MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40b5b8c546d9a03fcdb1f4815c41b5c5335afa4195a61cdce7b14b4cc7bfb918. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 40b5b8c546d9a03fcdb1f4815c41b5c5335afa4195a61cdce7b14b4cc7bfb918
SHA3-384 hash: 4280c0b86f295de709bbf2cfb6db10d4e21e45be4e88f5ac0162f9d25318b1fa87a6749c489133ed54ec3e84eb576ad6
SHA1 hash: 31de2cbc3890bb404aef162e120655d1e1a86d1a
MD5 hash: 42383b9b89a8091519c4a7103395fe6f
humanhash: mexico-indigo-carolina-mexico
File name:Scan_Doc.z
Download: download sample
Signature AsyncRAT
File size:120'492 bytes
First seen:2020-06-26 07:53:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:ogb72wWGrRdVzcYP7iCeVoUuU9/5WH2KhYgm:oM5RdVzcbCeV8EFKVm
TLSH 43C3123BD097A176E40541923C663E3DCF8139EDBE14D7801EA7E7AC890738B467CA96
Reporter abuse_ch
Tags:AsyncRAT DHL nVpn RAT z


Avatar
abuse_ch
Malspam distributing AsyncRAT:

HELO: 120.ip-51-79-161.net
Sending IP: 51.79.161.120
From: DHL Express | Shipping, Tracking and Courier Delivery Services <support@preinscription.lyceedesmascareignes.org>
Subject: Your Parcel just arrived
Attachment: Scan_Doc.z (contains "Scan_Doc.exe")

AsyncRAT C2:
nmaxom.duckdns.org:8301 (79.134.225.19)

Pointing to nVpn:

% Information related to '79.134.225.0 - 79.134.225.63'

% Abuse contact for '79.134.225.0 - 79.134.225.63' is 'abuse@anmaxx.net'

inetnum: 79.134.225.0 - 79.134.225.63
netname: BASEL-HOSTING-225-0
country: CH
admin-c: AM38880-RIPE
tech-c: AM38880-RIPE
status: ASSIGNED PA
mnt-by: AF15-MNT
created: 2016-04-17T00:42:52Z
last-modified: 2016-04-18T06:23:19Z
source: RIPE
remarks: abuse-c AIS166-RIPE
org: ORG-AGIS12-RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 07:55:04 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

zip 40b5b8c546d9a03fcdb1f4815c41b5c5335afa4195a61cdce7b14b4cc7bfb918

(this sample)

  
Dropping
AsyncRAT
  
Delivery method
Distributed via e-mail attachment

Comments