Remote Access Trojan
VenomRAT - ClientAny.exe
- Author
- Moise Medici
- Updated
- 15 Nov 2025 · Completed
- Difficulty
- Easy
- Platform
- Capabilities
- Tags
Basic Static Analysis
To answer these questions, a common starting point is to load the file in pestudio and use FLOSS to check the strings.
From pestudio, in the summary tab, it is possible to retrieve all the information listed in the “File Info” section above. Two pieces of information are worth noting:
- The original file name is
ClientAny.exe(see summary > names > version > original-file-name). - The language detected is C# (see summary > file > signature | tooling), which can significantly change how the analysis proceeds. This is because executables written with the .NET framework can have their source code easily read with tools like DnSpy. The only downside is that it is necessary to be at least a little bit familiar with the programming language to understand what is going on. Given this constraint, the analysis will continue with a standard static/dynamic approach and then move to full code analysis.
Also note that under indicators > .NET > module > name, the name of the project is Monotone, which is what is expected to appear in DnSpy.
Continuing with pestudio, in the imports section pestudio recognizes 1103 imports, and looking in the libraries section the majority of them appear to come from mscoree.dll, which is the main DLL used by the .NET framework. To get an idea of other functionalities of the sample, it is useful to see which other calls are imported from the other three libraries (user32.dll, kernel32.dll, ntdll.dll).
From the import table it is possible to observe some potential interaction with the OS. Specifically:
- The combination of
CreateToolhelp32Snapshot,Process32FirstandProcess32Nextis used to enumerate the processes running in the system, often for code injection or anti-analysis, by stopping the execution if a specific tool is running. See Process Enumeration for more details. GetKeyState,GetWindowTextand the other calls that are related to the keyboard are often used for keylogging activities.
| Import | Library |
|---|---|
CloseHandle | kernel32.dll |
CreateToolhelp32Snapshot | kernel32.dll |
GetModuleHandle | kernel32.dll |
OpenProcess | kernel32.dll |
SetThreadExecutionState | kernel32.dll |
Process32Next | kernel32.dll |
Process32First | kernel32.dll |
TerminateProcess | kernel32.dll |
RtlSetProcessIsCritical | ntdll.dll |
CallNextHookEx | user32.dll |
GetKeyboardState | user32.dll |
GetKeyboardLayout | user32.dll |
GetKeyState | user32.dll |
GetForegroundWindow | user32.dll |
GetWindowText | user32.dll |
GetWindowThreadProcessId | user32.dll |
MapVirtualKey | user32.dll |
SetWindowsHookEx | user32.dll |
ToUnicodeEx | user32.dll |
UnhookWindowsHookEx | user32.dll |
As a final note on the imports section of pestudio, there are a few imports that have no library from which they were imported. These are probably the functions that are exposed by the C# code:
| Import | Class |
|---|---|
KeylogParams | Params |
CGRInfo | Client |
Keylogger | Client |
Program | Client |
Logger | Client |
Settings | Client |
ClientSocket | Client.Connection |
NormalStartup | Client.Install |
AntiProcess | Client.Helper |
PROCESSENTRY32 | Client.Helper |
Anti_Analysis | Client.Helper |
Camera | Client.Helper |
HwidGen | Client.Helper |
IdSender | Client.Helper |
Methods | Client.Helper |
DInvokeCore | Client.Helper |
Some of the names are very telling of what they do, which gives more confidence in answering the first three questions. However, before proceeding, the FLOSS output should be reviewed.
For FLOSS, the analysis starts by running it with -n 12 to get an approximate idea of what type of strings are visible, then it is run again without filters and the focus moves to parts of the output where something might have been missed. For example, below is a partial output of FLOSS with -n 12, with some of the most revealing strings from the FLOSS STATIC STRINGS: UTF-16LE section of the output. In the middle of the output there is a list of exe that the sample might be looking for. It is common to have executables with less than 12 characters in the name, hence FLOSS is then run without filters and that area is inspected to see if the list of executables is different.
DataLogs.confDataLogs_keylog_offline.txtDataLogs_keylog_online.txtSelect * from Win32_Processor{0} ({1} Core)NumberOfCoresSelect * From Win32_ComputerSystemTotalPhysicalMemoryselect * from Win32_VideoControllerDriverVersionSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\UninstallUninstallStringInstallLocationMM-dd HH:mm:ssC://Temp//1.logq8K37CrspQ1+t9ns7FUwBJCGCOq4t7gxvo9rhwzlqO2XAsRhaLRtPGnpX4MISpA25bZsLz5dCYognpQW5QPmEg==e+f8i10ZnXn8+EhS2bSotaWY9dpgmq+nW35Xcli0P3ddB5WKIWKl9G5HdopYTZXGH7J3UhLvkl8uENP4vL2OEg==yaXdv8wK79vHZXEtzmYJBhAtQmp/Gaf9nHVAVxGNOe3sERzkkM0w0UvIWfGMvDFZWy1VjdPRwabj/iyNDU4CVW2xTcxcVBROXWK9s0Mrfo3dg2xODghycSAyagfMUKVceKgYqOIL0Z/apslCcnl5Ra+kcNvvx7E18T8/5/4IpTbzeRZUGTHIwDZ/uR1asKVK/AMNIblodiLMc6L5fhqwbQ==V2xtNGFlR3I0SVZVMW43MHlPOFdET09HMGY1NFRxZTg=clQIFtQkc92phNMbP0ezjphWFVk9Jx5Z5G/WJNV/MKO9+eDjJagIODbZ+dU9QWnYXYB3wh2rNRGETdo9txeKhw==YTQUllDQFThgg8G/dO1jqrAgnbQDgi0qs7QDFtIpElBFT+JRYiPkAa56IVxz77/5JztuRuxsi+/u84JTHDqhZHmu4XiFlnMUUGVl7sbRzXL3Z5CnDCPj4qXwGv/88xr97JDIM64yOzqr66pin6ZypzoCBOHnR6WwnkDHpLJ10PjEDCU/HxUGhyCFZJ40LtdA5WZ1/JjVv7vY/h9Yjluftz8t98DqtS143hdgi8Aw9+JxPC4w5tK2DMvNC5rXkmxAVW9E3or6pWqZJf8uH8FbL8KmFVRKYxdsMVdXlIcV8YvIknpjO3L1DuyoHwvAzZ77XkKsbqEhB4wqBZlAH6Um7nvIFMXfuJIMRaD6GlaN1H8wuII3o/09bvIR8kTk4vTl+4CV8IuwbF4KzZ5CrraxsNSnO7M9C47/+p1PUgAm/pI6+0PKizRQ1s9MBoafLKQkryLb49b1JnCJX99G4ipe5KYuvO56FLMZpWfOSeOiG+K0HkG7pHJYPSJj9OSn9yRfePkmZz0y4uUrMbRj4Vl+/oUJ8Gdl4TqCLTAYaxlr0LoEQlJxhYpIv5iaIszuBgNJY2vLE9Rjm7R5i8gMS/FS6npbbMkIwHIAH4pH4fZXmTnXCo+iAAN9OXnftw2netuVjUFz+dGH8j9H0sR/ifdb4wdTIvK09etBVlj7pyVu4r0LDPbHUvxQiYNCGxhuP6IrTTXhh+XAKsmyVgoQH/kc67bkkJDB2AwsArSZIYJ3BR0rr0Qa6T0skh2v6d6NZIx9uNfSqKLsDCQr4u0m3omt1YOI9CbaD5hpWzGEJq0CaYkO4PsC+zLzfUxleMPWWxSOEdLru0zmElpOe7HgUFM17Nw+PY1XRHvK42GdPI3gBlxntV6LBtFiBYPDGccoPzgD8EEU7+ne487UVAZJAm+OBe+dPeHwO5BZBAXu7m2SKaG8dFkyDWP2lWCgBh7SOqfIOEaUeSI13akt+otg7H0xOhBjw/HSlPs8k9waR/6HHDDj1dLatr8NSfW0FAJi566WGWgOrA3+BDHvfcn+0yM+AA7+6RCa62RGXddtFIE5vVfGMwWUYKFyhYzO4P9eo31hZ6TvZutmHCIt77GBgYsTqLG5HOyGeCgnIenjHFDfAJzF8sV4Yt+E/5Ruk8w84iTkrcS89a9bzl1/QqWD8fEfEgikXBSv4GW9d7rfAyERrjGTrdLqcWF2SUrZEaD8aTJHyleVHfel74gzasxF/cUr3A2u69pdbTo3hEFNvp5u4PbD+ZaUi4wa5lHhwBspFr+JCHc//2h85zX6Kd4oeRyjdNdhl7hk5wXNZYBPQ9xIcbSUU52+lQAvAjfmweZolI2UZkMBS0UunGKcW+RmU5+biSI0bhxQ6ZsPz7hv1CBBCW4=j367jkqRZoI4mUxxGQT2wH5xnFZE1VY5eKqC3h+XVaz5qBNg3Cpsu0e/MtZgRrYXvosL5Tiu0UYlH8Uca3RZiPH/eIxfxWQg2tZE7pY8lt8=Hx34l1q8r1By6bbGYxXsp8F5XA6TzjrWDgt9sbQ9JbYnUO+cgLCgsRHCkFF3JKX10NWLah0zXTO/FSDDjMtSvA==SoFEfX0M/TfZMNduUyuYiYyk58KnTIgSLdu5oEYD7vftpWwUYUbdVWx2dwjrPWB8CWr2duhBYqVqyqRxVJwD0w==RurwXO7i4a91c1daSLyv5axbUwxAVu+GKOYBcv85v6yLRtfLPUxOUuNF8cz9Y1UW+MEnFIoe9BSLLaHNJyW4zA==WOaq/Out8IEaCfHETOVUryn8zg98gQ2F+Wm9HWug/5Rb26VfM0fY3uG1Fdty09aBDCsF1SSTEP3Obd5uClmEpg==loadofflinelogkeylogsettingOfflineKeylog sending....Plugin.PluginUmVjZWl2ZWQ=/c schtasks /create /f /sc onlogon /rl highest /tn "SOFTWARE\Microsoft\Windows\CurrentVersion\Run\timeout 3 > NULInstall Failed :ProcessHacker.exeMpCmdRun.exeConfigSecurityPolicy.exeMSConfig.exeUserAccountControlSettings.exetaskkill.exe\{0}\root\CIMV2SELECT * FROM Win32_OperatingSystemSelect * from Win32_CacheMemory{860BB310-5D01-11d0-BD3B-00A0C911CE86}{62BE5D10-60EB-11d0-BD3B-00A0C911CE86}{55272A00-42CB-11CE-8135-00AA004BB851}FriendlyNamePerfor_manceC:\Temp\client.logC:\Temp\client_ex.log\root\SecurityCenter2Select * from AntivirusProduct, Dll was not found or not loaded.Failed to parse module exports., export not found.Could not get the handle for the function.NtProtectVirtualMemoryYW1zaS5kbGw=AmsiScanBufferEtwEventWritemasterKey can not be null or empty.input can not be null.Invalid message authentication code (MAC).VenomRATByVenom(never used) type $c1(ext8,ext16,ex32) type $c7,$c8,$c9OfflineKeyloggerThere is a large variety of information, including:
-
files that might be written:
DataLogs.conf,DataLogs_keylog_offline.txt,DataLogs_keylog_online.txt,C://Temp//1.log
-
queries executed in Windows, maybe via
wmicto scan the system:Select * from Win32_Processor,Select * From Win32_ComputerSystem,select * from Win32_VideoController,SELECT * FROM Win32_OperatingSystem,Select * from Win32_CacheMemory,Select * from AntivirusProduct
-
mentions of the
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\registry key, used as a persistence mechanism to execute something at startup. -
encrypted and base64 encoded strings
-
a list of executables, some of which are not present in the snip above as they are less than 12 characters long, which are probably tools that the sample looks for during the anti-analysis assessment:
Taskmgr.exeProcessHacker.exeprocexp.exeMSASCui.exeMsMpEng.exeMpUXSrv.exeMpCmdRun.exeNisSrv.exeConfigSecurityPolicy.exeMSConfig.exeRegedit.exeUserAccountControlSettings.exetaskkill.exe
-
DOS command execution like:
/c schtasks /create /f /sc onlogon /rl highest /tnwhich creates a new task in the task scheduler.timeout 3 > NUL START "" " DEL " " /f /qwhich is probably going to delete itself or the original sample.
-
most telling of all:
VenomRATByVenom, which literally reveals that this is a VenomRAT sample, a remote access trojan.
At this point, it is possible to answer the first three questions:
The next part of the analysis will be performed both dynamically, by executing the sample and observing as much of the malware behaviour as possible, and statically, with a full code analysis. The two techniques will then be combined to answer any open questions that come up during each analysis. At the end, the malware will probably be run again in dnSpy to get some of the information that is not as easy to retrieve otherwise.
In a real scenario, the chosen approach will mostly depend on skills and requirements. If the goal is to collect IOCs from this sample, it is often sufficient to execute the malware and trace the behaviour. If the objective is to understand all the details around the sample and there is some familiarity with the programming language, opening the sample with dnSpy and looking directly at the code is more informative.