MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 396750d3837d60b8d8aa0253a5b569acfcdf872224e01ecd8f744dd73db4a850. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: 396750d3837d60b8d8aa0253a5b569acfcdf872224e01ecd8f744dd73db4a850
SHA3-384 hash: 8346e65d31b93fe0d885385f9281bae34aab7bbb6fe3f8e44a0e66c12f2eb90ff81aac7fea22f613468020a041d54aa2
SHA1 hash: 7e5b9bc2c4c04125bb903ae5786788bf36c895ca
MD5 hash: dc95438760cc8ae9e8b9bcbfa6f63da3
humanhash: xray-winner-monkey-bacon
File name:Swift Bilgilendirmeniz 180826-.exe
Download: download sample
Signature AsyncRAT
File size:852'992 bytes
First seen:2026-08-19 08:15:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'195 x AgentTesla, 20'345 x Formbook, 12'365 x SnakeKeylogger)
ssdeep 24576:L9jBQ++rL6SK2+yQev/JGQcqyIPuQR+io:L9jBQ++vPKlyQwJ+q1PuQRa
TLSH T15805F2083799ED06D4655FB45C31F7B40FB46DD5A820D2078EFABEEBB835B45A848283
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter threatcat_ch
Tags:AsyncRAT exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-08-19 08:29:18 UTC
Tags:
auto-reg netreactor xworm remote loader pastebin auto-sch

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Launching a process
Creating a file
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Connection attempt to an infection source
Unauthorized injection to a system process
Result
Threat name:
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Connects to a pastebin service (likely for C&C)
Contains functionality to check if Internet connection is working
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Found evasive API chain (may stop execution after checking mutex)
Found evasive API chain checking for user administrative privileges
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the windows firewall
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potential Privilege Escalation using Task Scheduler highest RunLevel
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Silenttrinity Stager Msbuild Activity
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses netsh to modify the Windows network and firewall settings
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected UAC Bypass using CMSTP
Yara detected XWorm
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1960226 Sample: Swift Bilgilendirmeniz 1808... Startdate: 19/08/2026 Architecture: WINDOWS Score: 100 113 pastebin.com 2->113 115 pki-goog.l.google.com 2->115 117 8 other IPs or domains 2->117 127 Suricata IDS alerts for network traffic 2->127 129 Found malware configuration 2->129 131 Malicious sample detected (through community Yara rule) 2->131 135 20 other signatures 2->135 12 Swift Bilgilendirmeniz 180826-.exe 1 5 2->12         started        16 diskdiag.exe 2->16         started        19 powershell.exe 11 2->19         started        21 3 other processes 2->21 signatures3 133 Connects to a pastebin service (likely for C&C) 113->133 process4 dnsIp5 105 C:\Users\user\AppData\Roaming\hfL.exe, PE32 12->105 dropped 107 C:\...\Swift Bilgilendirmeniz 180826-.exe.log, ASCII 12->107 dropped 167 Creates autostart registry keys with suspicious values (likely registry only malware) 12->167 169 Creates an autostart registry key pointing to binary in C:\Windows 12->169 171 Writes to foreign memory regions 12->171 177 2 other signatures 12->177 23 MSBuild.exe 15 5 12->23         started        109 139.99.88.62, 3778, 49716 OVHFR Singapore 16->109 111 pastebin.com 104.20.29.150, 443, 49715 CLOUDFLARENET-CloudflareIncUS Canada 16->111 173 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 16->173 175 Adds a directory exclusion to Windows Defender 16->175 28 powershell.exe 16->28         started        30 netsh.exe 16->30         started        32 netsh.exe 16->32         started        40 2 other processes 16->40 34 conhost.exe 19->34         started        36 conhost.exe 21->36         started        38 diskdiag.exe 21->38         started        file6 signatures7 process8 dnsIp9 119 31.56.209.234, 443, 49703 SWISSNET-ASUS Netherlands 23->119 121 45.141.27.27, 49711, 80 CLOUDFORESTCOLTD-AS-APCLOUDFORESTCOLTDTH Thailand 23->121 123 85.203.4.64, 49714, 80 CLOUDFORESTCOLTD-AS-APCLOUDFORESTCOLTDTH Thailand 23->123 97 C:\Users\user\AppData\...\fikqdfclient.exe, PE32+ 23->97 dropped 99 C:\Users\...\ebgsjkSecurityHealthService.exe, PE32 23->99 dropped 137 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 23->137 42 fikqdfclient.exe 23->42         started        46 ebgsjkSecurityHealthService.exe 9 23->46         started        139 Loading BitLocker PowerShell Module 28->139 48 conhost.exe 28->48         started        50 WmiPrvSE.exe 28->50         started        52 conhost.exe 30->52         started        54 conhost.exe 32->54         started        56 conhost.exe 40->56         started        58 conhost.exe 40->58         started        file10 signatures11 process12 file13 101 C:\Users\user\AppData\Local\...\diskdiag.exe, PE32+ 42->101 dropped 147 Multi AV Scanner detection for dropped file 42->147 149 Found evasive API chain (may stop execution after checking mutex) 42->149 151 Found evasive API chain checking for user administrative privileges 42->151 60 diskdiag.exe 42->60         started        63 schtasks.exe 42->63         started        65 schtasks.exe 42->65         started        103 C:\Users\user\...\SecurtyHeathService.exe, PE32+ 46->103 dropped 153 Antivirus detection for dropped file 46->153 67 cmd.exe 1 46->67         started        signatures14 process15 signatures16 155 Multi AV Scanner detection for dropped file 60->155 157 Found evasive API chain (may stop execution after checking mutex) 60->157 159 Uses netsh to modify the Windows network and firewall settings 60->159 165 3 other signatures 60->165 69 conhost.exe 63->69         started        71 conhost.exe 65->71         started        161 Uses schtasks.exe or at.exe to add and modify task schedules 67->161 163 Potential Privilege Escalation using Task Scheduler highest RunLevel 67->163 73 SecurtyHeathService.exe 67->73         started        77 conhost.exe 67->77         started        process17 dnsIp18 125 82.26.104.192, 31104, 49712 DE-CORPDE-CORPTH Thailand 73->125 141 Antivirus detection for dropped file 73->141 143 Multi AV Scanner detection for dropped file 73->143 145 Contains functionality to check if Internet connection is working 73->145 79 cmd.exe 1 73->79         started        81 cmd.exe 1 73->81         started        83 cmd.exe 73->83         started        signatures19 process20 process21 85 conhost.exe 79->85         started        87 schtasks.exe 1 79->87         started        89 conhost.exe 81->89         started        91 schtasks.exe 1 81->91         started        93 conhost.exe 83->93         started        95 schtasks.exe 1 83->95         started       
Verdict:
inconclusive
YARA:
10 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.41 Win 32 Exe x86
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-19 08:16:29 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery execution persistence rat trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Detect Xworm Payload
Family: Xworm
Malware Config
C2 Extraction:
31.56.209.234:443
Unpacked files
SH256 hash:
396750d3837d60b8d8aa0253a5b569acfcdf872224e01ecd8f744dd73db4a850
MD5 hash:
dc95438760cc8ae9e8b9bcbfa6f63da3
SHA1 hash:
7e5b9bc2c4c04125bb903ae5786788bf36c895ca
SH256 hash:
ee3f696a8717e0fae60e166f1df7edfcb0c92f00e515792bbbecfcfe77c2c555
MD5 hash:
08630964baa8d18f5401458efcea6ff0
SHA1 hash:
39318b36089b988ab1eb67f7822ff09a4af1e05e
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
SH256 hash:
49baffd57a2753b9b97346e3d9b7c896900bdf92e9cacc5c6e1526c90e6e696d
MD5 hash:
407f7273447577aaaa1abe8ac8df8876
SHA1 hash:
62672d83b00e66016789a758c7133b1b1b55137d
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
2f8e7c4e7a42013541967b22f6afca709eef095c661875a691476252fae3c152
MD5 hash:
4975e543d617167b41dfe8df45442573
SHA1 hash:
efcf918eaa7f3aa6832a694887154ffca6d67b67
Detections:
win_xworm_a0 win_xworm_w0 XWorm INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA MALWARE_Win_AsyncRAT MALWARE_Win_XWorm win_mal_XWorm
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

Executable exe 396750d3837d60b8d8aa0253a5b569acfcdf872224e01ecd8f744dd73db4a850

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments