← Reports

Remote Access Trojan

VenomRAT - ClientAny.exe

Author
Moise Medici
Updated
15 Nov 2025 · Completed
Difficulty
Easy
Platform
Windows
Capabilities
Persistence MechanismsCommand Execution via Powershell Cmd BashData-Exfiltration
Tags
C#VenomRAT

Basic Static Analysis

To answer these questions, a common starting point is to load the file in pestudio and use FLOSS to check the strings.
From pestudio, in the summary tab, it is possible to retrieve all the information listed in the “File Info” section above. Two pieces of information are worth noting:

  1. The original file name is ClientAny.exe (see summary > names > version > original-file-name).
  2. The language detected is C# (see summary > file > signature | tooling), which can significantly change how the analysis proceeds. This is because executables written with the .NET framework can have their source code easily read with tools like DnSpy. The only downside is that it is necessary to be at least a little bit familiar with the programming language to understand what is going on. Given this constraint, the analysis will continue with a standard static/dynamic approach and then move to full code analysis.

Also note that under indicators > .NET > module > name, the name of the project is Monotone, which is what is expected to appear in DnSpy.

Continuing with pestudio, in the imports section pestudio recognizes 1103 imports, and looking in the libraries section the majority of them appear to come from mscoree.dll, which is the main DLL used by the .NET framework. To get an idea of other functionalities of the sample, it is useful to see which other calls are imported from the other three libraries (user32.dll, kernel32.dll, ntdll.dll).

From the import table it is possible to observe some potential interaction with the OS. Specifically:

  • The combination of CreateToolhelp32Snapshot, Process32First and Process32Next is used to enumerate the processes running in the system, often for code injection or anti-analysis, by stopping the execution if a specific tool is running. See Process Enumeration for more details.
  • GetKeyState, GetWindowText and the other calls that are related to the keyboard are often used for keylogging activities.
ImportLibrary
CloseHandlekernel32.dll
CreateToolhelp32Snapshotkernel32.dll
GetModuleHandlekernel32.dll
OpenProcesskernel32.dll
SetThreadExecutionStatekernel32.dll
Process32Nextkernel32.dll
Process32Firstkernel32.dll
TerminateProcesskernel32.dll
RtlSetProcessIsCriticalntdll.dll
CallNextHookExuser32.dll
GetKeyboardStateuser32.dll
GetKeyboardLayoutuser32.dll
GetKeyStateuser32.dll
GetForegroundWindowuser32.dll
GetWindowTextuser32.dll
GetWindowThreadProcessIduser32.dll
MapVirtualKeyuser32.dll
SetWindowsHookExuser32.dll
ToUnicodeExuser32.dll
UnhookWindowsHookExuser32.dll

As a final note on the imports section of pestudio, there are a few imports that have no library from which they were imported. These are probably the functions that are exposed by the C# code:

ImportClass
KeylogParamsParams
CGRInfoClient
KeyloggerClient
ProgramClient
LoggerClient
SettingsClient
ClientSocketClient.Connection
NormalStartupClient.Install
AntiProcessClient.Helper
PROCESSENTRY32Client.Helper
Anti_AnalysisClient.Helper
CameraClient.Helper
HwidGenClient.Helper
IdSenderClient.Helper
MethodsClient.Helper
DInvokeCoreClient.Helper

Some of the names are very telling of what they do, which gives more confidence in answering the first three questions. However, before proceeding, the FLOSS output should be reviewed.

For FLOSS, the analysis starts by running it with -n 12 to get an approximate idea of what type of strings are visible, then it is run again without filters and the focus moves to parts of the output where something might have been missed. For example, below is a partial output of FLOSS with -n 12, with some of the most revealing strings from the FLOSS STATIC STRINGS: UTF-16LE section of the output. In the middle of the output there is a list of exe that the sample might be looking for. It is common to have executables with less than 12 characters in the name, hence FLOSS is then run without filters and that area is inspected to see if the list of executables is different.

DataLogs.conf
DataLogs_keylog_offline.txt
DataLogs_keylog_online.txt
Select * from Win32_Processor
{0} ({1} Core)
NumberOfCores
Select * From Win32_ComputerSystem
TotalPhysicalMemory
select * from Win32_VideoController
DriverVersion
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
UninstallString
InstallLocation
MM-dd HH:mm:ss
C://Temp//1.log
q8K37CrspQ1+t9ns7FUwBJCGCOq4t7gxvo9rhwzlqO2XAsRhaLRtPGnpX4MISpA25bZsLz5dCYognpQW5QPmEg==
e+f8i10ZnXn8+EhS2bSotaWY9dpgmq+nW35Xcli0P3ddB5WKIWKl9G5HdopYTZXGH7J3UhLvkl8uENP4vL2OEg==
yaXdv8wK79vHZXEtzmYJBhAtQmp/Gaf9nHVAVxGNOe3sERzkkM0w0UvIWfGMvDFZWy1VjdPRwabj/iyNDU4CVW2xTcxcVBROXWK9s0Mrfo3dg2xODghycSAyagfMUKVc
eKgYqOIL0Z/apslCcnl5Ra+kcNvvx7E18T8/5/4IpTbzeRZUGTHIwDZ/uR1asKVK/AMNIblodiLMc6L5fhqwbQ==
V2xtNGFlR3I0SVZVMW43MHlPOFdET09HMGY1NFRxZTg=
clQIFtQkc92phNMbP0ezjphWFVk9Jx5Z5G/WJNV/MKO9+eDjJagIODbZ+dU9QWnYXYB3wh2rNRGETdo9txeKhw==
YTQUllDQFThgg8G/dO1jqrAgnbQDgi0qs7QDFtIpElBFT+JRYiPkAa56IVxz77/5JztuRuxsi+/u84JTHDqhZHmu4XiFlnMUUGVl7sbRzXL3Z5CnDCPj4qXwGv/88xr97JDIM64yOzqr66pin6ZypzoCBOHnR6WwnkDHpLJ10PjEDCU/HxUGhyCFZJ40LtdA5WZ1/JjVv7vY/h9Yjluftz8t98DqtS143hdgi8Aw9+JxPC4w5tK2DMvNC5rXkmxAVW9E3or6pWqZJf8uH8FbL8KmFVRKYxdsMVdXlIcV8YvIknpjO3L1DuyoHwvAzZ77XkKsbqEhB4wqBZlAH6Um7nvIFMXfuJIMRaD6GlaN1H8wuII3o/09bvIR8kTk4vTl+4CV8IuwbF4KzZ5CrraxsNSnO7M9C47/+p1PUgAm/pI6+0PKizRQ1s9MBoafLKQkryLb49b1JnCJX99G4ipe5KYuvO56FLMZpWfOSeOiG+K0HkG7pHJYPSJj9OSn9yRfePkmZz0y4uUrMbRj4Vl+/oUJ8Gdl4TqCLTAYaxlr0LoEQlJxhYpIv5iaIszuBgNJY2vLE9Rjm7R5i8gMS/FS6npbbMkIwHIAH4pH4fZXmTnXCo+iAAN9OXnftw2netuVjUFz+dGH8j9H0sR/ifdb4wdTIvK09etBVlj7pyVu4r0LDPbHUvxQiYNCGxhuP6IrTTXhh+XAKsmyVgoQH/kc67bkkJDB2AwsArSZIYJ3BR0rr0Qa6T0skh2v6d6NZIx9uNfSqKLsDCQr4u0m3omt1YOI9CbaD5hpWzGEJq0CaYkO4PsC+zLzfUxleMPWWxSOEdLru0zmElpOe7HgUFM17Nw+PY1XRHvK42GdPI3gBlxntV6LBtFiBYPDGccoPzgD8EEU7+ne487UVAZJAm+OBe+dPeHwO5BZBAXu7m2SKaG8dFkyDWP2lWCgBh7SOqfIOEaUeSI13akt+otg7H0xOhBjw/HSlPs8k9waR/6HHDDj1dLatr8NSfW0FAJi566WGWgOrA3+BDHvfcn+0yM+AA7+6RCa62RGXddtFIE5vVfGMwWUYKFyhYzO4P9eo31h
Z6TvZutmHCIt77GBgYsTqLG5HOyGeCgnIenjHFDfAJzF8sV4Yt+E/5Ruk8w84iTkrcS89a9bzl1/QqWD8fEfEgikXBSv4GW9d7rfAyERrjGTrdLqcWF2SUrZEaD8aTJHyleVHfel74gzasxF/cUr3A2u69pdbTo3hEFNvp5u4PbD+ZaUi4wa5lHhwBspFr+JCHc//2h85zX6Kd4oeRyjdNdhl7hk5wXNZYBPQ9xIcbSUU52+lQAvAjfmweZolI2UZkMBS0UunGKcW+RmU5+biSI0bhxQ6ZsPz7hv1CBBCW4=
j367jkqRZoI4mUxxGQT2wH5xnFZE1VY5eKqC3h+XVaz5qBNg3Cpsu0e/MtZgRrYXvosL5Tiu0UYlH8Uca3RZiPH/eIxfxWQg2tZE7pY8lt8=
Hx34l1q8r1By6bbGYxXsp8F5XA6TzjrWDgt9sbQ9JbYnUO+cgLCgsRHCkFF3JKX10NWLah0zXTO/FSDDjMtSvA==
SoFEfX0M/TfZMNduUyuYiYyk58KnTIgSLdu5oEYD7vftpWwUYUbdVWx2dwjrPWB8CWr2duhBYqVqyqRxVJwD0w==
RurwXO7i4a91c1daSLyv5axbUwxAVu+GKOYBcv85v6yLRtfLPUxOUuNF8cz9Y1UW+MEnFIoe9BSLLaHNJyW4zA==
WOaq/Out8IEaCfHETOVUryn8zg98gQ2F+Wm9HWug/5Rb26VfM0fY3uG1Fdty09aBDCsF1SSTEP3Obd5uClmEpg==
loadofflinelog
keylogsetting
OfflineKeylog sending....
Plugin.Plugin
UmVjZWl2ZWQ=
/c schtasks /create /f /sc onlogon /rl highest /tn "
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
timeout 3 > NUL
Install Failed :
ProcessHacker.exe
MpCmdRun.exe
ConfigSecurityPolicy.exe
MSConfig.exe
UserAccountControlSettings.exe
taskkill.exe
\{0}\root\CIMV2
SELECT * FROM Win32_OperatingSystem
Select * from Win32_CacheMemory
{860BB310-5D01-11d0-BD3B-00A0C911CE86}
{62BE5D10-60EB-11d0-BD3B-00A0C911CE86}
{55272A00-42CB-11CE-8135-00AA004BB851}
FriendlyName
Perfor_mance
C:\Temp\client.log
C:\Temp\client_ex.log
\root\SecurityCenter2
Select * from AntivirusProduct
, Dll was not found or not loaded.
Failed to parse module exports.
, export not found.
Could not get the handle for the function.
NtProtectVirtualMemory
YW1zaS5kbGw=
AmsiScanBuffer
EtwEventWrite
masterKey can not be null or empty.
input can not be null.
Invalid message authentication code (MAC).
VenomRATByVenom
(never used) type $c1
(ext8,ext16,ex32) type $c7,$c8,$c9
OfflineKeylogger

There is a large variety of information, including:

  • files that might be written:

    • DataLogs.conf,
    • DataLogs_keylog_offline.txt,
    • DataLogs_keylog_online.txt,
    • C://Temp//1.log
  • queries executed in Windows, maybe via wmic to scan the system:

    • Select * from Win32_Processor,
    • Select * From Win32_ComputerSystem,
    • select * from Win32_VideoController,
    • SELECT * FROM Win32_OperatingSystem,
    • Select * from Win32_CacheMemory,
    • Select * from AntivirusProduct
  • mentions of the SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ registry key, used as a persistence mechanism to execute something at startup.

  • encrypted and base64 encoded strings

  • a list of executables, some of which are not present in the snip above as they are less than 12 characters long, which are probably tools that the sample looks for during the anti-analysis assessment:

    • Taskmgr.exe
    • ProcessHacker.exe
    • procexp.exe
    • MSASCui.exe
    • MsMpEng.exe
    • MpUXSrv.exe
    • MpCmdRun.exe
    • NisSrv.exe
    • ConfigSecurityPolicy.exe
    • MSConfig.exe
    • Regedit.exe
    • UserAccountControlSettings.exe
    • taskkill.exe
  • DOS command execution like:

    • /c schtasks /create /f /sc onlogon /rl highest /tn which creates a new task in the task scheduler.
    • timeout 3 > NUL START "" " DEL " " /f /q which is probably going to delete itself or the original sample.
  • most telling of all: VenomRATByVenom, which literally reveals that this is a VenomRAT sample, a remote access trojan.

At this point, it is possible to answer the first three questions:

The next part of the analysis will be performed both dynamically, by executing the sample and observing as much of the malware behaviour as possible, and statically, with a full code analysis. The two techniques will then be combined to answer any open questions that come up during each analysis. At the end, the malware will probably be run again in dnSpy to get some of the information that is not as easy to retrieve otherwise.

In a real scenario, the chosen approach will mostly depend on skills and requirements. If the goal is to collect IOCs from this sample, it is often sufficient to execute the malware and trace the behaviour. If the objective is to understand all the details around the sample and there is some familiarity with the programming language, opening the sample with dnSpy and looking directly at the code is more informative.