VT-04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0
medium
📛 Threat Title
File hash (SHA256): 04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0
Description
Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
abuse.ch
VT 0 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
abuse.ch- First seen
- Last seen
- Attached to this threat
- Appears in
- 4019 threats
- Description
- Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | ch |
History
| Last analysis | 2026-05-24 09:28 UTC |
| Last modified on VirusTotal | 2026-05-24 16:38 UTC |
| WHOIS record date | 2026-03-29 11:09 UTC |
hash_sha256
04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0
VT 60 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- AsyncRAT
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 60 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.RL_Generic.C3546893 |
| Alibaba | malicious | Backdoor:MSIL/AsyncRat.e056658d |
| alibabacloud | malicious | Rat:Win/AsyncRAT.Stub |
| ALYac | malicious | Generic.AsyncRAT.Marte.B.B94C0C08 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.Crysan |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.AsyncRAT.Marte.B.B94C0C08 |
| Avast | malicious | MSIL:AsyncRat-E [Pws] |
| AVG | malicious | MSIL:AsyncRat-E [Pws] |
| Avira | malicious | TR/AsyncRat.E |
| BitDefender | malicious | Generic.AsyncRAT.Marte.B.B94C0C08 |
| Bkav | malicious | W32.Malware.CE228D70 |
| CAT-QuickHeal | malicious | Backdoor.MsilFC.S13564499 |
| ClamAV | malicious | Win.Packed.Razy-9625918-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Siggen9.56514 |
| Elastic | malicious | Windows.Generic.Threat |
| Emsisoft | malicious | Generic.AsyncRAT.Marte.B.B94C0C08 (B) |
| ESET-NOD32 | malicious | MSIL/AsyncRAT.A trojan |
| F-Secure | malicious | Trojan.TR/AsyncRat.E |
| Fortinet | malicious | MSIL/AsyncRAT.A!tr |
| GData | malicious | MSIL.Backdoor.DCRat.D |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win32.Packed.sa |
| huorong | malicious | Backdoor/MSIL.DcRat.a |
| Ikarus | malicious | Trojan.MSIL.AsyncRAT |
| Jiangmin | malicious | Backdoor.MSIL.gguk |
| K7AntiVirus | malicious | Trojan ( 005678321 ) |
| K7GW | malicious | Trojan ( 005678321 ) |
| Kaspersky | malicious | HEUR:Backdoor.MSIL.Crysan.gen |
| Kingsoft | malicious | malware.kb.c.977 |
| Lionic | malicious | Trojan.Win32.AsyncRAT.m!c |
| Malwarebytes | malicious | Generic.Trojan.MSIL.DDS |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| McAfeeD | malicious | Trojan:Win/Generic.BCX |
| Microsoft | malicious | Backdoor:MSIL/AsyncRat!atmn |
| MicroWorld-eScan | malicious | Generic.AsyncRAT.Marte.B.B94C0C08 |
| NANO-Antivirus | malicious | Trojan.Win32.Crysan.hwjaer |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/CI.A |
| Rising | malicious | Trojan.AntiVM!1.CF63 (CLASSIC) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Fareit-FZT!20A96E130D7C |
| Sophos | malicious | Troj/AsyncRat-B |
| Symantec | malicious | Backdoor.ASync!g2 |
| Tencent | malicious | Trojan.Msil.Agent.zap |
| Trapmine | malicious | malicious.moderate.ml.score |
| TrellixENS | malicious | Fareit-FZT!20A96E130D7C |
| TrendMicro | malicious | Backdoor.MSIL.ASYNCRAT.TL0101EG26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/Samas.B.gen!Eldorado |
| VBA32 | malicious | OScope.Backdoor.MSIL.Crysan |
| VIPRE | malicious | Generic.AsyncRAT.Marte.B.B94C0C08 |
| VirIT | malicious | Trojan.Win32.MSIL.JQO |
| ViRobot | malicious | Trojan.Win.Z.Asyncrat.77824.AA |
| ZoneAlarm | malicious | Troj/AsyncRat-B |
Details From VirusTotal
Basic Properties
| MD5 | 20a96e130d7c0141531d4be69baed599 |
| SHA-1 | 8efecef829efc0232ae2cd48f5e1b4f7eda71a02 |
| SHA-256 | 04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0 |
| VHash | 274036556511d08d2e1d104d |
| SSDEEP | 1536:MuyJNTAGL2NwIZlsIbOXSLCbqdrjC5wM5IN:MuyHTAGL2rbsIbOJ29C5wkIN |
| TLSH | T138735B0077D88566F1BE0B7499E2D1B5467AEE637503EA4E2CC47C8B3733BC25502AE9 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 76.0 KB |
History
| Creation date | 2023-10-16 21:40 UTC |
| First seen on VirusTotal | 2026-05-15 08:33 UTC |
| Last submission | 2026-05-15 08:33 UTC |
| Last analysis | 2026-06-01 06:02 UTC |
| Last modified on VirusTotal | 2026-06-03 17:53 UTC |
Known Names
CapCut_04206c143c79f1c33d855eb781995ff764fbcb8649a3422d59b0540cbc2e00f0.exegrx5joz.exe
References (1)
-
VirusTotal report
Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).
Remediations (10)
-
web:check.town
Free file hash checker. Upload a file and compute MD5, SHA-1, SHA-256 , and SHA-512 checksums client-side.
-
web:cybercheck360.com
Calculate the MD5, SHA-1, SHA-256 , and SHA-512 hash of any file directly in your browser. No upload needed, hashes are computed locally.
-
web:eakondratiev.github.io
Validate your downloads quickly — check a file's integrity with a SHA‑256 checksum, or create hashes for any files using this fast, easy tool.
-
web:hashgenerator.co
Free online hash generator for text and files . Generate MD5 hashes, SHA256 hashes, SHA-512, SHA-3 and BLAKE2b checksums with HMAC support in your browser.
-
web:scanly.co
Free file hash calculator. Generate SHA-256 , SHA-512, SHA-1, and MD5 checksums for any file . Verify integrity and detect tampering in your browser.
-
web:talosintelligence.com
Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256 .
-
web:www.getzenquery.com
Verify file integrity instantly with our free online File Hash Checker. Upload any file to compute MD5, SHA-1, SHA-256 , and SHA-512 hashes—then compare with original or expected checksums. Perfect for ensuring downloaded files are intact, validating software authenticity, or detecting corruption. All processing happens locally in your browser for privacy.
-
web:www.hexhero.com
Generate secure SHA-256 hashes instantly for text and files . Client-side file hashing with auto-generation. Perfect for file verification, blockchain, and data integrity. Free online SHA256 calculator.
-
web:www.thehackerwire.com
Free Client-Side File Hash Calculator. Calculate MD5, SHA1, SHA256 , and SHA512 hashes for any file directly in your browser. No file uploads.
-
web:www.toolsley.com
Calculate the hash for any file online. Generate MD5, SHA1, SHA256 or CRC32 instantly in your browser using JavaScript. Make share-able links to validate files . No need to install anything, just drag & drop.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.