MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0384e80d3e541b243f0bd66f0ca4e346a15574039c30e25060bf0c0a7f0e5e4e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AsyncRAT
Vendor detections: 16
| SHA256 hash: | 0384e80d3e541b243f0bd66f0ca4e346a15574039c30e25060bf0c0a7f0e5e4e |
|---|---|
| SHA3-384 hash: | 8120a66629f64246df2644076ce4f31c49ed602ac028ef73df356c2aedf18bc4a8d62672ee310197f1263df75026c572 |
| SHA1 hash: | d3ca69da866842d3dc0bd2854906e90fcd1c55f5 |
| MD5 hash: | 229d2c8e2d68ee55f336d5393e2f4721 |
| humanhash: | earth-magnesium-nitrogen-red |
| File name: | 0384e80d3e541b243f0bd66f0ca4e346a15574039c30e25060bf0c0a7f0e5e4e |
| Download: | download sample |
| Signature | AsyncRAT |
| File size: | 867'328 bytes |
| First seen: | 2026-09-10 10:45:04 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'233 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger) |
| ssdeep | 24576:OQR+ioCfTGU/9xJLrM0AEBe7E1+v29DioPhD2MzX:OQRa6GU/l/A+ePcPbzX |
| TLSH | T19505F118231AE905D8464F784D72E7F45B655EC8BA50D3038EFEBEFFB875A096C05282 |
| TrID | 72.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.4% (.EXE) Win64 Executable (generic) (6522/11/2) 4.4% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Magika | pebin |
| dhash icon | 86a2e86860e8ee9a (2 x Formbook, 1 x OverlordRAT, 1 x MassLogger) |
| Reporter | |
| Tags: | AsyncRAT exe |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Malware Config
Unpacked files
396750d3837d60b8d8aa0253a5b569acfcdf872224e01ecd8f744dd73db4a850
f8a087e8bb376bde31086c42c4ba72bb5995749981e4af328e35473743814ef8
42b65197ee2dddb7b3cae26cf2d595a0f074e20e9ba0aa2efdf41d5ec3461579
9ed95464e794e9fe8b2baa4621507c8322b7eb2a3fa182f18f66a457a75a633f
3ae574a12cf7dfb2a9bb4bd4c112734ce7add39dbadab31d06cae1087350f345
80302e06b8a16f6690b194ba63b1e2876d832bb4b10d177b4e345173919e78c5
9db47d46c9411cef28cb767455f523c0ed8bfdb9cb6a087b665fdab87d7741eb
6fd53ae72adea774fa0bbdadcad880f0e171d1377c365c86a58232827828b66b
ac8d27b7a2414e9cdbac6c3e3ad9baa8e52594a0c732f551b514c3db857932cf
66d384f935d74fd0b94f60ec85895a64c4871036b3b06071d16f4204e0936b88
a06457b56de7cd6b96488bb621f899119e8de18fffb78b5c23e739b40c43f9a2
dc800f154b08d376a98b8eca1db7df6735fd2634c196b924b9ab1e1e16319002
32f850cfd77d50360a70c0f2ed66a988b91e7047d539482d46d21798a0eb8af8
0384e80d3e541b243f0bd66f0ca4e346a15574039c30e25060bf0c0a7f0e5e4e
75e36e7ee5ceb2a7eabbbcec4d3ae7498e09f21605a716098de3493299430afe
1ac1a7b392ec9ec678e4ae037a60669f8858910bb5bd57549b06d8f209294a45
0b6d0dcb1033d2eb8765146b23d0b58c39b15f1e3dae0b6251f4015de7211ab1
39ce2ed80d7db874133b15544c0033c7d964603250ba3bf26fd1e80e4803647f
515d1070878b9409f3195f47e4e5dd4fb03bba2a80b78d820871a1acf996793b
cd5d62e7ee22e00bd87533ac409b77d8387ebbd512e7e7aee4d085670e5f22c3
187aa13d50ceea33ab4aac1a72c02bcd248ca065901e71bf5ae2941ffaa0a046
d8c8f20046ae50d9fe926d237ce06fa27777b89135157013982534287a163446
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | ByteCode_MSIL_Backdoor_AsyncRAT |
|---|---|
| Author: | ReversingLabs |
| Description: | Yara rule that detects AsyncRAT backdoor. |
| Rule name: | Detect_PowerShell_Obfuscation |
|---|---|
| Author: | daniyyell |
| Description: | Detects obfuscated PowerShell commands commonly used in malicious scripts. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Windows executables referencing non-Windows User-Agents |
| Rule name: | MALWARE_Win_AsyncRAT |
|---|---|
| Author: | ditekSHen |
| Description: | Detects AsyncRAT |
| Rule name: | MALWARE_Win_XWorm |
|---|---|
| Author: | ditekSHen |
| Description: | Detects XWorm |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | Njrat |
|---|---|
| Author: | botherder https://github.com/botherder |
| Description: | Njrat |
| Rule name: | pe_imphash |
|---|
| Rule name: | rat_win_xworm_v3 |
|---|---|
| Author: | Sekoia.io |
| Description: | Finds XWorm (version XClient, v3) samples based on characteristic strings |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | SUSP_DOTNET_PE_List_AV |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detecs .NET Binary that lists installed AVs |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
| Rule name: | win_xworm_w0 |
|---|---|
| Author: | jeFF0Falltrades |
| Description: | Detects win.xworm. |
| Rule name: | xworm |
|---|---|
| Author: | jeFF0Falltrades |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.RAT King Parser (https://github.com/jeFF0Falltrades/rat_king_parser) Output:
{
"sha256": "0384e80d3e541b243f0bd66f0ca4e346a15574039c30e25060bf0c0a7f0e5e4e",
"yara_possible_family": "No match",
"key": "None",
"salt": "None",
"config": {
"obfuscated_key_1": "UnknownFolder(120)",
"obfuscated_key_2": false,
"obfuscated_key_3": false,
"obfuscated_key_4": false,
"obfuscated_key_5": false
}
}