MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3565a7a2bb632357c35f6ca9e98eb083e1505526f0ab0e4d88df216299540069. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 3565a7a2bb632357c35f6ca9e98eb083e1505526f0ab0e4d88df216299540069
SHA3-384 hash: 2ca4de082a9e44077fec2f22df437fbaa72239eb82855b324b701dcdfe1555f51a5f211014c014f22ed5ec77d7ae9b38
SHA1 hash: e22c05e7ec4147eddeab8abd5ac5a10d6e3efae9
MD5 hash: 83d9bf538d7809c98f331d469b48e083
humanhash: wolfram-august-ten-pizza
File name:rar.rar
Download: download sample
Signature AsyncRAT
File size:3'344 bytes
First seen:2026-07-21 09:44:07 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 48:Gzjb9HUQx3p1Djrg5CViZcqSKCCEhwT9AKgIsm5HfPVgg1RyG8juo+4Agj3Q:GzjJ0q574t6wJzXsm/PV9h8juo+4RA
TLSH T137614CEA743BE608E9551BB2416FE490B6853CB93DB57A79F4BB03028D7C454082F1F2
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter JAMESWT_WT
Tags:AsyncRAT ikzwhpl rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:sample_product inquirywa004678.hta
File size:1'686'072 bytes
SHA256 hash: 1624cb659dab77b455bcd9fc0e106216cc29ae443bb3443c1fae1ea3b029f640
MD5 hash: ff3bbc4ca5b236727a1c0cfdacc770bb
MIME type:text/plain
Signature AsyncRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
shell spawn sage
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-21T07:25:00Z UTC
Last seen:
2026-07-21T07:36:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-07-22 21:36:00 UTC
AV detection:
12 of 24 (50.00%)
Threat level:
  2/5
Result
Malware family:
asyncrat
Score:
  10/10
Tags:
family:asyncrat botnet:default discovery execution persistence rat suricata
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: PowerShell
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Badlisted process makes network request
Family: AsyncRat
Process spawned unexpected child process
Suricata alert: AsyncRAT Malware Default X.509 Certificate Detected - Inbound
Malware Config
C2 Extraction:
contabili.balanteo.shop:6606
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments