s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc high

📛 Threat Title

AsyncRAT: dekont_html.exe

Category: AsyncRAT First seen: Last updated:

Description

File type: exe. Size: 814747 bytes. Tags: AsyncRAT, exe. Reporter: threatcat_ch. First seen: 2026-05-12 09:34:25.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc VT 50 / 73

IOC database

Type
hash_sha256
Value
73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AsyncRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 73 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Injector.C5882608
Alibaba malicious Backdoor:Win64/AgentTesla.8709c5f3
alibabacloud malicious Backdoor:Win/Egairtigado.Gen
ALYac malicious Gen:Variant.AgentTesla.109
Antiy-AVL malicious Trojan[PSW]/MSIL.Agensla
Arcabit malicious Trojan.AgentTesla.109
Avast malicious Win64:BadJwrapper-A [Drp]
AVG malicious Win64:BadJwrapper-A [Drp]
Avira malicious DR/W64.BadJwrapper.A
BitDefender malicious Gen:Variant.AgentTesla.109
Bkav malicious W32.Malware.A12DB848
CrowdStrike malicious win/malicious_confidence_70% (W)
CTX malicious exe.trojan.agenttesla
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.AgentTesla.109 (B)
ESET-NOD32 malicious Win64/Kryptik.GWI trojan
F-Secure malicious Dropper.DR/W64.BadJwrapper.A
Fortinet malicious W64/Knotweed.A!tr
GData malicious Gen:Variant.AgentTesla.109
Google malicious Detected
huorong malicious Trojan/Injector.cns
K7AntiVirus malicious Password-Stealer ( 005d1cb31 )
K7GW malicious Password-Stealer ( 005d1cb31 )
Kaspersky malicious Backdoor.MSIL.XWorm.jnn
Kingsoft malicious Win32.Troj.Unknown.a
Lionic malicious Trojan.Win32.BadJwrapper.m!c
Malwarebytes malicious Trojan.AgentTesla
McAfeeD malicious Trojan:Win/Generickdz.BN
Microsoft malicious Trojan:Win64/AgentTesla.HL!MTB
MicroWorld-eScan malicious Gen:Variant.AgentTesla.109
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Spyware.Noon!8.E7C9 (TFE:5:OMS9nzD5xVQ)
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious PWS-FEFN!C64FBFE4BF22
Sophos malicious Mal/Generic-S
Symantec malicious Trojan Horse
Tencent malicious Trojan.Msil.Spy.16003938
TrellixENS malicious PWS-FEFN!C64FBFE4BF22
TrendMicro malicious Trojan.Win64.GENERICFCA.TL0101ED26ZZ
TrendMicro-HouseCall malicious Trojan.Win64.GENERICFCA.TL0101ED26ZZ
Varist malicious W64/Agent.NHFK
VBA32 malicious TrojanPSW.MSIL.Stealer
VIPRE malicious Gen:Variant.AgentTesla.109
VirIT malicious Trojan.Win64.GenusT.FUDT
ViRobot malicious Trojan.Win.Z.Kryptik.814747
Webroot malicious W32.Malware.gen
Yandex malicious Trojan.Igent.b6wWfI.7

Details From VirusTotal

Basic Properties
MD5c64fbfe4bf22012fb43c9a6f5e4b36b7
SHA-16d79432e43aa466100783d67e10bb5e1d93b3ac9
SHA-25673690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc
VHash085066656d1555551068z637z4vz
SSDEEP24576:mvFZ7RU/5ouxIxvVC22vdF4+BVDhnD23oxY9GAvP9BLBB:mZi/5FxnF4+BVda3tAAvT
TLSHT166057C16E7E416B4E63BD238CAA64633E6B678450770ADCF0258D6192F33ED06B3B315
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size795.7 KB
History
Creation date2026-05-12 00:59 UTC
First seen on VirusTotal2026-05-12 05:07 UTC
Last submission2026-06-11 09:53 UTC
Last analysis2026-06-17 10:35 UTC
Last modified on VirusTotal2026-06-18 19:06 UTC
Known Names
  • aethsync.dll
  • dekont_html.exe
  • 73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc.exe
  • software.exe
  • rxiduq.exe
  • _73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc.exe
  • tyy9ak3.exe
hash_sha1 6d79432e43aa466100783d67e10bb5e1d93b3ac9 VT 50 / 73

IOC database

Type
hash_sha1
Value
6d79432e43aa466100783d67e10bb5e1d93b3ac9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 73 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Injector.C5882608
Alibaba malicious Backdoor:Win64/AgentTesla.8709c5f3
alibabacloud malicious Backdoor:Win/Egairtigado.Gen
ALYac malicious Gen:Variant.AgentTesla.109
Antiy-AVL malicious Trojan[PSW]/MSIL.Agensla
Arcabit malicious Trojan.AgentTesla.109
Avast malicious Win64:BadJwrapper-A [Drp]
AVG malicious Win64:BadJwrapper-A [Drp]
Avira malicious DR/W64.BadJwrapper.A
BitDefender malicious Gen:Variant.AgentTesla.109
Bkav malicious W32.Malware.A12DB848
CrowdStrike malicious win/malicious_confidence_70% (W)
CTX malicious exe.trojan.agenttesla
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.AgentTesla.109 (B)
ESET-NOD32 malicious Win64/Kryptik.GWI trojan
F-Secure malicious Dropper.DR/W64.BadJwrapper.A
Fortinet malicious W64/Knotweed.A!tr
GData malicious Gen:Variant.AgentTesla.109
Google malicious Detected
huorong malicious Trojan/Injector.cns
K7AntiVirus malicious Password-Stealer ( 005d1cb31 )
K7GW malicious Password-Stealer ( 005d1cb31 )
Kaspersky malicious Backdoor.MSIL.XWorm.jnn
Kingsoft malicious Win32.Troj.Unknown.a
Lionic malicious Trojan.Win32.BadJwrapper.m!c
Malwarebytes malicious Trojan.AgentTesla
McAfeeD malicious Trojan:Win/Generickdz.BN
Microsoft malicious Trojan:Win64/AgentTesla.HL!MTB
MicroWorld-eScan malicious Gen:Variant.AgentTesla.109
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Spyware.Noon!8.E7C9 (TFE:5:OMS9nzD5xVQ)
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious PWS-FEFN!C64FBFE4BF22
Sophos malicious Mal/Generic-S
Symantec malicious Trojan Horse
Tencent malicious Trojan.Msil.Spy.16003938
TrellixENS malicious PWS-FEFN!C64FBFE4BF22
TrendMicro malicious Trojan.Win64.GENERICFCA.TL0101ED26ZZ
TrendMicro-HouseCall malicious Trojan.Win64.GENERICFCA.TL0101ED26ZZ
Varist malicious W64/Agent.NHFK
VBA32 malicious TrojanPSW.MSIL.Stealer
VIPRE malicious Gen:Variant.AgentTesla.109
VirIT malicious Trojan.Win64.GenusT.FUDT
ViRobot malicious Trojan.Win.Z.Kryptik.814747
Webroot malicious W32.Malware.gen
Yandex malicious Trojan.Igent.b6wWfI.7

Details From VirusTotal

Basic Properties
MD5c64fbfe4bf22012fb43c9a6f5e4b36b7
SHA-16d79432e43aa466100783d67e10bb5e1d93b3ac9
SHA-25673690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc
VHash085066656d1555551068z637z4vz
SSDEEP24576:mvFZ7RU/5ouxIxvVC22vdF4+BVDhnD23oxY9GAvP9BLBB:mZi/5FxnF4+BVda3tAAvT
TLSHT166057C16E7E416B4E63BD238CAA64633E6B678450770ADCF0258D6192F33ED06B3B315
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size795.7 KB
History
Creation date2026-05-12 00:59 UTC
First seen on VirusTotal2026-05-12 05:07 UTC
Last submission2026-06-11 09:53 UTC
Last analysis2026-06-17 10:35 UTC
Last modified on VirusTotal2026-07-03 02:30 UTC
Known Names
  • aethsync.dll
  • dekont_html.exe
  • 73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc.exe
  • software.exe
  • rxiduq.exe
  • _73690e32177b11e117d5e13867bbd6fe5e95450c71322de56dddc82bf9f0b5dc.exe
  • tyy9ak3.exe
hash_md5 c64fbfe4bf22012fb43c9a6f5e4b36b7 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c64fbfe4bf22012fb43c9a6f5e4b36b7

IOC database

Type
hash_md5
Value
c64fbfe4bf22012fb43c9a6f5e4b36b7
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/c64fbfe4bf22012fb43c9a6f5e4b36b7

hash_imphash d4652face233fd6b259d63f8abb6894f

IOC database

Type
hash_imphash
Value
d4652face233fd6b259d63f8abb6894f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page

    File type: exe. Size: 814747 bytes. Tags: AsyncRAT, exe. Reporter: threatcat_ch. First seen: 2026-05-12 09:34:25.

Remediations (10)

  • web:any.run

    AsyncRAT is a remote access trojan that observes and administers infected machines. Follow live malware statistics of this downloader and get new reports, samples, IOCs, etc.

  • web:medium.com

    This report details the analysis of a malicious software sample identified as AsyncRAT , a sophisticated Remote Access Trojan (RAT). The malware was observed employing advanced techniques to ...

  • web:www.checkpoint.com

    AsyncRAT is a family of malware commonly used in cyberattacks as a Remote Access Trojan (RAT), providing remote control to a victim's system. Once AsyncRAT malware infiltrates a system, attackers covertly execute commands, exfiltrate sensitive data, or monitor user activity in the background.

  • web:www.huntress.com

    AsyncRAT removal instructions Manually removing AsyncRAT involves identifying and terminating the malicious processes, deleting associated files, and cleaning altered registry keys. Using endpoint detection and response (EDR) solutions, such as Huntress, is strongly recommended for thorough remediation and prevention of reinfection.

  • web:www.infosecinstitute.com

    AsyncRat is one of the most popular and open-source remote access trojans. This piece of malware has been used for the last few months by professionals and cybercriminals in their activities. The more decent malicious wave of AsyncRat can escape security defenses by using a specially crafted .bat loader like other trojans, including URSA.

  • web:www.mcafee.com

    AsyncRAT , short for "Asynchronous Remote Access Trojan," is a sophisticated piece of malware designed to compromise the security of computer systems and steal sensitive information. What sets AsyncRAT apart from other malware strains is its stealthy nature, making it a formidable adversary in the world of cybersecurity.

  • web:www.microsoft.com

    Trojan:Win64/ AsyncRat is a .NET-based remote access trojan that provides threat actors with comprehensive control. The infection begins through phishing campaigns distributing malicious HTML files or ISO images.

  • web:www.pcrisk.com

    This script injects AsyncRAT , VenomRAT, or XWorm malware into legitimate processes like notepad.exe, allowing attackers to gain remote access and steal data. Update September 11, 2025 - new campaign spreading AsyncRAT has been discovered. It revealed vast improvements to the malware's infiltration process and anti-detection techniques.

  • web:www.securityscientist.net

    12 Questions and Answers About AsyncRAT (RAT) What Is AsyncRAT and Where Did It Come From? AsyncRAT is an open-source Remote Access Trojan written in C# and targeting the .NET framework. It was published on GitHub in 2019, originally framed as a legitimate remote administration tool. Within months, threat actors began repurposing it for malicious campaigns, making it one of the most widely ...

  • web:www.trendmicro.com

    The AsyncRAT campaign analyzed in this report demonstrates the increasing sophistication of threat actors in abusing legitimate services and open-source tools to evade detection and establish persistent remote access.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.