144999b008e9650057144457b82d260569ab9276482d4be814c6efe542adf5fc276d5d344b0561118cc9a5ab61a718b5a972b29784b467edc7fd767

    • SSDEEP

      12288:a7hTrBnuvYkNa2VNYKbpeFy1eLq/FQW8uok7GCoShNZ5LG:a3UYkswNYgpwee+/F78u5yCoS9k

    Score
    10/10
    • AsyncRat

      AsyncRAT is designed to remotely monitor and control other computers written in C#.

    • Suspicious use of SetThreadContext

MITRE ATT&CK Matrix

Tasks