MALICIOUS — dfea615110f480d5ff695d936be2c19bcb4fc7da3ca602881e378b1269b57310
MALICIOUS — dfea615110f480d5ff695d936be2c19bcb4fc7da3ca602881e378b1269b57310 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the AsyncRAT family. 10 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
dfea615110f480d5ff695d936be2c19bcb4fc7da3ca602881e378b1269b57310 - SHA-1:
00f08ee35da4ebc89e85a774237258735d0ef79e - MD5:
134f0b88befcae3405e10ba5388abcd3 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:99+6Wur8YL6hD2x/HAWbR2zS4si0O1A83u2BSDoCqKcvDu+A:99+6Wurp6uHAW92zt/0Wu2BSMCqD - TLSH:
T18F4EE1CF10293716C93BDB222F4D96DE54E3A886AFB57B1D0E004A7230646778C7536A - Submitted as: dfea615110f480d5ff695d936be2c19bcb4fc7da3ca602881e378b1269b57310
- File type: pe · Size: 676352 bytes
- Verdict: malicious (98/100) · Family: AsyncRAT
Detections (10 of 52 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Packed.AsyncRAT-9938103-1
- YARA: PhishingKit (t4d): PK_Credential_Exfil_Telegram
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: MalwareAnalyser community pack: TL_Ransomware_Note_Markers
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: PWS:MSIL/StormKitty.GA!MTB
- Emsisoft (Emergency Kit): Dump:Generic.DataStealer.1.F6EAB974
- Kaspersky (KVRT): HEUR:Trojan-Banker.MSIL.ClipBanker.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Win.Packed.AsyncRAT-9938103-1 (rule
Win.Packed.AsyncRAT-9938103-1) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: PhishingKit (t4d) flagged PK_Credential_Exfil_Telegram (rule
PK_Credential_Exfil_Telegram) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.35, confidence 0.70 - YARA: MalwareAnalyser community pack flagged TL_Ransomware_Note_Markers (rule
TL_Ransomware_Note_Markers) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://api.telegram.org/bot - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://github.com/LimerBoy/StormKitty
- https://api.telegram.org/bot
- https://google.com/
Embedded domains
- github.com
- api.telegram.org
- battle.net
- nicehash.com
- yobit.net
- electroneum.com
- freewallet.org
- backit.me
- letyshop.com
- exmo.me
- blockchain.info
- onlinesim.ru
- sms-acktiwator.ru
- vsms-reg.com
- sms-activate.ru
- smska.net
- 5sim.net
- cryptonator.com
- bittrex.com
- aliexpress.ru
- viabtc.com
- kryptex.org
- exploit.in
- payeer.com
- antiscan.me
More AsyncRAT samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report