ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | AsyncRAT.rar |
| Full analysis: | https://app.any.run/tasks/77c164c8-9719-427f-a49d-bdd10ab264d4 |
| Verdict: | Malicious activity |
| Threats: | AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions. |
| Analysis date: | January 30, 2024, 20:19:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | DFCCCF9242115CE1FF79847C20200E63 |
| SHA1: | 97D3F8197BE85AE3CC2A2FA36DD553033C66FA86 |
| SHA256: | AD6379917A7BD5069085BC8A66AFEB4A4532F76CD921CC6EFB7BDE0FE9F88E38 |
| SSDEEP: | 98304:CC/aIsQ6AGuMCA7AqmYekWFZnR5DflUarlxYZCv/YVan7fwSdr7nEtznsqSbPGXf:hkkoxcDvS |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 668 | "C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe" | C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: AsyncRAT Exit code: 0 Version: 0.5.8.0 Modules
| |||||||||||||||
| 1432 | "C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe" | C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1588 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AsyncRAT.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2752 | "C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe" | C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3316 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3576 | "C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe" | C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: AsyncRAT Exit code: 0 Version: 0.5.8.0 Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe" | C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 1.0.0.0 Modules
AsyncRat(PID) Process(3668) AsyncClient.exe C2 (1)127.0.0.1 Ports (3)6606 7707 8808 BotnetDefault Version0.5.8 Options AutoRunfalse Mutex7S8TTULudN1y InstallFolder%AppData% BSoDfalse AntiVMfalse Certificates Cert1MIIE8DCCAtigAwIBAgIQAPBu90DrdieqLjG/XFc+uzANBgkqhkiG9w0BAQ0FADAZMRcwFQYDVQQDDA5Bc3luY1JBVCBTZXJ2ZTAgFw0yNDAxMjgyMDIyMDNaGA85OTk5MTIzMTIzNTk1OVowGTEXMBUGA1UEAwwOQXN5bmNSQVQgU2VydmUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCiMKL7/7UYOtHEa6m0tYkOJzFvtX5W/yUdxkRQwts8GNlkxUkfEsy+ZlydgGlZ7+yHlVJWn348vzNd... Server_SignaturebNBnauTO0J5mgDcVbVRUCUVUSzBm72jWaht7fFI5VC5TxLVfMOl8aYR3MOynFfZDt9AN6IC6zn11UuRpydYgUtqfbZb8JK5sQH4qXR2ld2EjHrWVZIYYOIxjta/0o3DNNHck+3iaxx9JIezoItjwL1bz2MTKhBh0ERZMzCceFDwP4qhRoEnv7q05itjAgfLCHjs0aTAY47lZtbduuCeCEhXeL9/FB7lK+/0VyAtCrnsWhhNjtdUbc6vlHyzvkFxHk+lYXzHrYlXu+b9qo7wWq4DGa7MUhyTeyc7PVXKLcwhf... Keys AES92c5b71edcbc6cbcdb1c644ca3023800f4f588dae016f51841447362df169101 Saltbfeb1e56fbcd973bb219022430a57843003d5644d21e62b9d4f180e7e6c33941 | |||||||||||||||
| 3708 | "C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe" | C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: AsyncRAT Exit code: 0 Version: 0.5.8.0 Modules
| |||||||||||||||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1588) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\LimeLogger.dll | executable | |
MD5:732839C93B7E0AB6796CB1C4544EDA66 | SHA256:CD5CDF0EADE067FB0D97881258E4E29D88386CC9EC7A6EA315D159D284858857 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\FileSearcher.dll | executable | |
MD5:4E1922EE8333847507A34823ED695131 | SHA256:A6BDD625FA1D9A7EE66E4CA09CED0B3DCA8AFD2AD92ECAF44FD9A879B57CB198 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Recovery.dll | executable | |
MD5:D8793438A77750CEA1B0D7EAAD3D0D0D | SHA256:7FD48AC68F182E0CED2ACE00B223FA1D35BD8A20D75600B5400267CD5DB5CC84 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\SendFile.dll | executable | |
MD5:C4B11C003ED1E394597F6A5201826A59 | SHA256:1A717C40FF7F60C18953B46A69A8FC47CCE7DAD6116CD3715DEB2ABF0D80722D | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\AsyncRAT.exe | executable | |
MD5:97A429C4B6A2CB95ECE0DDB24C3C2152 | SHA256:06899071233D61009A64C726A4523AA13D81C2517A0486CC99AC5931837008E5 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\AsyncRAT.exe.config | xml | |
MD5:CB1F2DCFEB5CBB5AF8EFA7EA40B8E908 | SHA256:58F956ABE9D717683F4A1CFA6F70E256C80461315A8D47B6456116B3D3075372 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Extra.dll | executable | |
MD5:3BBCB7C7967C714F767D751DB17ED1D0 | SHA256:7DD3978E7721F4460D639D17C47FE1307917DBACFB858D0D12E403105CD47089 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Chat.dll | executable | |
MD5:B230DA150AA974D2A0801CEF654CBE05 | SHA256:37D41C7042210845593DDD7E5A5E37A37F6605305264D50A30AA2BE1686000F6 | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\FileManager.dll | executable | |
MD5:9CAA1FA3B3B7824167610D309446223D | SHA256:9D1B94035F381B5183E82A317F001725674C8EA1C5CD82AB5AF408F7F53CA19D | |||
| 1588 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Miscellaneous.dll | executable | |
MD5:07BA8685CA3FAFF186F0D9F5400C1117 | SHA256:783D9D5334AA40F35ACF8FF941A6B5BED908FD94DC14A05712B8A9EB9220CD5B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3668 | AsyncClient.exe | GET | 200 | 173.222.108.243:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d628b748aec6f287 | CH | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3668 | AsyncClient.exe | 173.222.108.243:80 | ctldl.windowsupdate.com | Akamai International B.V. | CH | unknown |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |