Suspicious
Suspect

115a1aafb4fcab45d56972de88c55e4e

PE Executable
MD5: 115a1aafb4fcab45d56972de88c55e4e
Size: 33.28 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very low
MD5 115a1aafb4fcab45d56972de88c55e4e
Sha1 70f73fd3b046ea2e0b72dc09cfde61298a2d754e
Sha256 e9c9827d41d12feb1ccc270cba9f82b08da359999fb95fdaa59f45015bcc90b1
Sha384 b6cfa1bdaccc93d500236cb390e6127391cf61338112fd264aa34590b1b9564600c3c08d9796c9775e2d0991a5ad380f
Sha512 2ec0b37e6919563c6c54f9535071b7073210579b24ea9553909006e2d2443a4cd9ffdfb2d7d7d6e836d46787b5668a0d4f01da7ee912d1ec0b363f41ebcae91e
SSDeep 768:1nq/q+Sc5zEr2z65I1sYwkbs4q1MguQ+:1WFvRE6OkbFqeguQ+
TLSH 27E23A0473E49625E2FE4ABD593291045336F6475E23D79E2FD8A08F1623BC88F51FA1
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Module Name
MalwareRAT.exe
Full Name
MalwareRAT.exe
EntryPoint
System.Void Client.Program::Main()
Scope Name
MalwareRAT.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
MalwareRAT
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
191
Main Method
System.Void Client.Program::Main()
Main IL Instruction Count
56
Main IL
nop <null>
nop <null>
ldsfld System.String Client.Settings::Install
call System.Boolean System.Convert::ToBoolean(System.String)
stloc.0 <null>
ldloc.0 <null>
brfalse.s IL_0016: ldsfld System.String Client.Settings::BDOS
call System.Void Client.Install.NormalStartup::Install()
nop <null>
ldsfld System.String Client.Settings::BDOS
call System.Boolean System.Convert::ToBoolean(System.String)
brfalse.s IL_0029: ldc.i4.0
call System.Boolean Client.Helper.Methods::IsAdmin()
br.s IL_002A: stloc.1
ldc.i4.0 <null>
stloc.1 <null>
ldloc.1 <null>
brfalse.s IL_0034: call System.Void Client.Helper.Methods::PreventSleep()
call System.Void Client.Helper.ProcessCritical::Set()
nop <null>
call System.Void Client.Helper.Methods::PreventSleep()
nop <null>
nop <null>
leave.s IL_0042: br.s IL_0074
pop <null>
nop <null>
nop <null>
leave.s IL_0042: br.s IL_0074
br.s IL_0074: ldc.i4.1
nop <null>
nop <null>
call System.Boolean Client.Connection.ClientSocket::get_IsConnected()
ldc.i4.0 <null>
ceq <null>
stloc.2 <null>
ldloc.2 <null>
brfalse.s IL_0060: nop
nop <null>
call System.Void Client.Connection.ClientSocket::Reconnect()
nop <null>
call System.Void Client.Connection.ClientSocket::InitializeClient()
nop <null>
nop <null>
nop <null>
leave.s IL_0068: ldc.i4 5000
pop <null>
nop <null>
nop <null>
leave.s IL_0068: ldc.i4 5000
ldc.i4 5000
call System.Void System.Threading.Thread::Sleep(System.Int32)
nop <null>
nop <null>
ldc.i4.1 <null>
stloc.3 <null>
br.s IL_0044: nop
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: D:\mw\AsyncRAT_1\AsyncRAT-C#\Client\obj\Debug\MalwareRAT.pdb
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙