Dosya
| SHA256 | aef327fcbd792f763f374dea26310f6349b71d772907f4166325682266d07127 |
|---|---|
| MD5 | 64fdbb65095866449dba3beae53f0065 |
| Dosya | aef327fcbd792f763f374dea26310f6349b71d772907f4166325682266d07127.ps1 |
| Boyut | 231,199 byte |
| Tür | ASCII text, with very long lines (65398), with CRLF line terminators |
| Stringler | 194 |
IOC
| SHA256 | aef327fcbd792f763f374dea26310f6349b71d772907f4166325682266d07127 |
|---|---|
| MD5 | 64fdbb65095866449dba3beae53f0065 |
| Domain | system.io |
| BTC | 1Qs3rs4H1pXCBXr7GLtcr7LHGt, 1T4HsBJmGGFbcdS2TxtCbyGi1WB, 3scfQWQjbRqXW91KQeD8zPp42cp9XNy7m, 3urHaXUwgtPUAiQtgygfsVLrGFDsH65nCNJ, 35VEM4RWzGhodNmkWqBkPb8FnHM4Vdc2PH |
| C2 | system.io |
AsyncRAT — Malware Profile
AsyncRAT, 2019'da acik kaynak olarak yayimlanan C# tabanli RAT ailesidir. Ekran yakalama, keylogger, dosya islemleri, HVNC ve plugin sistemine sahiptir. C2 AES-128-CBC ile sifrelenir, TCP uzerinden calisir. JS/PDF yemi ile dagitilir.
Technical Details
C# .NET, AES-128-CBC sifreleme, TCP port 6606/4449 (varsayilan), Mutex kontrol, Runtime assembly loading, Anti-analysis (VM check, Process listesi), HVNC, Keylogger, Stealer, Botnet modulu
Attribution / Threat Actor
Acik kaynak - orjinal gelistirici GitHub'da yayinladi; surekli siber suclu toplulugu tarafindan kullanilmaktadir. APT operasyonlari da dahil olmak uzere cok sayida farkli tehdit aktoru kullanmaktadir.
Capabilities & Behavior
IOC List (6 indicators)
#
1Qs3rs4H1pXCBXr7GLtcr7LHGt
#
1T4HsBJmGGFbcdS2TxtCbyGi1WB
#
3scfQWQjbRqXW91KQeD8zPp42cp9XNy7m
#
3urHaXUwgtPUAiQtgygfsVLrGFDsH65nCNJ
#
35VEM4RWzGhodNmkWqBkPb8FnHM4Vdc2PH
# DOMAIN
system.io
| Type | Value | Note |
|---|---|---|
| 1Qs3rs4H1pXCBXr7GLtcr7LHGt | BTC | |
| 1T4HsBJmGGFbcdS2TxtCbyGi1WB | BTC | |
| 3scfQWQjbRqXW91KQeD8zPp42cp9XNy7m | BTC | |
| 3urHaXUwgtPUAiQtgygfsVLrGFDsH65nCNJ | BTC | |
| 35VEM4RWzGhodNmkWqBkPb8FnHM4Vdc2PH | BTC | |
| domain | system.io | C2 domain |
C2 Servers (8 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| microsoft.com | domain | — | TCP | active | — |
| microsoft.com | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| microsoft.com | domain | — | TCP | active | — |
| microsoft.com | domain | — | TCP | active | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.