MALICIOUS — 0f0fd4870160fab8ca35512ecef8425e8c0e733f7a771109598e8efa36fc42e3.exe
MALICIOUS — 0f0fd4870160fab8ca35512ecef8425e8c0e733f7a771109598e8efa36fc42e3.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the AsyncRAT family. 6 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0f0fd4870160fab8ca35512ecef8425e8c0e733f7a771109598e8efa36fc42e3 - SHA-1:
0c1e615682656ef0567acd7a9dc4a1336cd67831 - MD5:
3b37fec109ca8e946266eb1bdf8ac1cd - imphash:
246a347f07eeee769d4ff08b3997a170 - ssdeep:
98304:YHKJElk0e+uXuzE9/c3m9u9CNJ4H3Fdyr0g3FMzCFoDC2rA/95Bn+:USMcNI42zCCDCWA/B - TLSH:
T1026B6BA140037211D5F5FC54B431C9EC802BB469A5719ECD920BE66E83EDBB7A6F00B6 - Submitted as: 0f0fd4870160fab8ca35512ecef8425e8c0e733f7a771109598e8efa36fc42e3.exe
- File type: pe · Size: 9956864 bytes
- Verdict: malicious (100/100) · Family: AsyncRAT
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (6 of 52 engines)
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Trellix/McAfee ATR: ATR_REvil_Sodinokibi
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Gen:Variant.Yogi.37984
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 10 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - Extracted AsyncRAT config (2 C2) - engine signal, weight 0.80, confidence 0.65
- Microsoft Defender flagged Trojan:Win32/Malgent (rule
Trojan:Win32/Malgent) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Yogi.37984 (rule
Gen:Variant.Yogi.37984) - engine signal, weight 0.55, confidence 0.85 - Contacted 42 external host(s) at runtime (29 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Trellix/McAfee ATR flagged ATR_REvil_Sodinokibi (rule
ATR_REvil_Sodinokibi) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://your-server.com, https://docs.rs/getrandom#nodejs-es-module-supportinternal_codeunknown_codeos_error, https://docs.rs/rustls/latest/rustls/manual/_03_howto/index.html#unexpected-eofTLS - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
954 behavior events · 1 ATT&CK techniques · 5 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- c.pki.goog
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- licensing.mp.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- fe3cr.delivery.mp.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/10782/files/0e90538b0be48f632bc0cd832d5c8e36faa5f962ad78e1c76907cca2878c6ac8 -
0e90538b0be48f632bc0cd832d5c8e36faa5f962ad78e1c76907cca2878c6ac8 - /opt/CAPEv2/storage/analyses/10782/files/422337745519e0c3a0ca8b605e6093dac52ba5859dd793fd180b4c64e6b09f78 -
422337745519e0c3a0ca8b605e6093dac52ba5859dd793fd180b4c64e6b09f78 - /opt/CAPEv2/storage/analyses/10782/files/51d39f39f884e264f73d1f5f8f6d69c98540138d65d637af108c1b4dfc95ffb6 -
51d39f39f884e264f73d1f5f8f6d69c98540138d65d637af108c1b4dfc95ffb6 - /opt/CAPEv2/storage/analyses/10782/files/2f92ebcf33481b1c16cf83190449b1f7e184c4979ca50cf182c725c935277114 -
2f92ebcf33481b1c16cf83190449b1f7e184c4979ca50cf182c725c935277114 - /opt/CAPEv2/storage/analyses/10782/files/3dd95f107bd1e526b68e2d76a8bfda06e728ffeed32611f08f737fb12f013095 -
3dd95f107bd1e526b68e2d76a8bfda06e728ffeed32611f08f737fb12f013095
Embedded URLs
- https://your-server.com
- https://github.com/clap-rs/clap/issues
- https://docs.rs/getrandom#nodejs-es-module-supportinternal_codeunknown_codeos_error
- https://docs.rs/rustls/latest/rustls/manual/_03_howto/index.html#unexpected-eofTLS
- http://www.msftconnecttest.com/connecttest.txt
- http://203.26.79.13/filestreamingservice//files/736bdc20-582e-46c5-ba31-d31d3d97258e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/736bdc20-582e-46c5-ba31-d31d3d97258e?P1=1786461593&P2=404&P3=2&P4=G7bxvl9GIWNLSVfRzVaQAI19ZhUld8gRx1J0xlOhDL6ZgBRjexUslVJ17OLMi0MBeIz0VUUYZ8rZEtt%2ftg4CTw%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c48ae315-f580-4b6c-801e-58a0f885749d/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c48ae315-f580-4b6c-801e-58a0f885749d?P1=1786461611&P2=404&P3=2&P4=GA41HSQwQ1BgmDXKHOgueK1PP3fJygqNGVc3kQ83V0lMrucPKc9PEk7xJeRQiVpy6UhHZ3G6Y7D5jm2gLKN75w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://c.pki.goog/r/gsr1.crl
- http://c.pki.goog/r/r4.crl
- http://c.pki.goog/we1/_-4iFwfCacM.crl
Embedded domains
- openssl.org
- index.crates.io
- destcloudflare-dns.com
- cloudflare-dns.com
- your-server.com
- nvidia.com
- github.com
- docs.rs
Embedded IP addresses
- 8.8.8.8
- 20.19.18.17
- 16.15.14.13
- 51.105.71.136
- 52.230.60.54
- 57.154.63.210
- 4.230.171.124
- 74.178.76.128
- 4.150.223.99
- 20.165.94.54
- 4.150.223.110
- 52.123.252.244
- 135.233.45.222
- 52.123.252.238
- 74.178.232.29
- 203.26.79.13
- 4.150.223.107
- 20.42.65.93
- 52.110.12.8
- 52.110.12.5
- 135.233.45.221
- 72.153.5.131
- 172.170.180.133
- 4.150.223.96
- 92.223.78.30
File paths
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\cipher-0.4.4\src\stream_core.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\future\try_join.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\http-body-util-0.1.3\src\combinators\collect.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-tungstenite-0.23.1\src\handshake.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\serde_json-1.0.149\src\de.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tungstenite-0.23.0\src\buffer.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tungstenite-0.23.0\src\handshake\machine.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-tungstenite-0.23.1\src\lib.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\regex-automata-0.4.14\src\util\pool.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-tungstenite-0.23.1\src\tls.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-tungstenite-0.23.1\src\connect.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\xz2-0.1.7\src\write.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\zip-2.4.2\src\zipcrypto.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\bzip2-0.5.2\src\write.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\image-0.25.10\src\imageops\sample.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\io\util\read_to_end.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\io\util\vec_with_initialized.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\sync\mpsc\unbounded.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\sync\mutex.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\lib.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\future\maybe_done.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\tokio-1.51.0\src\process\mod.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\flate2-1.1.9\src\zio.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\base64-0.22.1\src\engine\mod.rs
- C:\Users\funt\.cargo\registry\src\index.crates.io-1949cf8c6b5b557f\winnow-0.7.15\src\parser.rs
More AsyncRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report