MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20e5756039499fe5a89eadf7e242d3b9f7a4bf774dc9ad6ba66bfc3b8ba30e8d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 20e5756039499fe5a89eadf7e242d3b9f7a4bf774dc9ad6ba66bfc3b8ba30e8d
SHA3-384 hash: b25a4f7adbe68fe4142f6d0533f6ba32cf3772b29344c8f24dc62122c4bc7064e030be82123ea94ca8d8dfb6c55469fa
SHA1 hash: 18475e2bb0b168b2809daa736c75b537df62bd30
MD5 hash: ce5c413a4b8ba102978f796fd14886d2
humanhash: ten-oranges-tango-october
File name:malwareDocument.pdf
Download: download sample
Signature AsyncRAT
File size:1'875'216 bytes
First seen:2024-02-15 13:11:04 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 49152:9FyfS5FHOf02jdH7AjlppDXQD8nBN/qp319dfck:9Fyfg5O8U7qlrz0Uk
TLSH T1089533D244AD6A60C41F3431E51AE1A4B5F5BD8E84E339E4285ABB4FD5EF11AE733C01
Reporter ankit_anubhav
Tags:AsyncRAT pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
564
Origin country :
TH TH
Vendor Threat Intelligence
Label:
Malicious
Suspicious Score:
7.3/10
Score Malicious:
73%
Score Benign:
27%
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.expl.evad
Score:
84 / 100
Signature
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Clickable URLs found in PDF pointing to potentially malicious files
Downloads suspicious files via Chrome
Encrypted powershell cmdline option found
Found suspicious ZIP file
Potential dropper URLs found in powershell memory
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Suspicious execution chain found
Suspicious powershell command line found
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1392854 Sample: malwareDocument.pdf Startdate: 15/02/2024 Architecture: WINDOWS Score: 84 65 Antivirus detection for URL or domain 2->65 67 Clickable URLs found in PDF pointing to potentially malicious files 2->67 69 Found suspicious ZIP file 2->69 71 3 other signatures 2->71 11 chrome.exe 23 2->11         started        15 Acrobat.exe 18 80 2->15         started        process3 dnsIp4 59 192.168.2.9, 138, 443, 49196 unknown unknown 11->59 61 239.255.255.250 unknown Reserved 11->61 51 C:\Users\user\...\Doc_Unlock.zip (copy), Zip 11->51 dropped 17 unarchiver.exe 4 11->17         started        19 chrome.exe 11->19         started        22 AcroCEF.exe 106 15->22         started        file5 process6 dnsIp7 24 cmd.exe 1 17->24         started        27 7za.exe 2 17->27         started        53 108.177.122.113, 443, 49743 GOOGLEUS United States 19->53 55 accounts.google.com 142.250.9.84, 443, 49724 GOOGLEUS United States 19->55 57 6 other IPs or domains 19->57 30 AcroCEF.exe 4 22->30         started        process8 dnsIp9 77 Suspicious powershell command line found 24->77 79 Encrypted powershell cmdline option found 24->79 81 Bypasses PowerShell execution policy 24->81 33 powershell.exe 12 24->33         started        35 conhost.exe 24->35         started        49 C:\Users\user\AppData\...\Doc_Unlock.bat, DOS 27->49 dropped 37 conhost.exe 27->37         started        63 23.54.200.159, 443, 49716 AKAMAI-ASUS United States 30->63 file10 signatures11 process12 process13 39 cmd.exe 1 33->39         started        signatures14 73 Suspicious powershell command line found 39->73 75 Encrypted powershell cmdline option found 39->75 42 powershell.exe 39->42         started        45 conhost.exe 39->45         started        process15 signatures16 83 Potential dropper URLs found in powershell memory 42->83 47 WmiPrvSE.exe 42->47         started        process17
Threat name:
Document.Trojan.Heuristic
Status:
Malicious
First seen:
2024-02-14 19:40:36 UTC
File Type:
Document
Extracted files:
5
AV detection:
3 of 38 (7.89%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments