MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26c61dbe68fb66f49e4555e54a734de168bcea27b4ac70c6ffbd27fe92efd9ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 26c61dbe68fb66f49e4555e54a734de168bcea27b4ac70c6ffbd27fe92efd9ba
SHA3-384 hash: 170d5cd54c88f51e2428cbc294bce0fd3745ac3f565f21849354802809f66f8ac07de5e6f27f1eca6cd998cf08648a34
SHA1 hash: 11fae8e3248df1f80a0c2ca11cf7e335d6914e78
MD5 hash: 7f7492ba7f6ceda3c1ae3c369858c724
humanhash: fanta-zebra-quiet-maryland
File name:AWB5305323204638,pdf.iso
Download: download sample
Signature AsyncRAT
File size:266'240 bytes
First seen:2020-05-11 09:03:50 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:McagIqfC1k3cwaX0ilMExlFE5aS/X0lOLH9q2xAQ:HIqfC1k3cwaX0iltlbpQ
TLSH 2744081036AC573AE8F99BF52D689052C3B2785A7894F7AD6CD654CA03E4F40CD60F2B
Reporter abuse_ch
Tags:AsyncRAT FedEx iso nVpn RAT


Avatar
abuse_ch
Malspam distributing AsyncRAT:

HELO: [193.56.28.18]
Sending IP: 193.56.28.18
From: FedEx <track@fedex.com>
Subject: FedEx's AWB#5305323204638 - Information is required
Attachment: AWB5305323204638,pdf.iso (contains "AWB#5305323204638,pdf.exe")

AsyncRAT C2:
185.244.29.129:9980

Hosted on nVpn:

% Information related to '185.244.29.0 - 185.244.29.255'

% Abuse contact for '185.244.29.0 - 185.244.29.255' is 'abuse@gerber-edv.net'

inetnum: 185.244.29.0 - 185.244.29.255
netname: GERBER-NETWORK
descr: Wonsan, Kangwon-do
descr: Choson Minjujuui Inmin Konghwaguk
country: KP
admin-c: GN5022-RIPE
tech-c: GN5022-RIPE
org: ORG-GN148-RIPE
status: SUB-ALLOCATED PA
mnt-by: GERBER-MNT
created: 2018-01-31T19:41:57Z
last-modified: 2020-04-06T22:16:40Z
source: RIPE


Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Geniso
Status:
Malicious
First seen:
2020-05-11 09:36:21 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

iso 26c61dbe68fb66f49e4555e54a734de168bcea27b4ac70c6ffbd27fe92efd9ba

(this sample)

  
Dropping
AsyncRAT
  
Delivery method
Distributed via e-mail attachment

Comments