{"id":"29d0ca716e7ba7bfdb279053351225d6","title":"AsyncRAT — AsyncRAT · 远程访问木马(RAT) · PE32","md5":"29d0ca716e7ba7bfdb279053351225d6","sha256":"418a07ebd7c417bb91e8ca0cbd5cc4ca89697104ce0e5480d9ed09b100463e5e","family":"AsyncRAT","apt":null,"verdict":null,"sample_type":"远程访问木马(RAT)","lang":"C#","file_format":"PE32","compiler":".NET","published_at":"2026-08-10T16:00:00.000Z","summary":"该样本为 VB.NET 编译的 AsyncRAT（xClient 分支）远程访问木马客户端。证据：① MsgPack 序列化（AsyncRAT 标志性 C2 协议）+ Plugin.Plugin 插件系统；② %Serversignature% / %Certificate% / %MTX% 构建器占位符（AsyncRAT 构建器特有）；③ C2 域名 new88.ooo（.ooo TLD）；④ 持久化：schtasks /create /sc onlogon /rl highest + Run 注册表键（反序存储 Software\\Microsoft\\Windows\\CurrentVersion\\Run）；⑤ 自删除批处理（@echo off + DEL /f /q）；⑥ WMI 反虚拟机（Win32_ComputerSystem 检测 VIRTUAL/vmware/VirtualBox/SbieDll）与反杀软（SecurityCenter2 枚举 AntivirusProduct）；⑦ Pastebin 备用 C2；⑧ HMAC 加密（masterKey/MAC 校验）。","url":"https://zseceye.com/report/29d0ca716e7ba7bfdb279053351225d6","json_url":"https://zseceye.com/report/29d0ca716e7ba7bfdb279053351225d6.json","html_url":"https://zseceye.com/report/29d0ca716e7ba7bfdb279053351225d6","hash_urls":{"md5":"https://zseceye.com/hash/29d0ca716e7ba7bfdb279053351225d6","sha256":"https://zseceye.com/hash/418a07ebd7c417bb91e8ca0cbd5cc4ca89697104ce0e5480d9ed09b100463e5e"},"search_urls":{"md5":"https://zseceye.com/?q=29d0ca716e7ba7bfdb279053351225d6","sha256":"https://zseceye.com/?q=418a07ebd7c417bb91e8ca0cbd5cc4ca89697104ce0e5480d9ed09b100463e5e"},"sample_download_url":"https://zseceye.com/report/29d0ca716e7ba7bfdb279053351225d6/sample","sample_filename":"418a07eb.zip","iocs":[],"ips":[]}