s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-1e009e3c1b579103ddc8531c7cc24fff3dae304e0e82366e337ebce5fe906fb2 high

📛 Threat Title

AsyncRAT: Copia de la transaccion.vbs

Category: AsyncRAT First seen: Last updated:

Description

File type: vbs. Size: 2892754 bytes. Tags: AsyncRAT, RAT, vbs. Reporter: abuse_ch. First seen: 2026-05-08 15:41:04.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain transaccion.vbs VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/transaccion.vbs

IOC database

Type
domain
Value
transaccion.vbs
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-1e009e3c1b579103ddc8531c7cc24fff3dae304e0e82366e337ebce5fe906fb2

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/transaccion.vbs

hash_sha256 1e009e3c1b579103ddc8531c7cc24fff3dae304e0e82366e337ebce5fe906fb2

IOC database

Type
hash_sha256
Value
1e009e3c1b579103ddc8531c7cc24fff3dae304e0e82366e337ebce5fe906fb2
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 5307d3665e603c5477a191c2ee30b9d61331995b VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/5307d3665e603c5477a191c2ee30b9d61331995b

IOC database

Type
hash_sha1
Value
5307d3665e603c5477a191c2ee30b9d61331995b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/5307d3665e603c5477a191c2ee30b9d61331995b

hash_md5 c17224217c64e6223752764fc44dfb2e

IOC database

Type
hash_md5
Value
c17224217c64e6223752764fc44dfb2e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page

    File type: vbs. Size: 2892754 bytes. Tags: AsyncRAT, RAT, vbs. Reporter: abuse_ch. First seen: 2026-05-08 15:41:04.

Remediations (10)

  • web:any.run

    AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.

  • web:cybersecuritynews.com

    Fileless AsyncRAT attacks rise, abusing ScreenConnect for access and using in-memory payloads to evade disk-based defenses.

  • web:malware.news

    Fileless malware continues to evade modern defenses due to its stealthy nature and reliance on legitimate system tools for execution. This approach bypasses traditional disk-based detection by operating in memory, making these threats harder to detect, analyze, and eradicate. A recent incident culminated in the deployment of AsyncRAT , a powerful Remote Access Trojan (RAT), through a multi ...

  • web:mssplab.github.io

    AsyncRAT is a Remote Access Trojan (RAT) designed to remotely monitor and control infected systems. It is free, open-source, and often used by cybercriminals for malicious purposes, such as stealing sensitive information, installing more malware, or performing DDoS attacks.

  • web:www.activecountermeasures.com

    A pop-up upon launching the AsyncRAT server confirms that ports 6606, 7707, and 8808 are the default ports. After conducting further research using the search term " AsyncRAT malware", we discover an excellent article by McAfee that details a specific "chain of infection" instance related to AsyncRAT .

  • web:www.checkpoint.com

    AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background.

  • web:www.huntress.com

    AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.

  • web:www.joesandbox.com

    General Information Sample name: Copia de la transaccion.vbs Analysis ID: 1911033 Has dependencies: false MD5: c17224217c64e6223752764fc44dfb2e SHA1: 5307d3665e603c5477a191c2ee30b9d61331995b SHA256: 1e009e3c1b579103ddc8531c7cc24fff3dae304e0e82366e337ebce5fe906fb2 Tags: AsyncRAT , RAT, vbs Infos: yarasigma

  • web:www.malwarebytes.com

    Backdoor. AsyncRAT is a backdoor Trojan that usually arrives through malicious email attachments or malicious ads on compromised websites. Sometimes it is dropped by other malware that usually arrives in the form of an archived visual basic script (vbs) file.

  • web:www.microsoft.com

    Trojan:VBS/ AsyncRAT represents a specialized loader for the AsyncRAT remote administration tool, which threat actors weaponize for complete device compromise. This trojan family infiltrates devices through social engineering tactics, where users are tricked into running malicious VBScript files disguised as legitimate documents or bundled within archive files. The script's fundamental purpose ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.