MB-103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7
high
📛 Threat Title
AsyncRAT: Telegram (1).exe
Description
File type: exe. Size: 114688 bytes. Tags: AsyncRAT, c2, DCRat, exe, RAT, windows. Reporter: anonymous. First seen: 2026-05-08 17:59:02.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 650 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7
IOC database
- Type
- hash_sha256
- Value
103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- AsyncRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7
hash_sha1
d93d360643cd95ca8b2f2bbcf61b2fec5dc208f0
VT 58 / 75
IOC database
- Type
- hash_sha1
- Value
d93d360643cd95ca8b2f2bbcf61b2fec5dc208f0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 58 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.RL_Generic.R358277 |
| Alibaba | malicious | Backdoor:MSIL/AsyncRat.e0ffb617 |
| alibabacloud | malicious | Rat:Win/AsyncRAT.Stub |
| ALYac | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.Crysan |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| Avast | malicious | MSIL:AsyncRat-E [Pws] |
| AVG | malicious | MSIL:AsyncRat-E [Pws] |
| Avira | malicious | TR/AsyncRat.E |
| BitDefender | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| Bkav | malicious | W32.Malware.CDC4A7C5 |
| CAT-QuickHeal | malicious | Backdoor.MsilFC.S13564499 |
| ClamAV | malicious | Win.Packed.Razy-9625918-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Siggen9.56514 |
| Elastic | malicious | Windows.Generic.Threat |
| Emsisoft | malicious | Generic.AsyncRAT.Marte.B.32E55F98 (B) |
| ESET-NOD32 | malicious | MSIL/AsyncRAT.A trojan |
| F-Secure | malicious | Trojan.TR/AsyncRat.E |
| Fortinet | malicious | MSIL/AsyncRAT.A!tr |
| GData | malicious | MSIL.Backdoor.DCRat.D |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win32.Packed.sa |
| huorong | malicious | Backdoor/MSIL.DcRat.a |
| K7AntiVirus | malicious | Trojan ( 005678321 ) |
| K7GW | malicious | Trojan ( 005678321 ) |
| Kaspersky | malicious | HEUR:Backdoor.MSIL.Crysan.gen |
| Kingsoft | malicious | MSIL.Backdoor.Crysan.gen |
| Lionic | malicious | Trojan.Win32.AsyncRAT.m!c |
| Malwarebytes | malicious | Generic.Trojan.MSIL.DDS |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!B669F2D36B0B |
| Microsoft | malicious | Backdoor:MSIL/AsyncRat!atmn |
| MicroWorld-eScan | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| NANO-Antivirus | malicious | Trojan.Win32.AsyncRAT.lhhviy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Trojan.AntiVM!1.CF63 (CLASSIC) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Fareit-FZT!B669F2D36B0B |
| Sophos | malicious | Troj/AsyncRat-B |
| Symantec | malicious | Backdoor.ASync!g2 |
| Tencent | malicious | Trojan.Msil.Agent.zap |
| Trapmine | malicious | malicious.moderate.ml.score |
| TrellixENS | malicious | Fareit-FZT!B669F2D36B0B |
| TrendMicro | malicious | Backdoor.MSIL.ASYNCRAT.TL0101E926ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/MSIL_Kryptik.DOD.gen!Eldorado |
| VBA32 | malicious | OScope.Backdoor.MSIL.Crysan |
| VIPRE | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| ViRobot | malicious | Trojan.Win.Z.Asyncrat.114688.D |
| ZoneAlarm | malicious | Troj/AsyncRat-B |
Details From VirusTotal
Basic Properties
| MD5 | b669f2d36b0b71f614751ed3c4486c0b |
| SHA-1 | d93d360643cd95ca8b2f2bbcf61b2fec5dc208f0 |
| SHA-256 | 103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7 |
| VHash | 215036555511d08d2e1d104d |
| SSDEEP | 1536:Aub+dT5Pk2ukBdUY3bcXSRE8DET/BdImW7DB5NRlmMGCCz:AubyT5Pk2tBGY3bciAbBod+z |
| TLSH | T172B32049E919485DE82D0E7C6CF3A45606D5BF37E508ABC50CDCB8CFAA33A820EC5759 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 112.0 KB |
History
| Creation date | 2026-05-08 13:36 UTC |
| First seen on VirusTotal | 2026-05-08 17:58 UTC |
| Last submission | 2026-05-12 08:17 UTC |
| Last analysis | 2026-06-07 06:04 UTC |
| Last modified on VirusTotal | 2026-06-17 21:03 UTC |
Known Names
Telegram.exenviymvqk.exe103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7 2.exe103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7 3.exey2bx6uu4b.exeTelegram (1).exe
hash_md5
b669f2d36b0b71f614751ed3c4486c0b
VT 58 / 75
IOC database
- Type
- hash_md5
- Value
b669f2d36b0b71f614751ed3c4486c0b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 58 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.RL_Generic.R358277 |
| Alibaba | malicious | Backdoor:MSIL/AsyncRat.e0ffb617 |
| alibabacloud | malicious | Rat:Win/AsyncRAT.Stub |
| ALYac | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.Crysan |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| Avast | malicious | MSIL:AsyncRat-E [Pws] |
| AVG | malicious | MSIL:AsyncRat-E [Pws] |
| Avira | malicious | TR/AsyncRat.E |
| BitDefender | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| Bkav | malicious | W32.Malware.CDC4A7C5 |
| CAT-QuickHeal | malicious | Backdoor.MsilFC.S13564499 |
| ClamAV | malicious | Win.Packed.Razy-9625918-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Siggen9.56514 |
| Elastic | malicious | Windows.Generic.Threat |
| Emsisoft | malicious | Generic.AsyncRAT.Marte.B.32E55F98 (B) |
| ESET-NOD32 | malicious | MSIL/AsyncRAT.A trojan |
| F-Secure | malicious | Trojan.TR/AsyncRat.E |
| Fortinet | malicious | MSIL/AsyncRAT.A!tr |
| GData | malicious | MSIL.Backdoor.DCRat.D |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win32.Packed.sa |
| huorong | malicious | Backdoor/MSIL.DcRat.a |
| K7AntiVirus | malicious | Trojan ( 005678321 ) |
| K7GW | malicious | Trojan ( 005678321 ) |
| Kaspersky | malicious | HEUR:Backdoor.MSIL.Crysan.gen |
| Kingsoft | malicious | MSIL.Backdoor.Crysan.gen |
| Lionic | malicious | Trojan.Win32.AsyncRAT.m!c |
| Malwarebytes | malicious | Generic.Trojan.MSIL.DDS |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!B669F2D36B0B |
| Microsoft | malicious | Backdoor:MSIL/AsyncRat!atmn |
| MicroWorld-eScan | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| NANO-Antivirus | malicious | Trojan.Win32.AsyncRAT.lhhviy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Trojan.AntiVM!1.CF63 (CLASSIC) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Fareit-FZT!B669F2D36B0B |
| Sophos | malicious | Troj/AsyncRat-B |
| Symantec | malicious | Backdoor.ASync!g2 |
| Tencent | malicious | Trojan.Msil.Agent.zap |
| Trapmine | malicious | malicious.moderate.ml.score |
| TrellixENS | malicious | Fareit-FZT!B669F2D36B0B |
| TrendMicro | malicious | Backdoor.MSIL.ASYNCRAT.TL0101E926ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/MSIL_Kryptik.DOD.gen!Eldorado |
| VBA32 | malicious | OScope.Backdoor.MSIL.Crysan |
| VIPRE | malicious | Generic.AsyncRAT.Marte.B.32E55F98 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| ViRobot | malicious | Trojan.Win.Z.Asyncrat.114688.D |
| ZoneAlarm | malicious | Troj/AsyncRat-B |
Details From VirusTotal
Basic Properties
| MD5 | b669f2d36b0b71f614751ed3c4486c0b |
| SHA-1 | d93d360643cd95ca8b2f2bbcf61b2fec5dc208f0 |
| SHA-256 | 103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7 |
| VHash | 215036555511d08d2e1d104d |
| SSDEEP | 1536:Aub+dT5Pk2ukBdUY3bcXSRE8DET/BdImW7DB5NRlmMGCCz:AubyT5Pk2tBGY3bciAbBod+z |
| TLSH | T172B32049E919485DE82D0E7C6CF3A45606D5BF37E508ABC50CDCB8CFAA33A820EC5759 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 112.0 KB |
History
| Creation date | 2026-05-08 13:36 UTC |
| First seen on VirusTotal | 2026-05-08 17:58 UTC |
| Last submission | 2026-05-12 08:17 UTC |
| Last analysis | 2026-06-07 06:04 UTC |
| Last modified on VirusTotal | 2026-06-09 08:57 UTC |
Known Names
Telegram.exenviymvqk.exe103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7 2.exe103bf7cda93749567f7e16e48cd205fd059fdda7f7396a781c6e4a096a3b47d7 3.exey2bx6uu4b.exeTelegram (1).exe
References (1)
-
MalwareBazaar sample page
File type: exe. Size: 114688 bytes. Tags: AsyncRAT, c2, DCRat, exe, RAT, windows. Reporter: anonymous. First seen: 2026-05-08 17:59:02.
Remediations (10)
-
web:any.run
AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.
-
web:bazaar.abuse.ch
Information on AsyncRAT malware sample (SHA256 5ca468704e7ccb8e1b37c0f7595c54df4e2f4035345b6e442e8bd4e11c58f791) MalwareBazaar uses YARA rules from several public and ...
-
web:t.me
Analysis of Yurei ransomware reveals its functionality, such as dropping a README file post-encryption and including sdelete, a tool for securely erasing evidence of attacks. Interestingly, a file named w.exe, commonly associated with Akira ransomware, was also found, suggesting potential overlaps in tool usage between ransomware groups.
-
web:thehackernews.com
The script then establishes persistence on the system, gathers and exfiltrates system information to a Telegram bot, takes a screenshot, and ultimately launches the AsyncRAT payload by injecting it into the "aspnet_compiler.exe" executable.
-
web:threatchain.hashnode.dev
AsyncRAT samples are typically distributed through phishing emails, malvertising, fake software downloads, or cracked installers. Once executed, the malware usually establishes persistence on the host, harvests credentials and sensitive data, and establishes an outbound channel to command-and-control infrastructure operated by the attackers.
-
web:www.checkpoint.com
AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background.
-
web:www.huntress.com
AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.
-
web:www.microsoft.com
The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.
-
web:www.pcrisk.com
This script injects AsyncRAT , VenomRAT, or XWorm malware into legitimate processes like notepad.exe, allowing attackers to gain remote access and steal data. Update September 11, 2025 - new campaign spreading AsyncRAT has been discovered. It revealed vast improvements to the malware's infiltration process and anti-detection techniques.
-
web:www.trendmicro.com
The AsyncRAT campaign analyzed in this report demonstrates the increasing sophistication of threat actors in abusing legitimate services and open-source tools to evade detection and establish persistent remote access.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.