s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-fe57b1b7f4fa3b1f59eefcea180c45e1e1535b664107be15b40f0f1061f7f253 high

📛 Threat Title

AsyncRAT: 7zip-ver2.exe

Category: AsyncRAT First seen: Last updated:

Description

File type: exe. Size: 47616 bytes. Tags: AsyncRAT, botnet, c2, exe, trojan. Reporter: VTR. First seen: 2026-05-10 18:46:56.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain 7zip-ver2.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/7zip-ver2.exe

IOC database

Type
domain
Value
7zip-ver2.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-fe57b1b7f4fa3b1f59eefcea180c45e1e1535b664107be15b40f0f1061f7f253

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/7zip-ver2.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
944 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 fe57b1b7f4fa3b1f59eefcea180c45e1e1535b664107be15b40f0f1061f7f253 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/fe57b1b7f4fa3b1f59eefcea180c45e1e1535b664107be15b40f0f1061f7f253

IOC database

Type
hash_sha256
Value
fe57b1b7f4fa3b1f59eefcea180c45e1e1535b664107be15b40f0f1061f7f253
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/fe57b1b7f4fa3b1f59eefcea180c45e1e1535b664107be15b40f0f1061f7f253

hash_sha1 0a8879eb2696933b3311dc3bff0d065d2ca4b21b VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0a8879eb2696933b3311dc3bff0d065d2ca4b21b

IOC database

Type
hash_sha1
Value
0a8879eb2696933b3311dc3bff0d065d2ca4b21b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0a8879eb2696933b3311dc3bff0d065d2ca4b21b

hash_md5 bfea6226bd69fedd169b72aff4fef114 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/bfea6226bd69fedd169b72aff4fef114

IOC database

Type
hash_md5
Value
bfea6226bd69fedd169b72aff4fef114
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/bfea6226bd69fedd169b72aff4fef114

References (1)

  • MalwareBazaar sample page

    File type: exe. Size: 47616 bytes. Tags: AsyncRAT, botnet, c2, exe, trojan. Reporter: VTR. First seen: 2026-05-10 18:46:56.

Remediations (8)

  • web:blog.qualys.com

    Prioritized Remediation Based on Real-Time Risk Qualys identifies which systems are running vulnerable 7-Zip versions and applies the patch for CVE-2025-11001 and CVE-2025-11002, delivering an immediate, high-impact reduction in risk. Conclusion With active exploitation of CVE-2025-11001 underway, it is important to update 7-Zip to version 25.00 or later, which includes fixes for both symbolic ...

  • web:cybersecuritynews.com

    A newly disclosed vulnerability in the popular file archiving software 7-Zip , identified as CVE-2025-0411, has raised significant security concerns. This flaw allows remote attackers to bypass Windows' Mark-of-the-Web (MOTW) protection mechanism, potentially enabling the execution of arbitrary code on affected systems.

  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

  • web:wpsites.ucalgary.ca

    A critical vulnerability in the popular 7-Zip file archiver, identified as CVE-2025-0411, has been actively exploited in the wild, primarily targeting Ukrainian entities [1]. This zero-day flaw allows attackers to bypass Windows' Mark of the Web (MoTW) security feature, enabling the execution of malicious code without user warnings. This poses a significant threat, as it lowers…

  • web:www.cve.news

    A critical vulnerability has recently been discovered in 7-Zip , a widely used open-source file archiver. This vulnerability, tracked as CVE-2025-0411 (also known as ZDI-CAN-25456), allows remote attackers to bypass the Mark-of-the-Web (MotW) security mechanism on Windows systems. This post will explain, in simple terms, what this means, how the vulnerability

  • web:www.huntress.com

    AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.

  • web:www.microsoft.com

    AsyncRAT is a tool developed in C# language as an open-source RAT for Windows. Due to its open-source nature, attackers have often modified the tool to be used as a backdoor. AsyncRAT has two key components: the server and the client. The server functions as a graphical user interface (GUI) program used for managing the client, while the client component runs on compromised devices allowing it ...

  • web:www.vicarius.io

    Removing 7-Zip as the default handler for .zip, .7z, and .rar files, ensuring Windows Explorer is used instead. Renaming 7-Zip executables (7zFM.exe, 7zG.exe, 7z.exe) to prevent manual execution.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.