Report - Stgedo.exe

AsyncRAT backdoor
ScreenShot
Created 2021.03.17 18:31 Machine s1_win7_x3201
Filename Stgedo.exe
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
AI Score
9
Behavior Score
3.2
ZERO API file : clean
VT API (file) 28 detected (malicious, high confidence, Save, confidence, Attribute, HighConfidence, RATX, Static AI, Malicious PE, opquo, Unsafe, Score, Wacapew, MGA5D0, R002H0CCB21, ZemsilF, bm0@a0syq4mi, HgIASQYA)
md5 4fa1dbfe022061e6699ae4754b45cb4f
sha256 2d8a94aa729c023228778bd3db76aec6ec015598c8a7e9f79d87b20e2a1c3c3e
ssdeep 384:5SZm9Hroe51UZgDUeUKQ4rkHi4vHtMc/TnXnJ+IkPsLI8uKS/fJXLgTK:5SZm9LENvHFDXJA0gXJ7
imphash f34d5f2d4577ed6d9ceec516c1f5a744
impfuzzy 3:rGsLdAIEK:tf
  Network IP location

Signature (9cnts)

Level Description
warning File has been identified by 28 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Moves the original executable to a new location
notice Performs some HTTP requests
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Queries for the computername
info Uses Windows APIs to generate a cryptographic key

Rules (5cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info IsNET_EXE (no description) binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info Win_Backdoor_AsyncRAT_Zero Win Backdoor AsyncRAT binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://192.168.56.103:2869/upnphost/udhisapi.dll?content=uuid:2d284ad3-5648-4376-8360-b0559e35418f Unknown 192.168.56.103 clean
http://192.168.56.103:5357/da8ea474-550f-433d-b444-54d2081d1d24/ Unknown 192.168.56.103 clean
http://liverpoolofcfanclub.com/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-D9F79B55F8D4D9EC712336B52F5A918A.html US CLOUDFLARENET 172.67.174.240 361 mailcious
liverpoolofcfanclub.com US CLOUDFLARENET 104.21.31.39 mailcious
172.67.174.240 US CLOUDFLARENET 172.67.174.240 clean

Suricata ids

PE API

IAT(Import Address Table) Library

mscoree.dll
 0x402000 _CorExeMain

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure