MB-270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608
high
📛 Threat Title
AsyncRAT: WinRar.exe
Description
File type: exe. Size: 119808 bytes. Tags: AsyncRAT, botnet, c2, exe, trojan. Reporter: VTR. First seen: 2026-05-11 02:10:22.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
winrar.exe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/winrar.exe
IOC database
- Type
- domain
- Value
winrar.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/winrar.exe
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 650 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608
VT 55 / 75
IOC database
- Type
- hash_sha256
- Value
270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- AsyncRAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 55 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.RL_Generic.C3546893 |
| Alibaba | malicious | Backdoor:MSIL/AsyncRat.ddd2ad59 |
| alibabacloud | malicious | Rat:Win/AsyncRAT.Stub |
| ALYac | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.Crysan |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| Avast | malicious | MSIL:AsyncRat-E [Pws] |
| AVG | malicious | MSIL:AsyncRat-E [Pws] |
| Avira | malicious | TR/AsyncRat.E |
| BitDefender | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| Bkav | malicious | W32.Malware.98EBB272 |
| CAT-QuickHeal | malicious | Backdoor.MsilFC.S13564499 |
| ClamAV | malicious | Win.Packed.Razy-9625918-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Siggen9.56514 |
| Elastic | malicious | Windows.Generic.Threat |
| Emsisoft | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 (B) |
| ESET-NOD32 | malicious | MSIL/AsyncRAT.A trojan |
| F-Secure | malicious | Trojan.TR/AsyncRat.E |
| Fortinet | malicious | MSIL/AsyncRAT.A!tr |
| GData | malicious | MSIL.Backdoor.DCRat.D |
| huorong | malicious | Backdoor/MSIL.DcRat.a |
| Jiangmin | malicious | Backdoor.MSIL.cxnh |
| K7AntiVirus | malicious | Trojan ( 005678321 ) |
| K7GW | malicious | Trojan ( 005678321 ) |
| Kaspersky | malicious | HEUR:Backdoor.MSIL.Crysan.gen |
| Kingsoft | malicious | MSIL.Backdoor.Crysan.gen |
| Lionic | malicious | Trojan.Win32.AsyncRAT.m!c |
| Malwarebytes | malicious | Generic.Trojan.MSIL.DDS |
| McAfeeD | malicious | Trojan:Win/Generic.BCX |
| Microsoft | malicious | Backdoor:MSIL/AsyncRat!atmn |
| MicroWorld-eScan | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| NANO-Antivirus | malicious | Trojan.Win32.AsyncRAT.lhffai |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Trojan.AntiVM!1.CF63 (CLASSIC) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Sophos | malicious | Troj/AsyncRat-B |
| Symantec | malicious | Backdoor.ASync!g2 |
| Tencent | malicious | Trojan.Msil.Agent.zap |
| TrellixENS | malicious | Fareit-FZT!A7B1BD2E7A92 |
| TrendMicro | malicious | Backdoor.MSIL.ASYNCRAT.TL0101EC26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/MSIL_Kryptik.DOD.gen!Eldorado |
| VBA32 | malicious | OScope.Backdoor.MSIL.Crysan |
| VIPRE | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| ViRobot | malicious | Trojan.Win.Z.Asyncrat.119808.P |
| Xcitium | malicious | Malware@#3bu5cc7tk6wwp |
| ZoneAlarm | malicious | Troj/AsyncRat-B |
Details From VirusTotal
Basic Properties
| MD5 | a7b1bd2e7a92deb5c1e11d56ca4d9461 |
| SHA-1 | 4d3d2852e42ba4c14289848b11ff39dbdc209c93 |
| SHA-256 | 270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608 |
| VHash | 215036557511d08d2e1d104d |
| SSDEEP | 3072:9ugoyTPPj2F3cv3bGoXu9BeF+YzB1hXeiYY0I26QqAN:9ugocyyv3bwBeYA/mIBpm |
| TLSH | T1B0C3B0043BD8C466F2AD4F789DF25245867EE9B73E03D94B1C84328B1623FC55B42AB9 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 117.0 KB |
History
| Creation date | 2020-05-10 05:24 UTC |
| First seen on VirusTotal | 2026-05-11 02:12 UTC |
| Last submission | 2026-05-11 02:12 UTC |
| Last analysis | 2026-06-04 06:04 UTC |
| Last modified on VirusTotal | 2026-06-04 08:37 UTC |
Known Names
WinRAR270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608.exegc31o.exeWinRar.exe
hash_sha1
4d3d2852e42ba4c14289848b11ff39dbdc209c93
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4d3d2852e42ba4c14289848b11ff39dbdc209c93
IOC database
- Type
- hash_sha1
- Value
4d3d2852e42ba4c14289848b11ff39dbdc209c93- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4d3d2852e42ba4c14289848b11ff39dbdc209c93
hash_md5
a7b1bd2e7a92deb5c1e11d56ca4d9461
VT 55 / 75
IOC database
- Type
- hash_md5
- Value
a7b1bd2e7a92deb5c1e11d56ca4d9461- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 55 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.RL_Generic.C3546893 |
| Alibaba | malicious | Backdoor:MSIL/AsyncRat.ddd2ad59 |
| alibabacloud | malicious | Rat:Win/AsyncRAT.Stub |
| ALYac | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| Antiy-AVL | malicious | Trojan[Backdoor]/MSIL.Crysan |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| Avast | malicious | MSIL:AsyncRat-E [Pws] |
| AVG | malicious | MSIL:AsyncRat-E [Pws] |
| Avira | malicious | TR/AsyncRat.E |
| BitDefender | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| Bkav | malicious | W32.Malware.98EBB272 |
| CAT-QuickHeal | malicious | Backdoor.MsilFC.S13564499 |
| ClamAV | malicious | Win.Packed.Razy-9625918-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Siggen9.56514 |
| Elastic | malicious | Windows.Generic.Threat |
| Emsisoft | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 (B) |
| ESET-NOD32 | malicious | MSIL/AsyncRAT.A trojan |
| F-Secure | malicious | Trojan.TR/AsyncRat.E |
| Fortinet | malicious | MSIL/AsyncRAT.A!tr |
| GData | malicious | MSIL.Backdoor.DCRat.D |
| huorong | malicious | Backdoor/MSIL.DcRat.a |
| Jiangmin | malicious | Backdoor.MSIL.cxnh |
| K7AntiVirus | malicious | Trojan ( 005678321 ) |
| K7GW | malicious | Trojan ( 005678321 ) |
| Kaspersky | malicious | HEUR:Backdoor.MSIL.Crysan.gen |
| Kingsoft | malicious | MSIL.Backdoor.Crysan.gen |
| Lionic | malicious | Trojan.Win32.AsyncRAT.m!c |
| Malwarebytes | malicious | Generic.Trojan.MSIL.DDS |
| McAfeeD | malicious | Trojan:Win/Generic.BCX |
| Microsoft | malicious | Backdoor:MSIL/AsyncRat!atmn |
| MicroWorld-eScan | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| NANO-Antivirus | malicious | Trojan.Win32.AsyncRAT.lhffai |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Trojan.AntiVM!1.CF63 (CLASSIC) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Sophos | malicious | Troj/AsyncRat-B |
| Symantec | malicious | Backdoor.ASync!g2 |
| Tencent | malicious | Trojan.Msil.Agent.zap |
| TrellixENS | malicious | Fareit-FZT!A7B1BD2E7A92 |
| TrendMicro | malicious | Backdoor.MSIL.ASYNCRAT.TL0101EC26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/MSIL_Kryptik.DOD.gen!Eldorado |
| VBA32 | malicious | OScope.Backdoor.MSIL.Crysan |
| VIPRE | malicious | Generic.AsyncRAT.Marte.B.46F5AC20 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| ViRobot | malicious | Trojan.Win.Z.Asyncrat.119808.P |
| Xcitium | malicious | Malware@#3bu5cc7tk6wwp |
| ZoneAlarm | malicious | Troj/AsyncRat-B |
Details From VirusTotal
Basic Properties
| MD5 | a7b1bd2e7a92deb5c1e11d56ca4d9461 |
| SHA-1 | 4d3d2852e42ba4c14289848b11ff39dbdc209c93 |
| SHA-256 | 270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608 |
| VHash | 215036557511d08d2e1d104d |
| SSDEEP | 3072:9ugoyTPPj2F3cv3bGoXu9BeF+YzB1hXeiYY0I26QqAN:9ugocyyv3bwBeYA/mIBpm |
| TLSH | T1B0C3B0043BD8C466F2AD4F789DF25245867EE9B73E03D94B1C84328B1623FC55B42AB9 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 117.0 KB |
History
| Creation date | 2020-05-10 05:24 UTC |
| First seen on VirusTotal | 2026-05-11 02:12 UTC |
| Last submission | 2026-05-11 02:12 UTC |
| Last analysis | 2026-06-04 06:04 UTC |
| Last modified on VirusTotal | 2026-06-04 08:37 UTC |
Known Names
WinRAR270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608.exegc31o.exeWinRar.exe
References (1)
-
MalwareBazaar sample page
File type: exe. Size: 119808 bytes. Tags: AsyncRAT, botnet, c2, exe, trojan. Reporter: VTR. First seen: 2026-05-11 02:10:22.
Remediations (9)
-
web:any.run
Online sandbox report for AsyncRAT .rar, tagged as asyncrat , verdict: Malicious activity
-
web:blog.qualys.com
WinRAR CVE-2025-8088 is actively exploited. Learn how Qualys TruRisk™ Eliminate helps patch, mitigate, or uninstall vulnerable versions fast, in one platform.
-
web:cyble.com
This file exploits a WinRAR vulnerability to deliver various malicious payloads to the victim's system. This particular campaign appears to target individuals who engage in viewing/downloading Illicit images and videos, aiming to infect them using various malware types, such as Apanyan Stealer, The Murk-Stealer, and AsyncRAT .
-
web:dailysecurityreview.com
The vulnerability stems from WinRAR's handling of symlinks pointing to executables. As stated in the WinRAR changelog: "If symlink pointing at an executable was started from WinRAR shell, the executable Mark of the Web data was ignored." This oversight allows attackers to circumvent the security warning entirely. Severity and Remediation
-
web:securityarsenal.com
Security teams must act: Learn how to detect and remediate the WinRAR vulnerability exploited in recent Amaranth-Dragon campaigns.
-
web:thehackernews.com
CISA warns WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal fixes by Dec. 30, 2025.
-
web:www.cirt.gov.bd
Analysis confirms that the malware payload masquerades as a WinRAR utility executable (winrar-x64.exe), while internally functioning as AsyncRAT v0.5.8, enabling full remote control over infected systems. Bangladesh Threat Context The campaign presents elevated risk to Bangladesh due to localized targeting characteristics. Observed indicators ...
-
web:www.pcrisk.com
This script injects AsyncRAT , VenomRAT, or XWorm malware into legitimate processes like notepad.exe, allowing attackers to gain remote access and steal data. Update September 11, 2025 - new campaign spreading AsyncRAT has been discovered. It revealed vast improvements to the malware's infiltration process and anti-detection techniques.
-
web:www.vicarius.io
This PowerShell script applies a non-patch workaround for CVE-2025-8088 in WinRAR by combining Software Restriction Policies (SRP) with Image File Execution Options (IFEO) to block winrar.exe , rar.exe, and unrar.exe—even if SRP is bypassed.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.