Posts

Showing posts with the label #AsyncRAT #UAC0173

AsyncRAT in Action: UAC-0173’s Latest Advanced Antivirus Detection & Evasion Techniques

Image
  Summary UAC-0173 is a threat actor group known for targeting Ukrainian organizations with sophisticated malware campaigns. One of their preferred tools is  AsyncRAT . This report explores the antivirus detection and evasion techniques used by UAC-0173 in their AsyncRAT campaigns, providing insights into how defenders can detect. Abuse.ch's Malware Bazaar  is an excellent platform for sharing and analyzing malware samples. By contributing to the community, I’m helping to improve global cybersecurity defenses and I’ve uploaded the sample to share.     Technical analysis   Basic info The sample hashs: md5 e9cedc98677b6b5146b14009ced7d624 Sha1 1b6e14e578c613932496bfd49c616760bdceb2c1   Operation system: Windows (I386, 32-bit, EXEC] Packer: no     Deploy main abilities This client program, like other RATs, has its main abilities: checking VMs or sandboxes, killing processes, privilege escalation, and so on. The...