Malicious
Malicious

Share on LinkedIn
Print
PE Executable
MD5: 29f352c9449534d38212375258517a45
Size: 30.72 KB
application/x-dosexec
Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Low

Hash
Hash Value
MD5
29f352c9449534d38212375258517a45
Sha1
2997be7d3009e304b07f16639133ed9c6620d83d
Sha256
5956f2eb705589549010d0bc2061369363791018e312eea2bdf2d5ef905d153e
Sha384
0dbdb61778124e134c86bcf1671a8d92cb8c43d044a2f85b6afc33b3c58458fc32e6ffa8e8ac2c0a12b5104688dc49c3
Sha512
80b900f74fd9d0395a8a27ae695c57a6e6fd9bd47cabc78958e5c4a91cf46ad0e36c01cddcb55eec889c661bb5b46249ff3582802b9b29a2377db202fb617f4e
SSDeep
768:o0oRXxvJ/qymYg/cIRGqou/Rb7fB/dTY/+:PoRXD/qymB1igRbN/C/+
TLSH
EDD23B08B3D48562E1FD57B94D7292048771EE5B9973DB9E1FC440AE2623B88CF15BE0
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Malware Configuration - AsyncRAT config.
Config. Field
Value
Key (AES_256)
Byhuhuhuhu
Pastebin
-huhuhuhu
Install
fhuhuhuhu
Install File
Asynhuhuhuhu
Install-Folder
%Cerhuhuhuhuhuhuhu
Version
0.huhuhuhu
Hosts
c88huhuhuhu
Mutex
Globalhuhuhuhuhuhuhuhuhuhuhu
Delay
0huhuhuhu
Group
Aphuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: D:\Cong Viec\malware\AsyncRAT-C-Sharp\malware chuan 1\AsyncRAT-C-Sharp-master\AsyncRAT-C#\Client\obj\Debug\AsyncRAT.pdb

Module Name

AsyncRAT.exe

Full Name

AsyncRAT.exe

EntryPoint

System.Void Client.Program::Main()

Scope Name

AsyncRAT.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

AsyncRAT

Assembly Version

1.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.8

Total Strings

147

Main Method

System.Void Client.Program::Main()

Main IL Instruction Count

101

Main IL

nop <null> ldc.i4.0 <null> stloc.0 <null> br.s IL_0016: ldloc.0 nop <null> ldc.i4 1000 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> nop <null> ldloc.0 <null> ldc.i4.1 <null> add <null> stloc.0 <null> ldloc.0 <null> ldsfld System.String Client.Settings::Delay call System.Int32 System.Convert::ToInt32(System.String) clt <null> stloc.1 <null> ldloc.1 <null> brtrue.s IL_0005: nop call System.Boolean Client.Settings::InitializeSettings() ldc.i4.0 <null> ceq <null> stloc.2 <null> ldloc.2 <null> brfalse.s IL_003A: nop ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> nop <null> nop <null> call System.Boolean Client.Helper.MutexControl::CreateMutex() ldc.i4.0 <null> ceq <null> stloc.3 <null> ldloc.3 <null> brfalse.s IL_004F: ldsfld System.String Client.Settings::Anti ldc.i4.0 <null> call System.Void System.Environment::Exit(System.Int32) nop <null> ldsfld System.String Client.Settings::Anti call System.Boolean System.Convert::ToBoolean(System.String) stloc.s V_4 ldloc.s V_4 brfalse.s IL_0065: ldsfld System.String Client.Settings::Install call System.Void Client.Helper.Anti_Analysis::RunAntiAnalysis() nop <null> ldsfld System.String Client.Settings::Install call System.Boolean System.Convert::ToBoolean(System.String) stloc.s V_5 ldloc.s V_5 brfalse.s IL_007B: ldsfld System.String Client.Settings::BDOS call System.Void Client.Install.NormalStartup::Install() nop <null> ldsfld System.String Client.Settings::BDOS call System.Boolean System.Convert::ToBoolean(System.String) brfalse.s IL_008E: ldc.i4.0 call System.Boolean Client.Helper.Methods::IsAdmin() br.s IL_008F: stloc.s V_6 ldc.i4.0 <null> stloc.s V_6 ldloc.s V_6 brfalse.s IL_009B: call System.Void Client.Helper.Methods::PreventSleep() call System.Void Client.Helper.ProcessCritical::Set() nop <null> call System.Void Client.Helper.Methods::PreventSleep() nop <null> nop <null> leave.s IL_00A9: br.s IL_00DD pop <null> nop <null> nop <null> leave.s IL_00A9: br.s IL_00DD br.s IL_00DD: ldc.i4.1 nop <null> nop <null> call System.Boolean Client.Connection.ClientSocket::get_IsConnected() ldc.i4.0 <null> ceq <null> stloc.s V_7 ldloc.s V_7 brfalse.s IL_00C9: nop nop <null> call System.Void Client.Connection.ClientSocket::Reconnect() nop <null> call System.Void Client.Connection.ClientSocket::InitializeClient() nop <null> nop <null> nop <null> leave.s IL_00D1: ldc.i4 5000 pop <null> nop <null> nop <null> leave.s IL_00D1: ldc.i4 5000 ldc.i4 5000 call System.Void System.Threading.Thread::Sleep(System.Int32) nop <null> nop <null> ldc.i4.1 <null> stloc.s V_8 br.s IL_00AB: nop

Artefacts
Name
Value
Key (AES_256)
Byhuhuhuhu
CnC
c88huhuhuhu
Mutex
Globalhuhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys…) are available with Essential.
Unlock with Essential
29f352c9449534d38212375258517a45 (30.72 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙