MB-130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
high
📛 Threat Title
AsyncRAT: 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
Description
File type: exe. Size: 164352 bytes. Tags: AsyncRAT, exe. Reporter: adrian__luca. First seen: 2026-05-08 12:44:39.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483
VT 50 / 75
IOC database
- Type
- hash_sha256
- Value
130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- AsyncRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win.XWorm.R769352 |
| Alibaba | malicious | Backdoor:Win64/Xworm.826d3cad |
| alibabacloud | malicious | Backdoor:MSIL/Xworm.ADL2XJC |
| ALYac | malicious | Gen:Variant.Lazy.716984 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.XWorm |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Lazy.DAF0B8 |
| Avast | malicious | Win64:MalwareX-gen [Rat] |
| AVG | malicious | Win64:MalwareX-gen [Rat] |
| Avira | malicious | TR/W64.MalwareX |
| BitDefender | malicious | Gen:Variant.Lazy.716984 |
| Bkav | malicious | W32.Malware.9CF53ECE |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.worm.msil |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| Emsisoft | malicious | Gen:Variant.Lazy.716984 (B) |
| ESET-NOD32 | malicious | Generik.EQIUDQP trojan |
| F-Secure | malicious | Trojan.TR/W64.MalwareX |
| Fortinet | malicious | W32/SPCL_Xworm.2DDC!tr |
| GData | malicious | Gen:Variant.Lazy.716984 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Injector.cnb |
| Ikarus | malicious | Trojan.SuspectCRC |
| K7AntiVirus | malicious | Backdoor ( 006de1391 ) |
| K7GW | malicious | Backdoor ( 006de1391 ) |
| Kaspersky | malicious | Backdoor.MSIL.XWorm.jel |
| Kingsoft | malicious | MSIL.Backdoor.XWorm.jel |
| Lionic | malicious | Trojan.Win32.XWorm.m!c |
| Malwarebytes | malicious | Worm.XWorm |
| McAfeeD | malicious | Trojan:Win/XWorm.NEK |
| Microsoft | malicious | Trojan:Win64/Xworm.AXW!MTB |
| MicroWorld-eScan | malicious | Gen:Variant.Lazy.716984 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Kryptik@AI.84 (RDML:rOgL5q99/SlVbJS6oLrycQ) |
| Sangfor | malicious | Backdoor.Win64.Xworm.Vuc4 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Malware.Win32.Gencirc.14acb2d9 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!E1CF1E28A618 |
| TrendMicro | malicious | Backdoor.Win64.XWORM.YXGDKZ |
| TrendMicro-HouseCall | malicious | Backdoor.Win64.XWORM.YXGDKZ |
| Varist | malicious | W64/ABTrojan.FNAF-4440 |
| VIPRE | malicious | Gen:Variant.Lazy.716984 |
| VirIT | malicious | Trojan.Win64.GenPsw.JQI |
| ViRobot | malicious | Trojan.Win.Z.Lazy.164352.I |
| Zillya | malicious | Backdoor.XWorm.Win32.3096 |
Details From VirusTotal
Basic Properties
| MD5 | e1cf1e28a618faa8aa6c72b260bd2ddc |
| SHA-1 | 059b09e6dbbfb78124d82203b037dd8b897a774b |
| SHA-256 | 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 |
| VHash | 015056655d15557az46!z |
| SSDEEP | 3072:bSzF0EOSgOnbhXa3rxt0q0xdXPybPLrK/E8tlDkVt0Nf4GN:bSzFcOnbyrxeqIqPh8t/f4G |
| TLSH | T1C8F36B07B3A530F8E17BC175C4924A46E772787A4761AB9F07A04A7A2F237D09D3DB21 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 160.5 KB |
History
| Creation date | 2026-04-08 14:59 UTC |
| First seen on VirusTotal | 2026-04-10 22:57 UTC |
| Last submission | 2026-04-10 23:00 UTC |
| Last analysis | 2026-05-25 06:34 UTC |
| Last modified on VirusTotal | 2026-05-25 08:37 UTC |
Known Names
mtasksvc.exemtasksvc130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exeptntjt.exetltwnv.exegcasy.exejnei.exex130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe2026-04-10_e1cf1e28a618faa8aa6c72b260bd2ddc_cobalt-strike_icedid_satacom_stealcwxcvdwe2.exe
hash_sha1
059b09e6dbbfb78124d82203b037dd8b897a774b
VT 50 / 75
IOC database
- Type
- hash_sha1
- Value
059b09e6dbbfb78124d82203b037dd8b897a774b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win.XWorm.R769352 |
| Alibaba | malicious | Backdoor:Win64/Xworm.826d3cad |
| alibabacloud | malicious | Backdoor:MSIL/Xworm.ADL2XJC |
| ALYac | malicious | Gen:Variant.Lazy.716984 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.XWorm |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Lazy.DAF0B8 |
| Avast | malicious | Win64:MalwareX-gen [Rat] |
| AVG | malicious | Win64:MalwareX-gen [Rat] |
| Avira | malicious | TR/W64.MalwareX |
| BitDefender | malicious | Gen:Variant.Lazy.716984 |
| Bkav | malicious | W32.Malware.9CF53ECE |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.worm.msil |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| Emsisoft | malicious | Gen:Variant.Lazy.716984 (B) |
| ESET-NOD32 | malicious | Generik.EQIUDQP trojan |
| F-Secure | malicious | Trojan.TR/W64.MalwareX |
| Fortinet | malicious | W32/SPCL_Xworm.2DDC!tr |
| GData | malicious | Gen:Variant.Lazy.716984 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Injector.cnb |
| Ikarus | malicious | Trojan.SuspectCRC |
| K7AntiVirus | malicious | Backdoor ( 006de1391 ) |
| K7GW | malicious | Backdoor ( 006de1391 ) |
| Kaspersky | malicious | Backdoor.MSIL.XWorm.jel |
| Kingsoft | malicious | MSIL.Backdoor.XWorm.jel |
| Lionic | malicious | Trojan.Win32.XWorm.m!c |
| Malwarebytes | malicious | Worm.XWorm |
| McAfeeD | malicious | Trojan:Win/XWorm.NEK |
| Microsoft | malicious | Trojan:Win64/Xworm.AXW!MTB |
| MicroWorld-eScan | malicious | Gen:Variant.Lazy.716984 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Kryptik@AI.84 (RDML:rOgL5q99/SlVbJS6oLrycQ) |
| Sangfor | malicious | Backdoor.Win64.Xworm.Vuc4 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Malware.Win32.Gencirc.14acb2d9 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!E1CF1E28A618 |
| TrendMicro | malicious | Backdoor.Win64.XWORM.YXGDKZ |
| TrendMicro-HouseCall | malicious | Backdoor.Win64.XWORM.YXGDKZ |
| Varist | malicious | W64/ABTrojan.FNAF-4440 |
| VIPRE | malicious | Gen:Variant.Lazy.716984 |
| VirIT | malicious | Trojan.Win64.GenPsw.JQI |
| ViRobot | malicious | Trojan.Win.Z.Lazy.164352.I |
| Zillya | malicious | Backdoor.XWorm.Win32.3096 |
Details From VirusTotal
Basic Properties
| MD5 | e1cf1e28a618faa8aa6c72b260bd2ddc |
| SHA-1 | 059b09e6dbbfb78124d82203b037dd8b897a774b |
| SHA-256 | 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 |
| VHash | 015056655d15557az46!z |
| SSDEEP | 3072:bSzF0EOSgOnbhXa3rxt0q0xdXPybPLrK/E8tlDkVt0Nf4GN:bSzFcOnbyrxeqIqPh8t/f4G |
| TLSH | T1C8F36B07B3A530F8E17BC175C4924A46E772787A4761AB9F07A04A7A2F237D09D3DB21 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 160.5 KB |
History
| Creation date | 2026-04-08 14:59 UTC |
| First seen on VirusTotal | 2026-04-10 22:57 UTC |
| Last submission | 2026-04-10 23:00 UTC |
| Last analysis | 2026-05-25 06:34 UTC |
| Last modified on VirusTotal | 2026-05-25 08:37 UTC |
Known Names
mtasksvc.exemtasksvc130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exeptntjt.exetltwnv.exegcasy.exejnei.exex130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe2026-04-10_e1cf1e28a618faa8aa6c72b260bd2ddc_cobalt-strike_icedid_satacom_stealcwxcvdwe2.exe
hash_md5
e1cf1e28a618faa8aa6c72b260bd2ddc
VT 50 / 75
IOC database
- Type
- hash_md5
- Value
e1cf1e28a618faa8aa6c72b260bd2ddc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win.XWorm.R769352 |
| Alibaba | malicious | Backdoor:Win64/Xworm.826d3cad |
| alibabacloud | malicious | Backdoor:MSIL/Xworm.ADL2XJC |
| ALYac | malicious | Gen:Variant.Lazy.716984 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.XWorm |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Lazy.DAF0B8 |
| Avast | malicious | Win64:MalwareX-gen [Rat] |
| AVG | malicious | Win64:MalwareX-gen [Rat] |
| Avira | malicious | TR/W64.MalwareX |
| BitDefender | malicious | Gen:Variant.Lazy.716984 |
| Bkav | malicious | W32.Malware.9CF53ECE |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.worm.msil |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| Emsisoft | malicious | Gen:Variant.Lazy.716984 (B) |
| ESET-NOD32 | malicious | Generik.EQIUDQP trojan |
| F-Secure | malicious | Trojan.TR/W64.MalwareX |
| Fortinet | malicious | W32/SPCL_Xworm.2DDC!tr |
| GData | malicious | Gen:Variant.Lazy.716984 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Injector.cnb |
| Ikarus | malicious | Trojan.SuspectCRC |
| K7AntiVirus | malicious | Backdoor ( 006de1391 ) |
| K7GW | malicious | Backdoor ( 006de1391 ) |
| Kaspersky | malicious | Backdoor.MSIL.XWorm.jel |
| Kingsoft | malicious | MSIL.Backdoor.XWorm.jel |
| Lionic | malicious | Trojan.Win32.XWorm.m!c |
| Malwarebytes | malicious | Worm.XWorm |
| McAfeeD | malicious | Trojan:Win/XWorm.NEK |
| Microsoft | malicious | Trojan:Win64/Xworm.AXW!MTB |
| MicroWorld-eScan | malicious | Gen:Variant.Lazy.716984 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Kryptik@AI.84 (RDML:rOgL5q99/SlVbJS6oLrycQ) |
| Sangfor | malicious | Backdoor.Win64.Xworm.Vuc4 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Malware.Win32.Gencirc.14acb2d9 |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!E1CF1E28A618 |
| TrendMicro | malicious | Backdoor.Win64.XWORM.YXGDKZ |
| TrendMicro-HouseCall | malicious | Backdoor.Win64.XWORM.YXGDKZ |
| Varist | malicious | W64/ABTrojan.FNAF-4440 |
| VIPRE | malicious | Gen:Variant.Lazy.716984 |
| VirIT | malicious | Trojan.Win64.GenPsw.JQI |
| ViRobot | malicious | Trojan.Win.Z.Lazy.164352.I |
| Zillya | malicious | Backdoor.XWorm.Win32.3096 |
Details From VirusTotal
Basic Properties
| MD5 | e1cf1e28a618faa8aa6c72b260bd2ddc |
| SHA-1 | 059b09e6dbbfb78124d82203b037dd8b897a774b |
| SHA-256 | 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 |
| VHash | 015056655d15557az46!z |
| SSDEEP | 3072:bSzF0EOSgOnbhXa3rxt0q0xdXPybPLrK/E8tlDkVt0Nf4GN:bSzFcOnbyrxeqIqPh8t/f4G |
| TLSH | T1C8F36B07B3A530F8E17BC175C4924A46E772787A4761AB9F07A04A7A2F237D09D3DB21 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 160.5 KB |
History
| Creation date | 2026-04-08 14:59 UTC |
| First seen on VirusTotal | 2026-04-10 22:57 UTC |
| Last submission | 2026-04-10 23:00 UTC |
| Last analysis | 2026-05-25 06:34 UTC |
| Last modified on VirusTotal | 2026-05-25 08:37 UTC |
Known Names
mtasksvc.exemtasksvc130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exeptntjt.exetltwnv.exegcasy.exejnei.exex130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483.exe2026-04-10_e1cf1e28a618faa8aa6c72b260bd2ddc_cobalt-strike_icedid_satacom_stealcwxcvdwe2.exe
hash_imphash
eb55951f74d08ec7d4b3760e87582915
IOC database
- Type
- hash_imphash
- Value
eb55951f74d08ec7d4b3760e87582915- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
File type: exe. Size: 164352 bytes. Tags: AsyncRAT, exe. Reporter: adrian__luca. First seen: 2026-05-08 12:44:39.
Remediations (10)
-
web:any.run
AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.
-
web:attackevals.github.io
AsyncRAT is an open source Remote Administration tool maintained by Nyan Cat and leveraged by Blind Eagle in its campaigns 1,2. For the purposes of this emulation a fork of AsyncRAT was made so that documentation could be added and relevent code functions could be highlighted with comments relating to their use and CTI.
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 130c6dc6832f699ea5a82d1d77ebf288c370402842debf136be1fe084cae1483 . While MalwareBazaar tries to identify ...
-
web:github.com
Open-Source Remote Administration Tool For Windows C# (RAT) - NYAN-x-CAT/ AsyncRAT -C-Sharp
-
web:howtoremove.guide
This article talks about a very harmful computer program called AsyncRat , which can get into your computer in sneaky ways.
-
web:www.checkpoint.com
AsyncRAT Malware Explained: Remote Access Trojan Used in Cyberattacks AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background. A sophisticated strain of ...
-
web:www.huntress.com
AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.
-
web:www.microsoft.com
Trojan:Win64/ AsyncRat is a standout as a versatile remote access trojan that first appeared on GitHub in 2019, positioned as a legitimate open-source remote management utility. However, records confirm that following its launch, it has been co-opted for illicit operations by threat actors, including entry-level cybercriminals and organized syndicates tied to ransomware efforts. It is built on ...
-
web:www.pcrisk.com
AsyncRAT can be used to proliferate malware such as ransomware, trojans, and other malicious programs. Furthermore, it allows users to monitor computing activities, access and manage various files (including personal documents), and start/end processes.
-
web:www.trendmicro.com
The AsyncRAT campaign analyzed in this report demonstrates the increasing sophistication of threat actors in abusing legitimate services and open-source tools to evade detection and establish persistent remote access.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.