Play interactive tourEdit tour
Windows Analysis Report KDH32783JHC73287SDF87.VBS
Overview
General Information
Detection
AsyncRAT
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
VBScript performs obfuscated calls to suspicious functions
Yara detected AsyncRAT
Antivirus detection for dropped file
Yara detected Powershell download and execute
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Writes to foreign memory regions
Compiles code for process injection (via .Net compiler)
Wscript starts Powershell (via cmd or directly)
Bypasses PowerShell execution policy
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected Costura Assembly Loader
Sigma detected: Suspicious PowerShell Command Line
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
Sigma detected: MSHTA Spawning Windows Shell
Obfuscated command line found
Creates an undocumented autostart registry key
Sigma detected: Mshta Spawning Windows Shell
Sigma detected: WScript or CScript Dropper
C2 URLs / IPs found in malware configuration
Sigma detected: Suspicious Csc.exe Source File Folder
Uses dynamic DNS services
Tries to harvest and steal browser information (history, passwords, etc)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Stores large binary data to the registry
Sample execution stops while process was sleeping (likely an evasion)
JA3 SSL client fingerprint seen in connection with other malware
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
Uses insecure TLS / SSL version for HTTPS connection
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
AV process strings found (often used to terminate AV products)
PE file does not import any functions
Java / VBScript file with very long strings (likely obfuscated code)
Searches for the Microsoft Outlook file path
Drops PE files
Tries to load missing DLLs
Detected TCP or UDP traffic on non-standard ports
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Compiles C# or VB.Net code
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: AsyncRAT |
---|
{"Server": "mo1010.duckdns.org", "Ports": "1010", "Version": "0.5.7B", "Autorun": "false", "Install_Folder": "%AppData%", "Install_File": "", "AES_key": "cavQVZf7osGMKDDytqZ6EDmJ5n2UgBk8", "Mutex": "AsyncMutex_6SI8OkPnk", "AntiDetection": "false", "External_config_on_Pastebin": "null", "BDOS": "false", "Startup_Delay": "3", "HWID": "null", "Certificate": "MIIE8jCCAtqgAwIBAgIQAJAz27qyWIi2FmYH0D0HHzANBgkqhkiG9w0BAQ0FADAaMRgwFgYDVQQDDA9Bc3luY1JBVCBTZXJ2ZXIwIBcNMjEwOTIwMDI0MzI0WhgPOTk5OTEyMzEyMzU5NTlaMBoxGDAWBgNVBAMMD0FzeW5jUkFUIFNlcnZlcjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAJNaTvGiSjKlfmPMVTEXQRetARCxvzPtIPxBZ9Q7itx0EVPNWU7CdxUz+G/SN+FykW26xzCu01Dbyual0D/9YHN8gKEmYkbVMABjLotY74Qfl0JEyx+GlU8Q/tAb1P2ywVy+JLoEmXm0KCRszRz9+ccqPli/NF1B0kZNdDMIPi5l+6/K5DvfgWwZ+esMu17wvo8iHm2YET4W5fcKJ/wKJd/uucvfZ9olryj8TT7BgoFwQiZuua2xaw5oMtzYvn/rqdGqvu4kc8HJS+c8DKGs25wy4xjxQNGBWszfSwiPliySmUUuXWMXX5EsCvxt62nB/T0fhn8RCbHEFKhcdVwhvwiX/Aqt5ebXggxLwuxRKdLIAJC4WzMLCVtoMltj4u5OdAF7qr2gQp92ULR2QSsTqOiBDBIkahPyAbJnvqOWX6yCDbo/iLzuxADMgJuqhIOkCBMag5+Cla84NtCgcXqinga2T1Wk8DlXBK4UNXbDFu2TY0tOMkr5c8QCfeALlNUDe72iZLchMa+acJQd4zXWgzsPV5gdgXn+EXbiFxHCQ320SygPP3sArTXkVMe1/cYpQY36t3Xsx8/jsZvDSch2NePjJa+hPXgoBvzLW/KdHpyKJ/nH0NJFjCoiND/2OViZ2FYGACOdNYjai3+d04MJpKJ4DsAKCWUs14MvImV/WK3pAgMBAAGjMjAwMB0GA1UdDgQWBBR+g5E8J076qCzjsnkVylHLdWvsSjAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDQUAA4ICAQA+kuRXiVE2XGsQDVfs9FTnwnJ6B/w7uowYKG5x3+jR+botdt49Dzd9hqRTetVqpRo4SvPiav8F1k/P5pC5R0afEIQl5OkLOXYx4n8Pq9Sh6TThKgyerb1zv1bqZfyCLAidx2wM4yLCadkkqKhXTrI/YZBkvHtKn1cUEVTQi8MXphAZMQFxlhdNYc04+592zFJnatx+M/gVAA7fAHF/dMmzm06k783xt/K6SxQC4NQ5yXV5DTyCbTVAMOOLFZlJIz67nN7FUFUtQ02SMTxh8yMICDyMopnhJyOhx/1cDNklOzco87JectaL+vDJ12/P1sywLrCWhduaB+ngYfXPJRhyeHbSLty4O+D+p3tmpmWy0D5NHWk4TFy0Tt9VXGtV8U2DDAlikKyZiAAN6nz0xB+NZ05mp0kyqB7C2q7OnZlkNH+jO+CDL/VhXlq7yfQwDxQ93NoS6cqGqqYNQvyNeIjaTxmMWowHM4QpszbCEbdksOPuvrOtAwwpLLgz62fkcbNN/2VRZkG6c36eU6avlD/dr4uYB3ou9Bk6hGQA1+Tw9JkfG8TAr2vC9YFqide9P1CGF3xQvo5G7/6RDN8H0zsaXmjsS9umY9wm2eEf0sprbHuwf+z6IpaVOWGyIdXY8ePVVJyL6mhLPsoqengpwRUl9+pizfeTWJ6oygud6DbRHw==", "ServerSignature": "A/n28mlKHRpABn1XleVu2B5EJNcUIcSJ1NVH/qHFhyP3VRxiHDxHzv19Tc5gU9jMlePSW3WyYs0Qbt6JOLVMZ1Vwse1JgI6CJlkb6Mu2Umrpd1CULO9yUF94eR8KvgsFrwiH1PeHtLOa2QaTEy6tZXWH+m3kPiCvBAh2GQporTqGbIWqxAKtu/7roMmhPw/75o4ml0o7B5x6CB0B6iwvLyRbG7EiCq1KnludEJQLWdOzQOcIzStkRtOiBjFIgLuqM6OfJYKO3ZhEXRzpkznk5t9id2kQn01446/1hxFl1LMl+2fQSvv6cW9lTykckSFd6qjlKoLC31A1WfOO0CsY4xEvSDGaHGNu43u+rvPfgrGBwufkbGHKrO4hM4kOjtnj+tCOKnIYC74xwq58jIs5xgmhUIHTwolDzyuD/KKrOuvk/WaZmgQw2OelUza+aWJxagH2jSKbAdKG/y7bovupy0+sxzgyB98UjoIHY9aKtVsvrL23IdG6w6huoXGqjHOlWBCZYSJ7Dgzkv6h/N1F2dRrQ378E+wuOnN058wNnBfku+u7uPBaFusF5kCYVHg01vRvGKJFZaXx++we4eJ3a3B2tdBYDdL18D70dxP6gRn+5JUGGIAM1kmO2wWxXgx7hO4HhARMbZew2L9L3X8u4Yx3dbRisGb9B8P5Vt3NeTF4=", "Group": "Default"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
PowerShell_Susp_Parameter_Combo | Detects PowerShell invocation with suspicious parameters | Florian Roth |
| |
Click to see the 3 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security |
Sigma Overview |
---|
System Summary: |
---|
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments | Show sources |
Source: | Author: Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth, Christian Burkard: |
Sigma detected: Suspicious PowerShell Command Line | Show sources |
Source: | Author: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community: |