File name:

AsyncRAT.rar

Full analysis: https://app.any.run/tasks/77c164c8-9719-427f-a49d-bdd10ab264d4
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: January 30, 2024, 20:19:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
asyncrat
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

DFCCCF9242115CE1FF79847C20200E63

SHA1:

97D3F8197BE85AE3CC2A2FA36DD553033C66FA86

SHA256:

AD6379917A7BD5069085BC8A66AFEB4A4532F76CD921CC6EFB7BDE0FE9F88E38

SSDEEP:

98304:CC/aIsQ6AGuMCA7AqmYekWFZnR5DflUarlxYZCv/YVan7fwSdr7nEtznsqSbPGXf:hkkoxcDvS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ASYNCRAT has been detected (YARA)

      • AsyncRAT.exe (PID: 668)
      • AsyncRAT.exe (PID: 3576)
      • AsyncClient.exe (PID: 3668)
      • AsyncRAT.exe (PID: 3708)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1588)
      • AsyncRAT.exe (PID: 668)
  • SUSPICIOUS

    • Reads the Internet Settings

      • AsyncRAT.exe (PID: 668)
      • AsyncRAT.exe (PID: 3576)
      • AsyncRAT.exe (PID: 3708)
      • AsyncClient.exe (PID: 3668)
    • Executable content was dropped or overwritten

      • AsyncRAT.exe (PID: 668)
    • Reads settings of System Certificates

      • AsyncClient.exe (PID: 3668)
  • INFO

    • Reads Environment values

      • AsyncRAT.exe (PID: 3576)
      • AsyncRAT.exe (PID: 668)
      • AsyncClient.exe (PID: 3668)
      • AsyncRAT.exe (PID: 3708)
    • Checks supported languages

      • AsyncRAT.exe (PID: 3576)
      • AsyncRAT.exe (PID: 668)
      • wmpnscfg.exe (PID: 3316)
      • AsyncClient.exe (PID: 3668)
      • AsyncClient.exe (PID: 1432)
      • AsyncRAT.exe (PID: 3708)
      • AsyncClient.exe (PID: 2752)
    • Reads the computer name

      • AsyncRAT.exe (PID: 3576)
      • wmpnscfg.exe (PID: 3316)
      • AsyncRAT.exe (PID: 668)
      • AsyncClient.exe (PID: 3668)
      • AsyncClient.exe (PID: 1432)
      • AsyncClient.exe (PID: 2752)
      • AsyncRAT.exe (PID: 3708)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3316)
      • AsyncRAT.exe (PID: 668)
      • AsyncRAT.exe (PID: 3576)
      • AsyncClient.exe (PID: 3668)
      • AsyncClient.exe (PID: 1432)
      • AsyncRAT.exe (PID: 3708)
      • AsyncClient.exe (PID: 2752)
    • Reads the machine GUID from the registry

      • AsyncRAT.exe (PID: 668)
      • AsyncRAT.exe (PID: 3576)
      • AsyncClient.exe (PID: 3668)
      • AsyncClient.exe (PID: 1432)
      • AsyncRAT.exe (PID: 3708)
      • AsyncClient.exe (PID: 2752)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1588)
    • Creates files or folders in the user directory

      • AsyncRAT.exe (PID: 668)
      • AsyncRAT.exe (PID: 3576)
      • AsyncRAT.exe (PID: 3708)
    • Create files in a temporary directory

      • AsyncClient.exe (PID: 3668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

AsyncRat

(PID) Process(3668) AsyncClient.exe
C2 (1)127.0.0.1
Ports (3)6606
7707
8808
BotnetDefault
Version0.5.8
Options
AutoRunfalse
Mutex7S8TTULudN1y
InstallFolder%AppData%
BSoDfalse
AntiVMfalse
Certificates
Cert1MIIE8DCCAtigAwIBAgIQAPBu90DrdieqLjG/XFc+uzANBgkqhkiG9w0BAQ0FADAZMRcwFQYDVQQDDA5Bc3luY1JBVCBTZXJ2ZTAgFw0yNDAxMjgyMDIyMDNaGA85OTk5MTIzMTIzNTk1OVowGTEXMBUGA1UEAwwOQXN5bmNSQVQgU2VydmUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCiMKL7/7UYOtHEa6m0tYkOJzFvtX5W/yUdxkRQwts8GNlkxUkfEsy+ZlydgGlZ7+yHlVJWn348vzNd...
Server_SignaturebNBnauTO0J5mgDcVbVRUCUVUSzBm72jWaht7fFI5VC5TxLVfMOl8aYR3MOynFfZDt9AN6IC6zn11UuRpydYgUtqfbZb8JK5sQH4qXR2ld2EjHrWVZIYYOIxjta/0o3DNNHck+3iaxx9JIezoItjwL1bz2MTKhBh0ERZMzCceFDwP4qhRoEnv7q05itjAgfLCHjs0aTAY47lZtbduuCeCEhXeL9/FB7lK+/0VyAtCrnsWhhNjtdUbc6vlHyzvkFxHk+lYXzHrYlXu+b9qo7wWq4DGa7MUhyTeyc7PVXKLcwhf...
Keys
AES92c5b71edcbc6cbcdb1c644ca3023800f4f588dae016f51841447362df169101
Saltbfeb1e56fbcd973bb219022430a57843003d5644d21e62b9d4f180e7e6c33941
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
668"C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe" C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AsyncRAT
Exit code:
0
Version:
0.5.8.0
Modules
Images
c:\users\admin\desktop\asyncrat\asyncrat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1432"C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe" C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\asyncrat\asyncclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1588"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AsyncRAT.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2752"C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe" C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\asyncrat\asyncclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3316"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3576"C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe" C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AsyncRAT
Exit code:
0
Version:
0.5.8.0
Modules
Images
c:\users\admin\desktop\asyncrat\asyncrat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3668"C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe" C:\Users\admin\Desktop\AsyncRAT\AsyncClient.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\asyncrat\asyncclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
AsyncRat
(PID) Process(3668) AsyncClient.exe
C2 (1)127.0.0.1
Ports (3)6606
7707
8808
BotnetDefault
Version0.5.8
Options
AutoRunfalse
Mutex7S8TTULudN1y
InstallFolder%AppData%
BSoDfalse
AntiVMfalse
Certificates
Cert1MIIE8DCCAtigAwIBAgIQAPBu90DrdieqLjG/XFc+uzANBgkqhkiG9w0BAQ0FADAZMRcwFQYDVQQDDA5Bc3luY1JBVCBTZXJ2ZTAgFw0yNDAxMjgyMDIyMDNaGA85OTk5MTIzMTIzNTk1OVowGTEXMBUGA1UEAwwOQXN5bmNSQVQgU2VydmUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCiMKL7/7UYOtHEa6m0tYkOJzFvtX5W/yUdxkRQwts8GNlkxUkfEsy+ZlydgGlZ7+yHlVJWn348vzNd...
Server_SignaturebNBnauTO0J5mgDcVbVRUCUVUSzBm72jWaht7fFI5VC5TxLVfMOl8aYR3MOynFfZDt9AN6IC6zn11UuRpydYgUtqfbZb8JK5sQH4qXR2ld2EjHrWVZIYYOIxjta/0o3DNNHck+3iaxx9JIezoItjwL1bz2MTKhBh0ERZMzCceFDwP4qhRoEnv7q05itjAgfLCHjs0aTAY47lZtbduuCeCEhXeL9/FB7lK+/0VyAtCrnsWhhNjtdUbc6vlHyzvkFxHk+lYXzHrYlXu+b9qo7wWq4DGa7MUhyTeyc7PVXKLcwhf...
Keys
AES92c5b71edcbc6cbcdb1c644ca3023800f4f588dae016f51841447362df169101
Saltbfeb1e56fbcd973bb219022430a57843003d5644d21e62b9d4f180e7e6c33941
3708"C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe" C:\Users\admin\Desktop\AsyncRAT\AsyncRAT.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AsyncRAT
Exit code:
0
Version:
0.5.8.0
Modules
Images
c:\users\admin\desktop\asyncrat\asyncrat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
13 407
Read events
13 265
Write events
139
Delete events
3

Modification events

(PID) Process:(1588) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1588) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
16
Suspicious files
11
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\LimeLogger.dllexecutable
MD5:732839C93B7E0AB6796CB1C4544EDA66
SHA256:CD5CDF0EADE067FB0D97881258E4E29D88386CC9EC7A6EA315D159D284858857
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\FileSearcher.dllexecutable
MD5:4E1922EE8333847507A34823ED695131
SHA256:A6BDD625FA1D9A7EE66E4CA09CED0B3DCA8AFD2AD92ECAF44FD9A879B57CB198
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Recovery.dllexecutable
MD5:D8793438A77750CEA1B0D7EAAD3D0D0D
SHA256:7FD48AC68F182E0CED2ACE00B223FA1D35BD8A20D75600B5400267CD5DB5CC84
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\SendFile.dllexecutable
MD5:C4B11C003ED1E394597F6A5201826A59
SHA256:1A717C40FF7F60C18953B46A69A8FC47CCE7DAD6116CD3715DEB2ABF0D80722D
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\AsyncRAT.exeexecutable
MD5:97A429C4B6A2CB95ECE0DDB24C3C2152
SHA256:06899071233D61009A64C726A4523AA13D81C2517A0486CC99AC5931837008E5
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\AsyncRAT.exe.configxml
MD5:CB1F2DCFEB5CBB5AF8EFA7EA40B8E908
SHA256:58F956ABE9D717683F4A1CFA6F70E256C80461315A8D47B6456116B3D3075372
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Extra.dllexecutable
MD5:3BBCB7C7967C714F767D751DB17ED1D0
SHA256:7DD3978E7721F4460D639D17C47FE1307917DBACFB858D0D12E403105CD47089
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Chat.dllexecutable
MD5:B230DA150AA974D2A0801CEF654CBE05
SHA256:37D41C7042210845593DDD7E5A5E37A37F6605305264D50A30AA2BE1686000F6
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\FileManager.dllexecutable
MD5:9CAA1FA3B3B7824167610D309446223D
SHA256:9D1B94035F381B5183E82A317F001725674C8EA1C5CD82AB5AF408F7F53CA19D
1588WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1588.47756\AsyncRAT\Plugins\Miscellaneous.dllexecutable
MD5:07BA8685CA3FAFF186F0D9F5400C1117
SHA256:783D9D5334AA40F35ACF8FF941A6B5BED908FD94DC14A05712B8A9EB9220CD5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3668
AsyncClient.exe
GET
200
173.222.108.243:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d628b748aec6f287
CH
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3668
AsyncClient.exe
173.222.108.243:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 173.222.108.243
  • 173.222.108.210
  • 173.222.108.226
whitelisted

Threats

No threats detected
No debug info