s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 high

📛 Threat Title

AsyncRAT: 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483

Category: AsyncRAT First seen: Last updated:

Description

File type: exe. Size: 164352 bytes. Tags: AsyncRAT, exe. Reporter: adrian__luca. First seen: 2026-05-08 12:44:39.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 VT 50 / 75

IOC database

Type
hash_sha256
Value
130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win.XWorm.R769352
Alibaba malicious Backdoor:Win64/Xworm.826d3cad
alibabacloud malicious Backdoor:MSIL/Xworm.ADL2XJC
ALYac malicious Gen:Variant.Lazy.716984
Antiy-AVL malicious Trojan[Backdoor]/MSIL.XWorm
APEX malicious Malicious
Arcabit malicious Trojan.Lazy.DAF0B8
Avast malicious Win64:MalwareX-gen [Rat]
AVG malicious Win64:MalwareX-gen [Rat]
Avira malicious TR/W64.MalwareX
BitDefender malicious Gen:Variant.Lazy.716984
Bkav malicious W32.Malware.9CF53ECE
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.worm.msil
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
Emsisoft malicious Gen:Variant.Lazy.716984 (B)
ESET-NOD32 malicious Generik.EQIUDQP trojan
F-Secure malicious Trojan.TR/W64.MalwareX
Fortinet malicious W32/SPCL_Xworm.2DDC!tr
GData malicious Gen:Variant.Lazy.716984
Google malicious Detected
huorong malicious Trojan/Injector.cnb
Ikarus malicious Trojan.SuspectCRC
K7AntiVirus malicious Backdoor ( 006de1391 )
K7GW malicious Backdoor ( 006de1391 )
Kaspersky malicious Backdoor.MSIL.XWorm.jel
Kingsoft malicious MSIL.Backdoor.XWorm.jel
Lionic malicious Trojan.Win32.XWorm.m!c
Malwarebytes malicious Worm.XWorm
McAfeeD malicious Trojan:Win/XWorm.NEK
Microsoft malicious Trojan:Win64/Xworm.AXW!MTB
MicroWorld-eScan malicious Gen:Variant.Lazy.716984
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Trojan.Kryptik@AI.84 (RDML:rOgL5q99/SlVbJS6oLrycQ)
Sangfor malicious Backdoor.Win64.Xworm.Vuc4
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Malware.Win32.Gencirc.14acb2d9
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!E1CF1E28A618
TrendMicro malicious Backdoor.Win64.XWORM.YXGDKZ
TrendMicro-HouseCall malicious Backdoor.Win64.XWORM.YXGDKZ
Varist malicious W64/ABTrojan.FNAF-4440
VIPRE malicious Gen:Variant.Lazy.716984
VirIT malicious Trojan.Win64.GenPsw.JQI
ViRobot malicious Trojan.Win.Z.Lazy.164352.I
Zillya malicious Backdoor.XWorm.Win32.3096

Details From VirusTotal

Basic Properties
MD5e1cf1e28a618faa8aa6c72b260bd2ddc
SHA-1059b09e6dbbfb78124d82203b037dd8b897a774b
SHA-256130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
VHash015056655d15557az46!z
SSDEEP3072:bSzF0EOSgOnbhXa3rxt0q0xdXPybPLrK/E8tlDkVt0Nf4GN:bSzFcOnbyrxeqIqPh8t/f4G
TLSHT1C8F36B07B3A530F8E17BC175C4924A46E772787A4761AB9F07A04A7A2F237D09D3DB21
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size160.5 KB
History
Creation date2026-04-08 14:59 UTC
First seen on VirusTotal2026-04-10 22:57 UTC
Last submission2026-04-10 23:00 UTC
Last analysis2026-05-25 06:34 UTC
Last modified on VirusTotal2026-05-25 08:37 UTC
Known Names
  • mtasksvc.exe
  • mtasksvc
  • 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe
  • ptntjt.exe
  • tltwnv.exe
  • gcasy.exe
  • jnei.exe
  • x130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe
  • 2026-04-10_e1cf1e28a618faa8aa6c72b260bd2ddc_cobalt-strike_icedid_satacom_stealc
  • wxcvdwe2.exe
hash_sha1 059b09e6dbbfb78124d82203b037dd8b897a774b VT 50 / 75

IOC database

Type
hash_sha1
Value
059b09e6dbbfb78124d82203b037dd8b897a774b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win.XWorm.R769352
Alibaba malicious Backdoor:Win64/Xworm.826d3cad
alibabacloud malicious Backdoor:MSIL/Xworm.ADL2XJC
ALYac malicious Gen:Variant.Lazy.716984
Antiy-AVL malicious Trojan[Backdoor]/MSIL.XWorm
APEX malicious Malicious
Arcabit malicious Trojan.Lazy.DAF0B8
Avast malicious Win64:MalwareX-gen [Rat]
AVG malicious Win64:MalwareX-gen [Rat]
Avira malicious TR/W64.MalwareX
BitDefender malicious Gen:Variant.Lazy.716984
Bkav malicious W32.Malware.9CF53ECE
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.worm.msil
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
Emsisoft malicious Gen:Variant.Lazy.716984 (B)
ESET-NOD32 malicious Generik.EQIUDQP trojan
F-Secure malicious Trojan.TR/W64.MalwareX
Fortinet malicious W32/SPCL_Xworm.2DDC!tr
GData malicious Gen:Variant.Lazy.716984
Google malicious Detected
huorong malicious Trojan/Injector.cnb
Ikarus malicious Trojan.SuspectCRC
K7AntiVirus malicious Backdoor ( 006de1391 )
K7GW malicious Backdoor ( 006de1391 )
Kaspersky malicious Backdoor.MSIL.XWorm.jel
Kingsoft malicious MSIL.Backdoor.XWorm.jel
Lionic malicious Trojan.Win32.XWorm.m!c
Malwarebytes malicious Worm.XWorm
McAfeeD malicious Trojan:Win/XWorm.NEK
Microsoft malicious Trojan:Win64/Xworm.AXW!MTB
MicroWorld-eScan malicious Gen:Variant.Lazy.716984
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Trojan.Kryptik@AI.84 (RDML:rOgL5q99/SlVbJS6oLrycQ)
Sangfor malicious Backdoor.Win64.Xworm.Vuc4
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Malware.Win32.Gencirc.14acb2d9
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!E1CF1E28A618
TrendMicro malicious Backdoor.Win64.XWORM.YXGDKZ
TrendMicro-HouseCall malicious Backdoor.Win64.XWORM.YXGDKZ
Varist malicious W64/ABTrojan.FNAF-4440
VIPRE malicious Gen:Variant.Lazy.716984
VirIT malicious Trojan.Win64.GenPsw.JQI
ViRobot malicious Trojan.Win.Z.Lazy.164352.I
Zillya malicious Backdoor.XWorm.Win32.3096

Details From VirusTotal

Basic Properties
MD5e1cf1e28a618faa8aa6c72b260bd2ddc
SHA-1059b09e6dbbfb78124d82203b037dd8b897a774b
SHA-256130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
VHash015056655d15557az46!z
SSDEEP3072:bSzF0EOSgOnbhXa3rxt0q0xdXPybPLrK/E8tlDkVt0Nf4GN:bSzFcOnbyrxeqIqPh8t/f4G
TLSHT1C8F36B07B3A530F8E17BC175C4924A46E772787A4761AB9F07A04A7A2F237D09D3DB21
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size160.5 KB
History
Creation date2026-04-08 14:59 UTC
First seen on VirusTotal2026-04-10 22:57 UTC
Last submission2026-04-10 23:00 UTC
Last analysis2026-05-25 06:34 UTC
Last modified on VirusTotal2026-05-25 08:37 UTC
Known Names
  • mtasksvc.exe
  • mtasksvc
  • 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe
  • ptntjt.exe
  • tltwnv.exe
  • gcasy.exe
  • jnei.exe
  • x130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe
  • 2026-04-10_e1cf1e28a618faa8aa6c72b260bd2ddc_cobalt-strike_icedid_satacom_stealc
  • wxcvdwe2.exe
hash_md5 e1cf1e28a618faa8aa6c72b260bd2ddc VT 50 / 75

IOC database

Type
hash_md5
Value
e1cf1e28a618faa8aa6c72b260bd2ddc
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win.XWorm.R769352
Alibaba malicious Backdoor:Win64/Xworm.826d3cad
alibabacloud malicious Backdoor:MSIL/Xworm.ADL2XJC
ALYac malicious Gen:Variant.Lazy.716984
Antiy-AVL malicious Trojan[Backdoor]/MSIL.XWorm
APEX malicious Malicious
Arcabit malicious Trojan.Lazy.DAF0B8
Avast malicious Win64:MalwareX-gen [Rat]
AVG malicious Win64:MalwareX-gen [Rat]
Avira malicious TR/W64.MalwareX
BitDefender malicious Gen:Variant.Lazy.716984
Bkav malicious W32.Malware.9CF53ECE
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.worm.msil
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
Emsisoft malicious Gen:Variant.Lazy.716984 (B)
ESET-NOD32 malicious Generik.EQIUDQP trojan
F-Secure malicious Trojan.TR/W64.MalwareX
Fortinet malicious W32/SPCL_Xworm.2DDC!tr
GData malicious Gen:Variant.Lazy.716984
Google malicious Detected
huorong malicious Trojan/Injector.cnb
Ikarus malicious Trojan.SuspectCRC
K7AntiVirus malicious Backdoor ( 006de1391 )
K7GW malicious Backdoor ( 006de1391 )
Kaspersky malicious Backdoor.MSIL.XWorm.jel
Kingsoft malicious MSIL.Backdoor.XWorm.jel
Lionic malicious Trojan.Win32.XWorm.m!c
Malwarebytes malicious Worm.XWorm
McAfeeD malicious Trojan:Win/XWorm.NEK
Microsoft malicious Trojan:Win64/Xworm.AXW!MTB
MicroWorld-eScan malicious Gen:Variant.Lazy.716984
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Trojan.Kryptik@AI.84 (RDML:rOgL5q99/SlVbJS6oLrycQ)
Sangfor malicious Backdoor.Win64.Xworm.Vuc4
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Malware.Win32.Gencirc.14acb2d9
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!E1CF1E28A618
TrendMicro malicious Backdoor.Win64.XWORM.YXGDKZ
TrendMicro-HouseCall malicious Backdoor.Win64.XWORM.YXGDKZ
Varist malicious W64/ABTrojan.FNAF-4440
VIPRE malicious Gen:Variant.Lazy.716984
VirIT malicious Trojan.Win64.GenPsw.JQI
ViRobot malicious Trojan.Win.Z.Lazy.164352.I
Zillya malicious Backdoor.XWorm.Win32.3096

Details From VirusTotal

Basic Properties
MD5e1cf1e28a618faa8aa6c72b260bd2ddc
SHA-1059b09e6dbbfb78124d82203b037dd8b897a774b
SHA-256130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
VHash015056655d15557az46!z
SSDEEP3072:bSzF0EOSgOnbhXa3rxt0q0xdXPybPLrK/E8tlDkVt0Nf4GN:bSzFcOnbyrxeqIqPh8t/f4G
TLSHT1C8F36B07B3A530F8E17BC175C4924A46E772787A4761AB9F07A04A7A2F237D09D3DB21
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size160.5 KB
History
Creation date2026-04-08 14:59 UTC
First seen on VirusTotal2026-04-10 22:57 UTC
Last submission2026-04-10 23:00 UTC
Last analysis2026-05-25 06:34 UTC
Last modified on VirusTotal2026-05-25 08:37 UTC
Known Names
  • mtasksvc.exe
  • mtasksvc
  • 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe
  • ptntjt.exe
  • tltwnv.exe
  • gcasy.exe
  • jnei.exe
  • x130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe
  • 2026-04-10_e1cf1e28a618faa8aa6c72b260bd2ddc_cobalt-strike_icedid_satacom_stealc
  • wxcvdwe2.exe
hash_imphash eb55951f74d08ec7d4b3760e87582915

IOC database

Type
hash_imphash
Value
eb55951f74d08ec7d4b3760e87582915
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page

    File type: exe. Size: 164352 bytes. Tags: AsyncRAT, exe. Reporter: adrian__luca. First seen: 2026-05-08 12:44:39.

Remediations (10)

  • web:any.run

    AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.

  • web:attackevals.github.io

    AsyncRAT is an open source Remote Administration tool maintained by Nyan Cat and leveraged by Blind Eagle in its campaigns 1,2. For the purposes of this emulation a fork of AsyncRAT was made so that documentation could be added and relevent code functions could be highlighted with comments relating to their use and CTI.

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 . While MalwareBazaar tries to identify ...

  • web:github.com

    Open-Source Remote Administration Tool For Windows C# (RAT) - NYAN-x-CAT/ AsyncRAT -C-Sharp

  • web:howtoremove.guide

    This article talks about a very harmful computer program called AsyncRat , which can get into your computer in sneaky ways.

  • web:www.checkpoint.com

    AsyncRAT Malware Explained: Remote Access Trojan Used in Cyberattacks AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background. A sophisticated strain of ...

  • web:www.huntress.com

    AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.

  • web:www.microsoft.com

    Trojan:Win64/ AsyncRat is a standout as a versatile remote access trojan that first appeared on GitHub in 2019, positioned as a legitimate open-source remote management utility. However, records confirm that following its launch, it has been co-opted for illicit operations by threat actors, including entry-level cybercriminals and organized syndicates tied to ransomware efforts. It is built on ...

  • web:www.pcrisk.com

    AsyncRAT can be used to proliferate malware such as ransomware, trojans, and other malicious programs. Furthermore, it allows users to monitor computing activities, access and manage various files (including personal documents), and start/end processes.

  • web:www.trendmicro.com

    The AsyncRAT campaign analyzed in this report demonstrates the increasing sophistication of threat actors in abusing legitimate services and open-source tools to evade detection and establish persistent remote access.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.