eSentire's Threat Response Unit (TRU) discovered an AsyncRAT infection that was delivered through a Windows Script File (.wsf) via email. The malicious .wsf file, named “SummaryForm_,” downloaded a VBScript from a remote server, which then fetched a fake image file. RegAsm.exe process using a DLL to further evade detection.
Download. Email me if you need the password scheme.Click to Open Code Editor