s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436 high

📛 Threat Title

AsyncRAT: file

Category: AsyncRAT Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 46080 bytes. Tags: AsyncRAT, dropped-by-remcos, exe, RemoteHost. Reporter: Bitsight. First seen: 2026-09-25 09:55:28.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
944 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436

IOC database

Type
hash_sha256
Value
5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436

hash_sha1 eae31670756fa1d5ccdae667604ca6b3ec941378 VT 59 / 75

IOC database

Type
hash_sha1
Value
eae31670756fa1d5ccdae667604ca6b3ec941378
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 59 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.RL_Generic.R358277
alibabacloud malicious Rat:Win/AsyncRAT.Stub
ALYac malicious Generic.AsyncRAT.Marte.B.24530607
Antiy-AVL malicious Trojan[Backdoor]/MSIL.Crysan
APEX malicious Malicious
Arcabit malicious Generic.AsyncRAT.Marte.B.D1764EAF
Avast malicious MSIL:AsyncRat-E [Pws]
AVG malicious MSIL:AsyncRat-E [Pws]
Avira malicious TR/Dropper.Gen
BitDefender malicious Generic.AsyncRAT.Marte.B.24530607
Bkav malicious W32.Malware.DAD4C1B6
CAT-QuickHeal malicious Trojan.IgenericFC.S14890850
ClamAV malicious Win.Packed.Razy-9625918-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.unknown.asyncrat
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Siggen9.56514
Elastic malicious Windows.Generic.Threat
Emsisoft malicious Trojan.Agent (A)
ESET-NOD32 malicious MSIL/AsyncRAT.A trojan
F-Secure malicious Trojan.TR/Dropper.Gen
Fortinet malicious MSIL/AsyncRAT.A!tr
GData malicious MSIL.Backdoor.DCRat.D
Google malicious Detected
huorong malicious Backdoor/MSIL.DcRat.a
Ikarus malicious Trojan.MSIL.AsyncRAT
Jiangmin malicious Backdoor.MSIL.gguk
K7AntiVirus malicious Trojan ( 005c228f1 )
K7GW malicious Trojan ( 005c228f1 )
Kaspersky malicious HEUR:Backdoor.MSIL.Crysan.gen
Kingsoft malicious malware.kb.c.1000
Lionic malicious Trojan.Win32.AsyncRAT.m!c
Malwarebytes malicious Generic.Trojan.MSIL.DDS
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Trojan:Win/Generic.BCX
Microsoft malicious Backdoor:MSIL/AsyncRat!atmn
MicroWorld-eScan malicious Generic.AsyncRAT.Marte.B.24530607
NANO-Antivirus malicious Trojan.Win32.AsyncRAT.lhhviy
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Trojan.AntiVM!1.CF63 (CLASSIC)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Fareit-FZT!541B5BBA7AD3
Sophos malicious Troj/AsyncRat-B
SUPERAntiSpyware malicious Trojan.Agent/Gen-Kryptik
Symantec malicious Backdoor.ASync!g2
Tencent malicious Trojan.Msil.Agent.zap
Trapmine malicious suspicious.low.ml.score
TrellixENS malicious Fareit-FZT!541B5BBA7AD3
TrendMicro malicious Backdoor.MSIL.ASYNCRAT.SMXSR
TrendMicro-HouseCall malicious Backdoor.MSIL.ASYNCRAT.SMXSR
Varist malicious W32/Samas.B.gen!Eldorado
VBA32 malicious OScope.Backdoor.MSIL.Crysan
VIPRE malicious Generic.AsyncRAT.Marte.B.24530607
VirIT malicious Trojan.Win32.MSIL_Heur.A
Zillya malicious Backdoor.Crysan.Win32.901
ZoneAlarm malicious Troj/AsyncRat-B

Details From VirusTotal

Basic Properties
MD5541b5bba7ad312556b8959c9f92af710
SHA-1eae31670756fa1d5ccdae667604ca6b3ec941378
SHA-2565346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436
VHash244036555511d08d2e1d104c
SSDEEP768:ZuyI5TdMhGqWU8Durmo2qrBKjPGaG6PIyzjbFgX3iMtiWqECrwgm23rr1KBDZrx:ZuyI5TdCf2oKTkDy3bCXSlWqZrwl23rq
TLSHT1CB231B103BE8822BF2BF4F7899F26145467AF2A32603D54D1CC452DB5613FC69A426FE
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size45.0 KB
History
Creation date2023-10-16 21:40 UTC
First seen on VirusTotal2026-09-25 09:55 UTC
Last submission2026-09-25 10:57 UTC
Last analysis2026-09-25 10:57 UTC
Last modified on VirusTotal2026-09-25 23:53 UTC
Known Names
  • Stub.exe
  • 5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436.exe
  • f6vkb7c63.exe
hash_md5 541b5bba7ad312556b8959c9f92af710 VT 59 / 75

IOC database

Type
hash_md5
Value
541b5bba7ad312556b8959c9f92af710
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 59 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.RL_Generic.R358277
alibabacloud malicious Rat:Win/AsyncRAT.Stub
ALYac malicious Generic.AsyncRAT.Marte.B.24530607
Antiy-AVL malicious Trojan[Backdoor]/MSIL.Crysan
APEX malicious Malicious
Arcabit malicious Generic.AsyncRAT.Marte.B.D1764EAF
Avast malicious MSIL:AsyncRat-E [Pws]
AVG malicious MSIL:AsyncRat-E [Pws]
Avira malicious TR/Dropper.Gen
BitDefender malicious Generic.AsyncRAT.Marte.B.24530607
Bkav malicious W32.Malware.DAD4C1B6
CAT-QuickHeal malicious Trojan.IgenericFC.S14890850
ClamAV malicious Win.Packed.Razy-9625918-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.unknown.asyncrat
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Siggen9.56514
Elastic malicious Windows.Generic.Threat
Emsisoft malicious Trojan.Agent (A)
ESET-NOD32 malicious MSIL/AsyncRAT.A trojan
F-Secure malicious Trojan.TR/Dropper.Gen
Fortinet malicious MSIL/AsyncRAT.A!tr
GData malicious MSIL.Backdoor.DCRat.D
Google malicious Detected
huorong malicious Backdoor/MSIL.DcRat.a
Ikarus malicious Trojan.MSIL.AsyncRAT
Jiangmin malicious Backdoor.MSIL.gguk
K7AntiVirus malicious Trojan ( 005c228f1 )
K7GW malicious Trojan ( 005c228f1 )
Kaspersky malicious HEUR:Backdoor.MSIL.Crysan.gen
Kingsoft malicious malware.kb.c.1000
Lionic malicious Trojan.Win32.AsyncRAT.m!c
Malwarebytes malicious Generic.Trojan.MSIL.DDS
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Trojan:Win/Generic.BCX
Microsoft malicious Backdoor:MSIL/AsyncRat!atmn
MicroWorld-eScan malicious Generic.AsyncRAT.Marte.B.24530607
NANO-Antivirus malicious Trojan.Win32.AsyncRAT.lhhviy
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Trojan.AntiVM!1.CF63 (CLASSIC)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Fareit-FZT!541B5BBA7AD3
Sophos malicious Troj/AsyncRat-B
SUPERAntiSpyware malicious Trojan.Agent/Gen-Kryptik
Symantec malicious Backdoor.ASync!g2
Tencent malicious Trojan.Msil.Agent.zap
Trapmine malicious suspicious.low.ml.score
TrellixENS malicious Fareit-FZT!541B5BBA7AD3
TrendMicro malicious Backdoor.MSIL.ASYNCRAT.SMXSR
TrendMicro-HouseCall malicious Backdoor.MSIL.ASYNCRAT.SMXSR
Varist malicious W32/Samas.B.gen!Eldorado
VBA32 malicious OScope.Backdoor.MSIL.Crysan
VIPRE malicious Generic.AsyncRAT.Marte.B.24530607
VirIT malicious Trojan.Win32.MSIL_Heur.A
Zillya malicious Backdoor.Crysan.Win32.901
ZoneAlarm malicious Troj/AsyncRat-B

Details From VirusTotal

Basic Properties
MD5541b5bba7ad312556b8959c9f92af710
SHA-1eae31670756fa1d5ccdae667604ca6b3ec941378
SHA-2565346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436
VHash244036555511d08d2e1d104c
SSDEEP768:ZuyI5TdMhGqWU8Durmo2qrBKjPGaG6PIyzjbFgX3iMtiWqECrwgm23rr1KBDZrx:ZuyI5TdCf2oKTkDy3bCXSlWqZrwl23rq
TLSHT1CB231B103BE8822BF2BF4F7899F26145467AF2A32603D54D1CC452DB5613FC69A426FE
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size45.0 KB
History
Creation date2023-10-16 21:40 UTC
First seen on VirusTotal2026-09-25 09:55 UTC
Last submission2026-09-25 10:57 UTC
Last analysis2026-09-25 10:57 UTC
Last modified on VirusTotal2026-09-25 23:53 UTC
Known Names
  • Stub.exe
  • 5346095025346221479e1fcae08c38da8f9febe17baa7315c84249d9a5bc1436.exe
  • f6vkb7c63.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 46080 bytes. Tags: AsyncRAT, dropped-by-remcos, exe, RemoteHost. Reporter: Bitsight. First seen: 2026-09-25 09:55:28.

Remediations (10)

  • web:any.run

    AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.

  • web:deepwiki.com

    This document covers the analysis of ASyncRAT (Asynchronous Remote Access Tool) campaigns and the methodology for decrypting stage 2 payloads. It provides indicators of compromise (IOCs) from multiple observed campaigns and technical details for payload extraction and decryption.

  • web:support.gridinsoft.com

    AsyncRAT Malware: Capabilities, Detection, Removal, and Recovery AsyncRAT is an open-source remote access tool for Windows that has been used in malicious campaigns. Once installed without authorization, it gives an operator persistent remote access and should be treated as a full endpoint compromise—not merely as one unwanted file .

  • web:www.checkpoint.com

    AsyncRAT Malware Explained: Remote Access Trojan Used in Cyberattacks AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background. A sophisticated strain of ...

  • web:www.cloudsek.com

    Does removing AsyncRAT end the incident? No. Credentials, session tokens, and files were already taken. Remediation has to cover identity cleanup alongside malware removal. Can AsyncRAT spread to other machines by itself? No. The base build has no worm capability, and certain forks add USB spreading plugins that change this behavior.

  • web:www.fortinet.com

    FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.

  • web:www.huntress.com

    AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files , and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.

  • web:www.microsoft.com

    Trojan:Win64/ AsyncRat is a .NET-based remote access trojan that provides threat actors with comprehensive control. The infection begins through phishing campaigns distributing malicious HTML files or ISO images.

  • web:www.pointwild.com

    Executive Summary Point Wild Threat Intelligence observed a five-stage AsyncRAT infection chain that begins with a socially engineered batch file , Right-click to open Invoice Details.bat, and ends with a .NET RAT running inside a Microsoft signed Windows process.

  • web:www.trendaisecurity.com

    Analyzing a Multi-Stage AsyncRAT Campaign via Managed Detection and Response Threat actors exploited Cloudflare's free-tier infrastructure and legitimate Python environments to deploy the AsyncRAT remote access trojan, demonstrating advanced evasion techniques that abuse trusted cloud services for malicious operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.