General

  • Target

    AsyncClient.exe

  • Size

    311KB

  • Sample

    240705-ldhxdawbmj

  • MD5

    802daf4207746e9f6e40bf9e37212aef

  • SHA1

    04927f465c343105ede7717bf2510f395db54e3b

  • SHA256

    f18c329c416a1ce16a941a55f77f30a1ec32756dcf6b074b8f70f26a52bd933a

  • SHA512

    54d084867be8f1feadce158af47967644e2b46ab9d25ec9025ad09a7bbc5dfa184d02124fa173f5b238e35017b846985653278f222a79b7897ca758a5fa8d7a6

  • SSDEEP

    6144:+ugHKETEbp7tRV1lZ39dXF0vNrPWqyyo/GwUtm5r0HfrBqIq:+rTUjIpPWJr/GwUtmr0HfrBqIq

Malware Config

Extracted

Family

asyncrat

Version

0.5.8

Botnet

Default

C2

five-sequences.gl.at.ply.gg:47561

Mutex

CRKcdCEX4ddF

Attributes
  • delay

    3

  • install

    true

  • install_file

    Test.exe

  • install_folder

    %AppData%

aes.plain

Targets

    • Target

      AsyncClient.exe

    • Size

      311KB

    • MD5

      802daf4207746e9f6e40bf9e37212aef

    • SHA1

      04927f465c343105ede7717bf2510f395db54e3b

    • SHA256

      f18c329c416a1ce16a941a55f77f30a1ec32756dcf6b074b8f70f26a52bd933a

    • SHA512

      54d084867be8f1feadce158af47967644e2b46ab9d25ec9025ad09a7bbc5dfa184d02124fa173f5b238e35017b846985653278f222a79b7897ca758a5fa8d7a6

    • SSDEEP

      6144:+ugHKETEbp7tRV1lZ39dXF0vNrPWqyyo/GwUtm5r0HfrBqIq:+rTUjIpPWJr/GwUtmr0HfrBqIq

    • AsyncRat

      AsyncRAT is designed to remotely monitor and control other computers written in C#.

    • Modifies visibility of file extensions in Explorer

    • Async RAT payload

    • Executes dropped EXE

MITRE ATT&CK Matrix ATT&CK v13

Execution

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Defense Evasion

Hide Artifacts

1
T1564

Hidden Files and Directories

1
T1564.001

Modify Registry

1
T1112

Discovery

System Information Discovery

2
T1082

Query Registry

1
T1012

Tasks