MB-ac58ac8e713e3720ce88a1243bde150ad4541b30ca3d8ddd72dbacd464d1a515
high
📛 Threat Title
AsyncRAT: WhatsApp image New PO 38359257N0..vbs
Description
File type: vbs. Size: 2642231 bytes. Tags: AsyncRAT, vbs. Reporter: lowmal3. First seen: 2026-05-11 12:17:53.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
ac58ac8e713e3720ce88a1243bde150ad4541b30ca3d8ddd72dbacd464d1a515
IOC database
- Type
- hash_sha256
- Value
ac58ac8e713e3720ce88a1243bde150ad4541b30ca3d8ddd72dbacd464d1a515- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- AsyncRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
d897c418366abe60651da21d24f7a72f
IOC database
- Type
- hash_md5
- Value
d897c418366abe60651da21d24f7a72f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
File type: vbs. Size: 2642231 bytes. Tags: AsyncRAT, vbs. Reporter: lowmal3. First seen: 2026-05-11 12:17:53.
Remediations (10)
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:argonsys.com
Mitigation and protection guidance Microsoft recommends the following mitigations to reduce the impact of the WhatsApp VBS Malware Campaign discussed in this report. These recommendations draw from established Defender blog guidance patterns and align with protections offered across Microsoft Defender.
-
web:bazaar.abuse.ch
Malspam AsyncRAT vbs ac58ac8e713e3720ce88a1243bde150ad4541b30ca3d8ddd72dbacd464d1a515 (this sample) Delivery method Distributed via e-mail attachment
-
web:cybrwolf.com
Learn how the WhatsApp image scam uses LSB steganography to hide malware. Clear tips from CybrWolf to protect your phone and bank account.
-
web:gadgetstouse.com
A new WhatsApp scam has emerged online where people claim that downloading a certain image on WhatsApp results in your phone getting hacked and money being stolen from your bank account.
-
web:web.whatsapp.com
Log in to WhatsApp Web for simple, reliable and private messaging on your desktop. Send and receive messages and files with ease, all for free.
-
web:www.joesandbox.com
Internet Provider seen in connection with other malware Java / VBScript file with very long strings (likely obfuscated code) May sleep (evasive loops) to hinder dynamic analysis Queries disk information (often used to detect virtual machines) Queries the installation date of Windows Queries the volume information (name, serial number etc) of a ...
-
web:www.microsoft.com
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack leverages renamed Windows tools and cloud-hosted payloads to install MSI backdoors and maintain persistent access to compromised systems.
-
web:www.qoli.ai
The WhatsApp image scam is a new scam where cybercriminals send you an image file from an unknown number. When you click on the image , it could contain malicious data, using a technique called steganography.
-
web:www.technerdo.com
Microsoft warns of an active WhatsApp -on-Windows malware campaign using VBS attachments and living-off-the-land techniques. What it is and how to block it in 60 seconds.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.