Try VMRay Platform
Malicious
Classifications

Backdoor Injector Downloader

Threat Names

AsyncRAT DnlibLoader Mal/HTMLGen-A

Remarks (2/2)

(0x00600018): Static Analysis failed to analyze the sample due to an error. Check the sample_static_analysis.log file for further information.

(0x02000050): This analysis has been updated with the latest reputation and static analysis results from the original analysis with the ID #17994119.

VMRay Threat Identifiers (13 rules, 23 matches)

ScoreCategoryOperationCountClassification
5/5
YARAMalicious content matched by YARA rules4Backdoor, Downloader
4/5
ObfuscationReads from memory of another process2-
4/5
Defense EvasionTries to detect the presence of antivirus software1-
4/5
InjectionWrites into the memory of another process1Injector
4/5
ReputationMalicious host or URL detected via reputation1-
3/5
Privilege EscalationEnables process privileges1-
3/5
Defense EvasionBypasses PowerShell execution policy2-
2/5
DiscoveryQueries OS version via WMI1-
2/5
Network ConnectionPerforms DNS request3-
2/5
Network ConnectionTries to connect using an uncommon port1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Windows Management Instrumentation
Command-Line Interface
Persistence
Privilege Escalation
Access Token Manipulation
Defense Evasion
Access Token Manipulation
Credential Access
Discovery
Security Software Discovery
System Information Discovery
Process Discovery
Lateral Movement
Collection
Command and Control
Uncommonly Used Port
Exfiltration
Impact

Sample Information

ID#8120929
MD5
ae498935d8a61b3008bd9393a2306dec
SHA1
b1858655d705e14c01cec8d008c3f3db0a09807b
SHA256
401f183d5553d4f01ff3a4df33524f39faa6138f40afb570300ae41ca31efc08
SSDeep
3072:0F8F8F8F8F8F8F8F8F8F8F8F8F8FjFoFoFoFoFoFoFoFoFoFoFoFoFoFoFoFoFod:X7HlvYPobr777lvrFI
File NameLana_Rhoades_Photoos.js
File Size548.33 KB
Sample TypeJScript

Analysis Information

Creation Time2024-10-28 02:10 (UTC+)
Analysis Duration00:04:00
Termination ReasonTimeout
Number of Monitored Processes5
Execution Successful
Reputation Enabled
Built-in AV Enabled
Number of AV Matches0
YARA Enabled
Number of YARA Matches5
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image