Summary | ZeroBOX

6606.exe

AsyncRAT .NET framework(MSIL) UPX Malicious Packer PE File OS Processor Check PE32 .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 6, 2023, 7:41 a.m. Sept. 6, 2023, 7:46 a.m.
Size 66.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 8e17227d496580ab3015b0196442e49f
SHA256 b54e02001dee93fe19986fb1fd3a1dbc5a69b1144c00100448dac0db0786a381
CRC32 F1445D4B
ssdeep 1536:BmfWSqHdykrVMKuJUYFu3mG+JPbJ5dugLNTrQTGhx:BmeSqHdykGKuJUYFuWG+JPbJegRTGSx
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult
  • AsyncRat - AsyncRat Payload
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
84.54.50.9 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 84.54.50.9
Lionic Trojan.Win32.ClipBanker.Z!c
MicroWorld-eScan IL:Trojan.MSILZilla.24027
CAT-QuickHeal Trojan.Malgent.S30658607
McAfee GenericRXOW-GX!8E17227D4965
Malwarebytes Backdoor.AsyncRAT
Sangfor Trojan.Win32.Save.a
Alibaba Backdoor:MSIL/AsyncRat.98e7007f
Cybereason malicious.d49658
Arcabit IL:Trojan.MSILZilla.D5DDB
VirIT Trojan.Win32.MSIL_Heur.B
Cyren W32/Samas.B.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic Windows.Trojan.Asyncrat
ESET-NOD32 a variant of MSIL/Agent.CFQ
Cynet Malicious (score: 100)
APEX Malicious
ClamAV Win.Packed.Razy-9625918-0
Kaspersky HEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefender IL:Trojan.MSILZilla.24027
Avast Win32:DropperX-gen [Drp]
Tencent Malware.Win32.Gencirc.13eaa719
Emsisoft IL:Trojan.MSILZilla.24027 (B)
F-Secure Trojan.TR/Dropper.Gen
DrWeb BackDoor.AsyncRATNET.2
VIPRE IL:Trojan.MSILZilla.24027
TrendMicro Backdoor.Win32.ASYNCRAT.YXDFVZ
McAfee-GW-Edition BehavesLike.Win32.Fareit.km
FireEye Generic.mg.8e17227d496580ab
Sophos Troj/AsyncRat-B
SentinelOne Static AI - Malicious PE
Jiangmin Trojan.Banker.MSIL.hnw
Avira TR/Dropper.Gen
MAX malware (ai score=88)
Antiy-AVL Trojan[Banker]/MSIL.ClipBanker
Microsoft Backdoor:MSIL/AsyncRat.AD!MTB
ViRobot Trojan.Win.Z.Asyncrat.67584.N
ZoneAlarm HEUR:Trojan-Banker.MSIL.ClipBanker.gen
GData IL:Trojan.MSILZilla.24027
Google Detected
AhnLab-V3 Malware/Win.Generic.C4980844
BitDefenderTheta Gen:NN.ZemsilF.36662.em0@aOf4Utg
ALYac IL:Trojan.MSILZilla.24027
VBA32 OScope.Backdoor.MSIL.Crysan
Cylance unsafe
Panda Trj/GdSda.A
TrendMicro-HouseCall Backdoor.Win32.ASYNCRAT.YXDFVZ
Rising Trojan.AntiVM!1.CF63 (CLASSIC)
Ikarus Trojan.MSIL.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.CFQ!tr
dead_host 192.168.56.101:49163
dead_host 84.54.50.9:6606