Edit tour
Windows
Analysis Report
rrats.exe
Overview
General Information
Detection
AsyncRAT
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Schedule system process
System process connects to network (likely due to code injection or exploit)
Yara detected AsyncRAT
AI detected suspicious sample
Adds a directory exclusion to Windows Defender
Connects to a pastebin service (likely for C&C)
Drops PE files with benign system names
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Protects its processes via BreakOnTermination flag
Sigma detected: Cmd.EXE Missing Space Characters Execution Anomaly
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: System File Execution Location Anomaly
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Generic Downloader
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
File is packed with WinRar
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found evasive API chain (date check)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Schtasks From Env Var Folder
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match
Classification
- System is w10x64
- rrats.exe (PID: 5780 cmdline:
"C:\Users\ user\Deskt op\rrats.e xe" MD5: A2BDB024C98B7E8D3D06FC86E110D204) - cmd.exe (PID: 3812 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Local \Temp\RarS FX0\a.bat" " MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6664 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - a.exe (PID: 1372 cmdline:
a.exe -p12 34 MD5: 7107F3FB53F9F3EAF3B95FD857F7AEE9) - rrat.exe (PID: 1968 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\RarSFX 1\rrat.exe " MD5: 3D91C31A52BE4E262F7F18272294ED99) - cmd.exe (PID: 5712 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell Add-Mp Preference -Exclusio nPath C:\ MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5524 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 2180 cmdline:
powershell Add-MpPre ference -E xclusionPa th C:\ MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - cmd.exe (PID: 7212 cmdline:
"C:\Window s\System32 \cmd.exe" /c schtask s /create /f /sc onl ogon /rl h ighest /tn "Windows\ WindowsUpd ater" /tr '"C:\Users \user\AppD ata\Roamin g\Explorer .exe"' & e xit MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 7220 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - schtasks.exe (PID: 7292 cmdline:
schtasks / create /f /sc onlogo n /rl high est /tn "W indows\Win dowsUpdate r" /tr '"C :\Users\us er\AppData \Roaming\E xplorer.ex e"' MD5: 48C2FE20575769DE916F48EF0676A965) - cmd.exe (PID: 7228 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Local \Temp\tmpE 75F.tmp.ba t"" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 7264 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - timeout.exe (PID: 7324 cmdline:
timeout 3 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - Explorer.exe (PID: 7412 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Explorer. exe" MD5: 3D91C31A52BE4E262F7F18272294ED99)
- Explorer.exe (PID: 7356 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Explorer.e xe MD5: 3D91C31A52BE4E262F7F18272294ED99) - cmd.exe (PID: 7492 cmdline:
"C:\Window s\System32 \cmd.exe" /Cschtasks /create / f /sc ONID LE /i 1 /r l highest /tn "Windo ws\WinUpda te" /tr "C :\Users\us er\AppData \Local\exp lore.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 7500 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - schtasks.exe (PID: 7588 cmdline:
schtasks / create /f /sc ONIDLE /i 1 /rl highest /t n "Windows \WinUpdate " /tr "C:\ Users\user \AppData\L ocal\explo re.exe" MD5: 48C2FE20575769DE916F48EF0676A965) - cmd.exe (PID: 7512 cmdline:
"C:\Window s\System32 \cmd.exe" /Cschtasks /create / f /sc ONID LE /i 1 /r l highest /tn "Windo ws\WinUpda ters" /tr "cmd.exe / C powershe ll Add-MpP reference -Exclusion Path C:\" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 7540 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - schtasks.exe (PID: 7596 cmdline:
schtasks / create /f /sc ONIDLE /i 1 /rl highest /t n "Windows \WinUpdate rs" /tr "c md.exe /C powershell Add-MpPre ference -E xclusionPa th C:\" MD5: 48C2FE20575769DE916F48EF0676A965)
- explore.exe (PID: 7636 cmdline:
C:\Users\u ser\AppDat a\Local\ex plore.exe MD5: 3D91C31A52BE4E262F7F18272294ED99)
- cmd.exe (PID: 7652 cmdline:
cmd.exe /C powershel l Add-MpPr eference - ExclusionP ath C:" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7692 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7748 cmdline:
powershell Add-MpPre ference -E xclusionPa th C:" MD5: 04029E121A0CFA5991749937DD22A1D9)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
AsyncRAT | AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victims computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques. | No Attribution |
{"Mutex": "RRAT_nMo7Zfs0N", "Certificate": "MIIE8jCCAtqgAwIBAgIQAP1hzmrgL5qNkPrA8fqq+zANBgkqhkiG9w0BAQ0FADAaMRgwFgYDVQQDDA9Bc3luY1JBVCBTZXJ2ZXIwIBcNMjAwNTA3MTgyNTI2WhgPOTk5OTEyMzEyMzU5NTlaMBoxGDAWBgNVBAMMD0FzeW5jUkFUIFNlcnZlcjCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAIIo9I64dBM7+4GawVLepf4oWhJAOY/dJ4gs5A8ivFPxJKpcXVNbUAF3J8kQGcQXQ9rP3T9mI6kK9FQVIHkQHkQ9CujdjULUw48/DnhM6TxtZKGAPNMceY6UjTOmvEASzwOzsIG16akW9RY2S4wbu2VRg7rkU9eiY3rtqt16/eJZgVZHWiO4hjkNgUyJCbkgxceew6xcmqQFaSAAcohOdaUJepuO6LLkt+rbwLIlCASIvM53oqu2eNL8Xk5/2bP2dhKTBfX/aD9xsfAN1BacEg5QcmwZgOeP8JJUC3nWLwXq8tRMPeTPYp9veHaQn9wWst6Rm3rDAh5bYbLxWNj4wi1stiAJ0yk0/+XXL5IQyCPfW/Q5oFYw+hhDiGFJQfim2ZfBvOjjoPVDdovpWp90c87gaiWGZbzLSedTomNfGcC36wUagtkKBXPFbcv4eWIXoPdwSjPk5LgJKgY+0g8iOCzawN9vIzUmkb3LPDwiluIqCOvqmUeAlrkthBhFJCOdfylNa3h4yDAsaZ+skQJle/YoF8AjBn0xAXsX1Q67/FSRUNDosuU+dqIZrii7jP8Qqc2F663sGamumrSAl3PXBL+UhVYoqkQqZG/D6e4qllcwH+dXBB27TMqY3b+xCv+slaraW2OIpYLQvTxGurpRF+BiCClZ9R0saYV2aSHBJW0rAgMBAAGjMjAwMB0GA1UdDgQWBBSjj9Cw11x4A95sxB4xy2LBe/0D8DAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDQUAA4ICAQBx9/VPQZFmIlqEl6QlR1lrToLbBdvksyr90Q/6LdGj9jlFfYpuzJjoSZ6UWYXifwEPHAIuaEqAzb91WeRkLgW6foTLlOOMu7fGFxi895huFT/QKfSUiKIRNxS8sM+/vBBz3YtvhehQaabSomOzl93/V5VJDt0e3xaANUeuVmnUlE1OMWWM0qRrGJtd7F8fE5Uk/rh7gIA/o8maQECpxpyHL1KTdcxdC3B+GyNQHYqiU9F/wRK5Zpx1+3YJ7162KhWtpzlm8iaVQToY3k8GPZkwj8sDRkuPpCzhDw3aHNtsAQmY0JEjBJcPAVCZ+/VzSboE+auT58BjwUf2DQRi2Xzh2jc/G08yvViXL4N88ZnK9QTiyMi50TFHBiqIizfDHL2YDJg2XpatRul49SPTxmIuwUt/3Wljz3kn/UM8MpcXPZbbzZMIYPjTiBqo9DijlBa/6JP4gtfzmgz6LCSv4wRGKR/9/Xkese/mE43zVLZopDMDn3tiPq8jobJ+2UAmm/V4WeRu3SiVn54aalDW3y9aWXpJhBXhldW+mF3q596n79OZDUNHZeor1Q3IFrXHZ/7zv9gk6Y5H96aQYUSEchAJikxVPk9Y5fygR16QG0U9sx0+7vTots9ioqvm7XMa+5xfZ+qk35RuiNqSlOY66mLEO0vex8cFFp3rvGj89VqD4g==", "Server Signature": "ZAEVYE4+WDbUbphyNWIlYDNiT/0G1m9oCuNRmqApkPq6DK43FO9IDy0E8zAIsJqQGMPgP1NzlXR2kcsyXklHOExDxYS3BgDNGipVUm+7oBSM9xIUV90aAwMlMzGtD/d5LKJ50z3PIis8Nj9WXzSPSL1/AbQ9Lq13L9V7jdRZiDkVQb2sLWoUErXM4eM0zmtCIpvRbO6yvBr/zUh3mKmOtugjkXGwE7CMEWCCB4fnfJm4tKYpDle+WxRa/ZfioEFdHTi9ZgzDLBvOWbQZWJMVvrlkXNZ7ENh/Ugpd+1rggG0z06CRTxmnEULOb+ej2kTU57iWbicoZRsme2t5XSwWmnD6OTmX1/mlgn9YnRFiqiL1GZlkNhXSuLUMELD7FV3L7xO86rjZLt8dX+BrHCZCzFF+3yzI7IEnpIf5Lmr+Q29LgsdB+ZUeCIBGnJ8GinuDNlijxi9AWzYj3Nmukgv2ltukS1k8021CWQu6TRKJXURqrECPkCwdt4z8i3A/3ojdz9AwFyK4tXUop7fkL++8lwinbMBXgxDLcXd/y+nmv34okEGRYMH5VUz1v6QIrfHhyYHSiQ7NqQ5953KaE+u9FN0JXCtZxmd2WiW/aoYw3ob7HIexuk0ytURxvG52YyVfdMuzhqe9QDc8U4MkkkOO4eQK2F/5q/iG99dyHrKwVek=", "External_config_on_Pastebin": "http://pastebin.com/raw/hbwHfEg3"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
| |
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Click to see the 4 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
| |
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
| |
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
Click to see the 14 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
| |
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Click to see the 3 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative: |
Persistence and Installation Behavior |
---|
Source: | Author: Joe Security: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-09T14:12:40.786601+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49760 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:12:53.020544+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49795 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:02.207565+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49819 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:08.614808+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49836 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:13:11.467632+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49844 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:20.624120+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49869 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:29.787528+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49894 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:36.117241+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49911 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:13:38.962820+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49919 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:48.479837+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49942 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:13:54.927268+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49959 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:13:57.774564+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49968 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:14:06.899015+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49994 | 172.67.19.24 | 443 | TCP |
2024-12-09T14:14:13.630369+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50010 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:14:20.317839+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50021 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:14:26.523182+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50023 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:14:34.583291+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50026 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:14:41.130094+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50028 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:14:47.676907+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50030 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:14:54.442475+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50033 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:01.185178+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50036 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:07.864248+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50039 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:22.618944+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50047 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:37.637427+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50053 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:38.178561+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50053 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:44.362516+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50054 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:44.785853+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50054 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:51.334402+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50056 | 172.67.19.24 | 80 | TCP |
2024-12-09T14:15:57.863773+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 50057 | 172.67.19.24 | 80 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |