MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1624cb659dab77b455bcd9fc0e106216cc29ae443bb3443c1fae1ea3b029f640. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 1624cb659dab77b455bcd9fc0e106216cc29ae443bb3443c1fae1ea3b029f640
SHA3-384 hash: 6386255dd0e77d94f6931f71284c30a347b77c3f30f8f61f68592883372d268b7c1beff22f8784f5d566ccc089b597b5
SHA1 hash: 33315c0906a83e46f62686ed71b6956aed30e868
MD5 hash: ff3bbc4ca5b236727a1c0cfdacc770bb
humanhash: jersey-oranges-zulu-cat
File name:sample_product inquirywa004678.hta
Download: download sample
Signature AsyncRAT
File size:1'686'072 bytes
First seen:2026-07-21 09:44:20 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/plain
ssdeep 192:5pxIahuv6OeK6LVLqvsbzRVX/Al8/Zmr7:5b9huvitJqvsbzRta8Qr7
TLSH T1087515E74ED8C483F4252626DE099034FA7287627EFF266F70F376885B21055886C9F6
Magika txt
Reporter JAMESWT_WT
Tags:AsyncRAT hta

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
shell spawn sage
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
https://pub-e17adc2984a64a2f8f2a3f402fd92e53.r2.dev/ikzwhpl.png
HTA File
Behaviour
BlacklistAPI detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
js
First seen:
2026-07-15T21:33:00Z UTC
Last seen:
2026-07-22T08:06:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Html
Threat name:
Script-JS.Trojan.Acsogenixx
Status:
Malicious
First seen:
2026-07-21 10:53:26 UTC
File Type:
Binary
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
asyncrat
Score:
  10/10
Tags:
family:asyncrat botnet:default discovery execution persistence rat suricata
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: PowerShell
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Badlisted process makes network request
Family: AsyncRat
Process spawned unexpected child process
Suricata alert: AsyncRAT Malware Default X.509 Certificate Detected - Inbound
Malware Config
C2 Extraction:
contabili.balanteo.shop:6606
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments