s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608 high

📛 Threat Title

AsyncRAT: WinRar.exe

Category: AsyncRAT First seen: Last updated:

Description

File type: exe. Size: 119808 bytes. Tags: AsyncRAT, botnet, c2, exe, trojan. Reporter: VTR. First seen: 2026-05-11 02:10:22.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain winrar.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/winrar.exe

IOC database

Type
domain
Value
winrar.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/winrar.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
650 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608 VT 55 / 75

IOC database

Type
hash_sha256
Value
270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 55 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.RL_Generic.C3546893
Alibaba malicious Backdoor:MSIL/AsyncRat.ddd2ad59
alibabacloud malicious Rat:Win/AsyncRAT.Stub
ALYac malicious Generic.AsyncRAT.Marte.B.46F5AC20
Antiy-AVL malicious Trojan[Backdoor]/MSIL.Crysan
APEX malicious Malicious
Arcabit malicious Generic.AsyncRAT.Marte.B.46F5AC20
Avast malicious MSIL:AsyncRat-E [Pws]
AVG malicious MSIL:AsyncRat-E [Pws]
Avira malicious TR/AsyncRat.E
BitDefender malicious Generic.AsyncRAT.Marte.B.46F5AC20
Bkav malicious W32.Malware.98EBB272
CAT-QuickHeal malicious Backdoor.MsilFC.S13564499
ClamAV malicious Win.Packed.Razy-9625918-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Siggen9.56514
Elastic malicious Windows.Generic.Threat
Emsisoft malicious Generic.AsyncRAT.Marte.B.46F5AC20 (B)
ESET-NOD32 malicious MSIL/AsyncRAT.A trojan
F-Secure malicious Trojan.TR/AsyncRat.E
Fortinet malicious MSIL/AsyncRAT.A!tr
GData malicious MSIL.Backdoor.DCRat.D
huorong malicious Backdoor/MSIL.DcRat.a
Jiangmin malicious Backdoor.MSIL.cxnh
K7AntiVirus malicious Trojan ( 005678321 )
K7GW malicious Trojan ( 005678321 )
Kaspersky malicious HEUR:Backdoor.MSIL.Crysan.gen
Kingsoft malicious MSIL.Backdoor.Crysan.gen
Lionic malicious Trojan.Win32.AsyncRAT.m!c
Malwarebytes malicious Generic.Trojan.MSIL.DDS
McAfeeD malicious Trojan:Win/Generic.BCX
Microsoft malicious Backdoor:MSIL/AsyncRat!atmn
MicroWorld-eScan malicious Generic.AsyncRAT.Marte.B.46F5AC20
NANO-Antivirus malicious Trojan.Win32.AsyncRAT.lhffai
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
Rising malicious Trojan.AntiVM!1.CF63 (CLASSIC)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Sophos malicious Troj/AsyncRat-B
Symantec malicious Backdoor.ASync!g2
Tencent malicious Trojan.Msil.Agent.zap
TrellixENS malicious Fareit-FZT!A7B1BD2E7A92
TrendMicro malicious Backdoor.MSIL.ASYNCRAT.TL0101EC26ZZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/MSIL_Kryptik.DOD.gen!Eldorado
VBA32 malicious OScope.Backdoor.MSIL.Crysan
VIPRE malicious Generic.AsyncRAT.Marte.B.46F5AC20
VirIT malicious Trojan.Win32.MSIL_Heur.A
ViRobot malicious Trojan.Win.Z.Asyncrat.119808.P
Xcitium malicious Malware@#3bu5cc7tk6wwp
ZoneAlarm malicious Troj/AsyncRat-B

Details From VirusTotal

Basic Properties
MD5a7b1bd2e7a92deb5c1e11d56ca4d9461
SHA-14d3d2852e42ba4c14289848b11ff39dbdc209c93
SHA-256270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608
VHash215036557511d08d2e1d104d
SSDEEP3072:9ugoyTPPj2F3cv3bGoXu9BeF+YzB1hXeiYY0I26QqAN:9ugocyyv3bwBeYA/mIBpm
TLSHT1B0C3B0043BD8C466F2AD4F789DF25245867EE9B73E03D94B1C84328B1623FC55B42AB9
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size117.0 KB
History
Creation date2020-05-10 05:24 UTC
First seen on VirusTotal2026-05-11 02:12 UTC
Last submission2026-05-11 02:12 UTC
Last analysis2026-06-04 06:04 UTC
Last modified on VirusTotal2026-06-04 08:37 UTC
Known Names
  • WinRAR
  • 270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608.exe
  • gc31o.exe
  • WinRar.exe
hash_sha1 4d3d2852e42ba4c14289848b11ff39dbdc209c93 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4d3d2852e42ba4c14289848b11ff39dbdc209c93

IOC database

Type
hash_sha1
Value
4d3d2852e42ba4c14289848b11ff39dbdc209c93
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4d3d2852e42ba4c14289848b11ff39dbdc209c93

hash_md5 a7b1bd2e7a92deb5c1e11d56ca4d9461 VT 55 / 75

IOC database

Type
hash_md5
Value
a7b1bd2e7a92deb5c1e11d56ca4d9461
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 55 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.RL_Generic.C3546893
Alibaba malicious Backdoor:MSIL/AsyncRat.ddd2ad59
alibabacloud malicious Rat:Win/AsyncRAT.Stub
ALYac malicious Generic.AsyncRAT.Marte.B.46F5AC20
Antiy-AVL malicious Trojan[Backdoor]/MSIL.Crysan
APEX malicious Malicious
Arcabit malicious Generic.AsyncRAT.Marte.B.46F5AC20
Avast malicious MSIL:AsyncRat-E [Pws]
AVG malicious MSIL:AsyncRat-E [Pws]
Avira malicious TR/AsyncRat.E
BitDefender malicious Generic.AsyncRAT.Marte.B.46F5AC20
Bkav malicious W32.Malware.98EBB272
CAT-QuickHeal malicious Backdoor.MsilFC.S13564499
ClamAV malicious Win.Packed.Razy-9625918-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Siggen9.56514
Elastic malicious Windows.Generic.Threat
Emsisoft malicious Generic.AsyncRAT.Marte.B.46F5AC20 (B)
ESET-NOD32 malicious MSIL/AsyncRAT.A trojan
F-Secure malicious Trojan.TR/AsyncRat.E
Fortinet malicious MSIL/AsyncRAT.A!tr
GData malicious MSIL.Backdoor.DCRat.D
huorong malicious Backdoor/MSIL.DcRat.a
Jiangmin malicious Backdoor.MSIL.cxnh
K7AntiVirus malicious Trojan ( 005678321 )
K7GW malicious Trojan ( 005678321 )
Kaspersky malicious HEUR:Backdoor.MSIL.Crysan.gen
Kingsoft malicious MSIL.Backdoor.Crysan.gen
Lionic malicious Trojan.Win32.AsyncRAT.m!c
Malwarebytes malicious Generic.Trojan.MSIL.DDS
McAfeeD malicious Trojan:Win/Generic.BCX
Microsoft malicious Backdoor:MSIL/AsyncRat!atmn
MicroWorld-eScan malicious Generic.AsyncRAT.Marte.B.46F5AC20
NANO-Antivirus malicious Trojan.Win32.AsyncRAT.lhffai
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
Rising malicious Trojan.AntiVM!1.CF63 (CLASSIC)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Sophos malicious Troj/AsyncRat-B
Symantec malicious Backdoor.ASync!g2
Tencent malicious Trojan.Msil.Agent.zap
TrellixENS malicious Fareit-FZT!A7B1BD2E7A92
TrendMicro malicious Backdoor.MSIL.ASYNCRAT.TL0101EC26ZZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/MSIL_Kryptik.DOD.gen!Eldorado
VBA32 malicious OScope.Backdoor.MSIL.Crysan
VIPRE malicious Generic.AsyncRAT.Marte.B.46F5AC20
VirIT malicious Trojan.Win32.MSIL_Heur.A
ViRobot malicious Trojan.Win.Z.Asyncrat.119808.P
Xcitium malicious Malware@#3bu5cc7tk6wwp
ZoneAlarm malicious Troj/AsyncRat-B

Details From VirusTotal

Basic Properties
MD5a7b1bd2e7a92deb5c1e11d56ca4d9461
SHA-14d3d2852e42ba4c14289848b11ff39dbdc209c93
SHA-256270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608
VHash215036557511d08d2e1d104d
SSDEEP3072:9ugoyTPPj2F3cv3bGoXu9BeF+YzB1hXeiYY0I26QqAN:9ugocyyv3bwBeYA/mIBpm
TLSHT1B0C3B0043BD8C466F2AD4F789DF25245867EE9B73E03D94B1C84328B1623FC55B42AB9
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size117.0 KB
History
Creation date2020-05-10 05:24 UTC
First seen on VirusTotal2026-05-11 02:12 UTC
Last submission2026-05-11 02:12 UTC
Last analysis2026-06-04 06:04 UTC
Last modified on VirusTotal2026-06-04 08:37 UTC
Known Names
  • WinRAR
  • 270887cd3939ea9eb91d47ce5eeedd4141cb112501d42844020e496c76384608.exe
  • gc31o.exe
  • WinRar.exe

References (1)

  • MalwareBazaar sample page

    File type: exe. Size: 119808 bytes. Tags: AsyncRAT, botnet, c2, exe, trojan. Reporter: VTR. First seen: 2026-05-11 02:10:22.

Remediations (9)

  • web:any.run

    Online sandbox report for AsyncRAT .rar, tagged as asyncrat , verdict: Malicious activity

  • web:blog.qualys.com

    WinRAR CVE-2025-8088 is actively exploited. Learn how Qualys TruRisk™ Eliminate helps patch, mitigate, or uninstall vulnerable versions fast, in one platform.

  • web:cyble.com

    This file exploits a WinRAR vulnerability to deliver various malicious payloads to the victim's system. This particular campaign appears to target individuals who engage in viewing/downloading Illicit images and videos, aiming to infect them using various malware types, such as Apanyan Stealer, The Murk-Stealer, and AsyncRAT .

  • web:dailysecurityreview.com

    The vulnerability stems from WinRAR's handling of symlinks pointing to executables. As stated in the WinRAR changelog: "If symlink pointing at an executable was started from WinRAR shell, the executable Mark of the Web data was ignored." This oversight allows attackers to circumvent the security warning entirely. Severity and Remediation

  • web:securityarsenal.com

    Security teams must act: Learn how to detect and remediate the WinRAR vulnerability exploited in recent Amaranth-Dragon campaigns.

  • web:thehackernews.com

    CISA warns WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal fixes by Dec. 30, 2025.

  • web:www.cirt.gov.bd

    Analysis confirms that the malware payload masquerades as a WinRAR utility executable (winrar-x64.exe), while internally functioning as AsyncRAT v0.5.8, enabling full remote control over infected systems. Bangladesh Threat Context The campaign presents elevated risk to Bangladesh due to localized targeting characteristics. Observed indicators ...

  • web:www.pcrisk.com

    This script injects AsyncRAT , VenomRAT, or XWorm malware into legitimate processes like notepad.exe, allowing attackers to gain remote access and steal data. Update September 11, 2025 - new campaign spreading AsyncRAT has been discovered. It revealed vast improvements to the malware's infiltration process and anti-detection techniques.

  • web:www.vicarius.io

    This PowerShell script applies a non-patch workaround for CVE-2025-8088 in WinRAR by combining Software Restriction Policies (SRP) with Image File Execution Options (IFEO) to block winrar.exe , rar.exe, and unrar.exe—even if SRP is bypassed.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.