{"id":"11767ecb9deb6b80bf781e6f47b859d5","title":"AsyncRAT/xClient — AsyncRAT/xClient · 木马/恶意软件 · PE32 .NET","md5":"11767ecb9deb6b80bf781e6f47b859d5","sha256":"c0cd9c51c4fc4f7805d5d2e5e08e3701c2214ab9ee25a239b2ab3c7af0c8e797","family":"AsyncRAT/xClient","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C#","file_format":"PE32 .NET","compiler":"VB.NET (ByteGuard)","published_at":"2020-02-24T16:00:00.000Z","summary":"该样本是一个全功能远程访问木马 (RAT)，基于 .NET Framework 4.0 编译，使用 ByteGuard 混淆器保护。 内部命名空间 xClient.Core.Packets.ServerPackets 表明其为 AsyncRAT / xClient 家族变种。 核心能力 (从字符串分析提取): 键盘记录 (KeyListener)、屏幕监控 (屏幕/摄像头4处)、 浏览器窃取 (Chrome/Firefox/Opera, Cookie/Password共33处)、 主机管理 (hostsManager, disabledHosts)、 持久化 (install/startup共26处)、 密码窃取 (password共20处)、 加密通信 (Rfc2898DeriveBytes = PBKDF2)。 C2配置通过PBKDF2加密存储，端口线索: 20114, 35138。","url":"https://zseceye.com/report/11767ecb9deb6b80bf781e6f47b859d5","json_url":"https://zseceye.com/report/11767ecb9deb6b80bf781e6f47b859d5.json","html_url":"https://zseceye.com/report/11767ecb9deb6b80bf781e6f47b859d5","hash_urls":{"md5":"https://zseceye.com/hash/11767ecb9deb6b80bf781e6f47b859d5","sha256":"https://zseceye.com/hash/c0cd9c51c4fc4f7805d5d2e5e08e3701c2214ab9ee25a239b2ab3c7af0c8e797"},"search_urls":{"md5":"https://zseceye.com/?q=11767ecb9deb6b80bf781e6f47b859d5","sha256":"https://zseceye.com/?q=c0cd9c51c4fc4f7805d5d2e5e08e3701c2214ab9ee25a239b2ab3c7af0c8e797"},"sample_download_url":"https://zseceye.com/report/11767ecb9deb6b80bf781e6f47b859d5/sample","sample_filename":"c0cd9c51.zip","iocs":[],"ips":[]}