s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0 medium

📛 Threat Title

File hash (SHA256): 04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0

Category: malware-hash Published: Source updated: First seen: Last updated:

Description

Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain abuse.ch VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
abuse.ch
First seen
Last seen
Attached to this threat
Appears in
4019 threats
Description
Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDch
History
Last analysis2026-05-24 09:28 UTC
Last modified on VirusTotal2026-05-24 16:38 UTC
WHOIS record date2026-03-29 11:09 UTC
hash_sha256 04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0 VT 60 / 75 1 feed

IOC database

Type
hash_sha256
Value
04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 60 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.RL_Generic.C3546893
Alibaba malicious Backdoor:MSIL/AsyncRat.e056658d
alibabacloud malicious Rat:Win/AsyncRAT.Stub
ALYac malicious Generic.AsyncRAT.Marte.B.B94C0C08
Antiy-AVL malicious Trojan[Backdoor]/MSIL.Crysan
APEX malicious Malicious
Arcabit malicious Generic.AsyncRAT.Marte.B.B94C0C08
Avast malicious MSIL:AsyncRat-E [Pws]
AVG malicious MSIL:AsyncRat-E [Pws]
Avira malicious TR/AsyncRat.E
BitDefender malicious Generic.AsyncRAT.Marte.B.B94C0C08
Bkav malicious W32.Malware.CE228D70
CAT-QuickHeal malicious Backdoor.MsilFC.S13564499
ClamAV malicious Win.Packed.Razy-9625918-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Siggen9.56514
Elastic malicious Windows.Generic.Threat
Emsisoft malicious Generic.AsyncRAT.Marte.B.B94C0C08 (B)
ESET-NOD32 malicious MSIL/AsyncRAT.A trojan
F-Secure malicious Trojan.TR/AsyncRat.E
Fortinet malicious MSIL/AsyncRAT.A!tr
GData malicious MSIL.Backdoor.DCRat.D
Google malicious Detected
Gridinsoft malicious Trojan.Win32.Packed.sa
huorong malicious Backdoor/MSIL.DcRat.a
Ikarus malicious Trojan.MSIL.AsyncRAT
Jiangmin malicious Backdoor.MSIL.gguk
K7AntiVirus malicious Trojan ( 005678321 )
K7GW malicious Trojan ( 005678321 )
Kaspersky malicious HEUR:Backdoor.MSIL.Crysan.gen
Kingsoft malicious malware.kb.c.977
Lionic malicious Trojan.Win32.AsyncRAT.m!c
Malwarebytes malicious Generic.Trojan.MSIL.DDS
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious Trojan:Win/Generic.BCX
Microsoft malicious Backdoor:MSIL/AsyncRat!atmn
MicroWorld-eScan malicious Generic.AsyncRAT.Marte.B.B94C0C08
NANO-Antivirus malicious Trojan.Win32.Crysan.hwjaer
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Trojan.AntiVM!1.CF63 (CLASSIC)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Fareit-FZT!20A96E130D7C
Sophos malicious Troj/AsyncRat-B
Symantec malicious Backdoor.ASync!g2
Tencent malicious Trojan.Msil.Agent.zap
Trapmine malicious malicious.moderate.ml.score
TrellixENS malicious Fareit-FZT!20A96E130D7C
TrendMicro malicious Backdoor.MSIL.ASYNCRAT.TL0101EG26ZZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/Samas.B.gen!Eldorado
VBA32 malicious OScope.Backdoor.MSIL.Crysan
VIPRE malicious Generic.AsyncRAT.Marte.B.B94C0C08
VirIT malicious Trojan.Win32.MSIL.JQO
ViRobot malicious Trojan.Win.Z.Asyncrat.77824.AA
ZoneAlarm malicious Troj/AsyncRat-B

Details From VirusTotal

Basic Properties
MD520a96e130d7c0141531d4be69baed599
SHA-18efecef829efc0232ae2cd48f5e1b4f7eda71a02
SHA-25604206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0
VHash274036556511d08d2e1d104d
SSDEEP1536:MuyJNTAGL2NwIZlsIbOXSLCbqdrjC5wM5IN:MuyHTAGL2rbsIbOJ29C5wkIN
TLSHT138735B0077D88566F1BE0B7499E2D1B5467AEE637503EA4E2CC47C8B3733BC25502AE9
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size76.0 KB
History
Creation date2023-10-16 21:40 UTC
First seen on VirusTotal2026-05-15 08:33 UTC
Last submission2026-05-15 08:33 UTC
Last analysis2026-06-01 06:02 UTC
Last modified on VirusTotal2026-06-03 17:53 UTC
Known Names
  • CapCut
  • _04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0.exe
  • grx5joz.exe

References (1)

  • VirusTotal report

    Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.