s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-7fe6d020d4e2861541bce306bf96970e89783b4823b6b86d428fc6d5e4241678 high

📛 Threat Title

AsyncRAT: 7fe6d020d4e2861541bce306bf96970e89783b4823b6b86d428fc6d5e4241678

Category: AsyncRAT First seen: Last updated:

Description

File type: exe. Size: 195692 bytes. Tags: AsyncRAT, exe. Reporter: adrian__luca. First seen: 2026-05-08 13:19:04.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7fe6d020d4e2861541bce306bf96970e89783b4823b6b86d428fc6d5e4241678

IOC database

Type
hash_sha256
Value
7fe6d020d4e2861541bce306bf96970e89783b4823b6b86d428fc6d5e4241678
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 13bceec256c6b9df43b9d8e2018986e8333098d0

IOC database

Type
hash_sha1
Value
13bceec256c6b9df43b9d8e2018986e8333098d0
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 7eb5ca638d0925e5eb7aafec205c0d53

IOC database

Type
hash_md5
Value
7eb5ca638d0925e5eb7aafec205c0d53
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_imphash 4fecd44dfc94ffab3c4ae3356e71b8f6

IOC database

Type
hash_imphash
Value
4fecd44dfc94ffab3c4ae3356e71b8f6
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page

    File type: exe. Size: 195692 bytes. Tags: AsyncRAT, exe. Reporter: adrian__luca. First seen: 2026-05-08 13:19:04.

Remediations (10)

  • web:attack.mitre.org

    AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious campaigns. [1] [2] [3]

  • web:cybersecsentinel.com

    The Desert Dexter campaign, utilizing AsyncRAT , exemplifies advanced threats exploiting legitimate tools for malicious purposes. Organizations must remain vigilant, integrate threat intelligence, and ensure robust multi-layered defenses are in place to effectively counteract this evolving threat.

  • web:cybersecuritynews.com

    Fileless AsyncRAT attacks rise, abusing ScreenConnect for access and using in-memory payloads to evade disk-based defenses.

  • web:securemyorg.com

    AsyncRAT has emerged as one of the most stubborn and stealthy Remote Access Trojans (RATs) plaguing Windows systems in 2025. It's fast, modular, and incredibly evasive. I've seen it repeatedly bypass traditional antivirus software, blend into normal network behavior, and dig deep into enterprise systems without setting off alarms. Unlike commodity malware, AsyncRAT has found favor among ...

  • web:www.anavem.com

    What is AsyncRAT Malware? AsyncRAT (Asynchronous Remote Access Trojan) is a sophisticated malware family that provides cybercriminals with comprehensive remote control capabilities over infected Windows systems.

  • web:www.bleepingcomputer.com

    A campaign delivering the AsyncRAT malware to select targets has been active for at least the past 11 months, using hundreds of unique loader samples and more than 100 domains.

  • web:www.checkpoint.com

    AsyncRAT Malware Explained: Remote Access Trojan Used in Cyberattacks AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background. A sophisticated strain of ...

  • web:www.huntress.com

    AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.

  • web:www.microsoft.com

    Trojan:Win64/ AsyncRat is a standout as a versatile remote access trojan that first appeared on GitHub in 2019, positioned as a legitimate open-source remote management utility. However, records confirm that following its launch, it has been co-opted for illicit operations by threat actors, including entry-level cybercriminals and organized syndicates tied to ransomware efforts. It is built on ...

  • web:www.securityscientist.net

    12 Questions and Answers About AsyncRAT (RAT) What Is AsyncRAT and Where Did It Come From? AsyncRAT is an open-source Remote Access Trojan written in C# and targeting the .NET framework. It was published on GitHub in 2019, originally framed as a legitimate remote administration tool. Within months, threat actors began repurposing it for malicious campaigns, making it one of the most widely ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.