MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 34bae751324dcb623efb9c061f097d715b1d2d93587e9b0ea59017a9e5778f6e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AsyncRAT
Vendor detections: 16
| SHA256 hash: | 34bae751324dcb623efb9c061f097d715b1d2d93587e9b0ea59017a9e5778f6e |
|---|---|
| SHA3-384 hash: | 2aad900b076038c57984cecd0569fb60f6a688d5756833b5608734f36e2f52ad3bbf75ea1d504a1292166f18ced79230 |
| SHA1 hash: | e7653a59dce272f06f56a32c7aa92a1037941930 |
| MD5 hash: | caf5b7d0873fbac47a3dd246a9130ffe |
| humanhash: | video-finch-football-wisconsin |
| File name: | specification.exe |
| Download: | download sample |
| Signature | AsyncRAT |
| File size: | 750'080 bytes |
| First seen: | 2026-08-18 19:15:22 UTC |
| Last seen: | 2026-08-18 19:16:22 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'234 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger) |
| ssdeep | 12288:dQ60VEp3/P9HauMR9LTO/DnqtkbmkvorhloGv8wFYoPsnQSaaPaTZP/sUYynki7U:dQnVaurTO/DO3kvor/kNznQ+qkfi796 |
| TLSH | T1FBF412A89AE8CE15D5FA03B65E62E73617B1BD6EB211C3524FF47CFB7522B160844302 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | AsyncRAT exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Malware Config
Unpacked files
6e482ca3bf3fcc53e4e91c43c50b1720a48090f3149fe7ff760c447a37c1ef04
cb0346cf3bf9665ec445b882981d5a1d05132601c7682051b234c2a391440750
a2ae20a3dae96a9c013499dda282f8b11a1c1a9758a001c3bedbb0b2184c6650
e5cfe69cb96d8fa21b39cb4a0dc60333fa7bacc7b452ebcd8acfbf58ef0625cf
2baf8b47911e361e0adc4834de3289f162ef118ac8c4cbcab98cb662746c6be3
7cf378dd9652caf18090ef97a17f93d4ec5bfd288b4493cc94d1039f1552f848
5d82d0ccc781b34d9a93164e0a7e723293755c21d6dd0fd23479f5f951d7014b
014d90b220ae7333d1811174a381cf9bce2befbc96f3ce66a3266b28aebcc652
4c67547dfe0e49d3735287dae9596b983bc82faa75363161197640c73fe2f902
4e13359697d315c3010c7d0747349146c428913d1b5bad117630102d1cbd5e2a
003e626ae5b7daa892d5d169f4be988ed47a6338c4f4610e7bf6e803a3972291
f4233e364c6d89eb9c342d7e1647dc0c87feba66b700fd1fff0d89bd5b4a398e
4a66534fbea74b27fd7fa3262ac4d025d0f9108b20426b5cd7f8a1784affe2fd
5690a8784a72840def954a1bfa1ecc493e47d7ff013801feba99a1f75c17f30c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | ByteCode_MSIL_Backdoor_AsyncRAT |
|---|---|
| Author: | ReversingLabs |
| Description: | Yara rule that detects AsyncRAT backdoor. |
| Rule name: | Detect_PowerShell_Obfuscation |
|---|---|
| Author: | daniyyell |
| Description: | Detects obfuscated PowerShell commands commonly used in malicious scripts. |
| Rule name: | Disable_Defender |
|---|---|
| Author: | iam-py-test |
| Description: | Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA |
|---|---|
| Author: | ditekSHen |
| Description: | Detects Windows executables referencing non-Windows User-Agents |
| Rule name: | MALWARE_Win_AsyncRAT |
|---|---|
| Author: | ditekSHen |
| Description: | Detects AsyncRAT |
| Rule name: | MALWARE_Win_XWorm |
|---|---|
| Author: | ditekSHen |
| Description: | Detects XWorm |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | Njrat |
|---|---|
| Author: | botherder https://github.com/botherder |
| Description: | Njrat |
| Rule name: | pe_imphash |
|---|
| Rule name: | rat_win_xworm_v3 |
|---|---|
| Author: | Sekoia.io |
| Description: | Finds XWorm (version XClient, v3) samples based on characteristic strings |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | SUSP_DOTNET_PE_List_AV |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detecs .NET Binary that lists installed AVs |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
| Rule name: | Windows_Trojan_XWorm_b7d6eaa8 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_xworm_bytestring |
|---|---|
| Author: | Matthew @ Embee_Research |
| Description: | Detects bytestring present in unobfuscated xworm |
| Rule name: | win_xworm_w0 |
|---|---|
| Author: | jeFF0Falltrades |
| Description: | Detects win.xworm. |
| Rule name: | xworm |
|---|---|
| Author: | jeFF0Falltrades |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.