Analyzing a a Multi-Stage AsyncRAT Campaign via Managed Detection and Response
ID: 1d8b4171-d205-595e-bd33-a27b8e6f3206
STIX ID: report--1d8b4171-d205-595e-bd33-a27b8e6f3206
Feed Name: TrendAI Security Blog
This report analyzes a multi-stage AsyncRAT campaign that begins with phishing emails delivering a double-extension Internet Shortcut (*.pdf.url) which redirects to TryCloudflare WebDAV hosts; attackers download and install an embedded Python environment, execute staged scripts and batch files (as.wsh, anc.wsf, vio.bat, xeno.bat), establish persistence via startup batch files (ahke.bat, olsm.bat), and perform polymorphic APC code injection into explorer.exe using ne.py and new.bin (Donut-generated shellcode) to deploy AsyncRAT, while abusing Cloudflare free-tier infrastructure to evade detection and providing numerous IOCs and hunting queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
