General

  • Target

    WaveInstaller (1).exe

  • Size

    1.6MB

  • Sample

    240705-r36mmasfqc

  • MD5

    00799dbcc9576bd4e72bef9700f27c1a

  • SHA1

    775d737e89f7a03209e383f3f3cb4fc1176865fe

  • SHA256

    b86a0eaa31ac1716902429c6bbef6b21ee987e667da7b236200b0199db69b837

  • SHA512

    ebef9a957a4c6e697e77ab01db5b45491a35cf5222bf332a7f7ee948783aaa0f96af7b627ba47bcfc193d3988a77a8d093379558aa0fa2556966ce84b1b54f9b

  • SSDEEP

    24576:2kxTd6WYLGJOgDLPgOAVG/v9l3bP0urOvGwaNmIfKG5xL/dEuvS:XciOgPPgOGG/vT7rrUGwaUIiG5lFS

Malware Config

Extracted

Family

asyncrat

Version

Venom RAT + HVNC + Stealer + Grabber v6.0.3

Botnet

Default

Mutex

excrnlqzxfdl

Attributes
  • delay

    1

  • install

    true

  • install_file

    Registry.exe

  • install_folder

    %AppData%

  • pastebin_config

    https://pastebin.com/raw/w5QC7zcd

aes.plain

Targets

    • Target

      WaveInstaller (1).exe

    • Size

      1.6MB

    • MD5

      00799dbcc9576bd4e72bef9700f27c1a

    • SHA1

      775d737e89f7a03209e383f3f3cb4fc1176865fe

    • SHA256

      b86a0eaa31ac1716902429c6bbef6b21ee987e667da7b236200b0199db69b837

    • SHA512

      ebef9a957a4c6e697e77ab01db5b45491a35cf5222bf332a7f7ee948783aaa0f96af7b627ba47bcfc193d3988a77a8d093379558aa0fa2556966ce84b1b54f9b

    • SSDEEP

      24576:2kxTd6WYLGJOgDLPgOAVG/v9l3bP0urOvGwaNmIfKG5xL/dEuvS:XciOgPPgOGG/vT7rrUGwaUIiG5lFS

    • AsyncRat

      AsyncRAT is designed to remotely monitor and control other computers written in C#.

    • Async RAT payload

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Legitimate hosting services abused for malware hosting/C2

MITRE ATT&CK Matrix ATT&CK v13

Execution

Command and Scripting Interpreter

1
T1059

PowerShell

1
T1059.001

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Persistence

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Privilege Escalation

Scheduled Task/Job

1
T1053

Scheduled Task

1
T1053.005

Discovery

Query Registry

4
T1012

System Information Discovery

3
T1082

Command and Control

Web Service

1
T1102

Tasks