MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 454f585b6276a2bf24aeac35e4593b2ca6f94623e6eb111a24a6a7f862f0c708. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 7


Intelligence 7 IOCs YARA 14 File information Comments

SHA256 hash: 454f585b6276a2bf24aeac35e4593b2ca6f94623e6eb111a24a6a7f862f0c708
SHA3-384 hash: d67d0bf754776f21d95b2c66802b9644d1f5400e1f7e4ed9cb2ab3328f29fa23ae722bb63a5d1a8aee26965372cd22c3
SHA1 hash: 029b7092f272114c69833790681783843609cc63
MD5 hash: 811a988d1820f2c5fef46f0d0f1bc155
humanhash: ack-river-eighteen-magnesium
File name:_DLL-SL_Tax_Notice_89574.img.iso
Download: download sample
Signature AsyncRAT
File size:700'416 bytes
First seen:2026-07-24 12:39:53 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:TCiXgkff4DqKz6wzrPLkJWGlz71Nfhu+1mqTnNFm:TC6gsf4DqelLgX5DLTr
TLSH T14EE49D40F381BEF9DCA98A7854E25319E3B2B0048328E62B765CEE6D4F177549D3B385
TrID 88.5% (.NULL) null bytes (2048000/1)
11.0% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.1% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Magika iso
Reporter TomU
Tags:AsyncRAT iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
CH CH
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Tax_Notice_89574.exe
File size:294'024 bytes
SHA256 hash: 93694473622f770d539263ae211dde4715264b0f23c858ba69796adca76cae35
MD5 hash: c9afda4f027fc9510134cffcc4d54da3
MIME type:application/x-dosexec
Signature AsyncRAT
File name:nvml.dll
File size:340'907 bytes
SHA256 hash: e1fdf4b2de8a2c811edda6e36daab874edff4822070f60fe9a9110d28911e161
MD5 hash: b6acbe89f3c5e4ab4e4a79891ed263e8
MIME type:application/x-dosexec
Signature AsyncRAT
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Executable ISO9660 Image PE (Portable Executable) PE File Layout
Threat name:
Win64.Trojan.Suschil
Status:
Malicious
First seen:
2026-07-13 03:58:31 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
asyncrat
Score:
  10/10
Tags:
family:asyncrat botnet:default discovery persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Uses Task Scheduler COM API
Checks installed software on the system
Executes dropped EXE
Loads dropped DLL
Adds Run key to start application
Async RAT payload
Family: AsyncRat
Malware Config
C2 Extraction:
192.252.180.45:4449
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

iso 454f585b6276a2bf24aeac35e4593b2ca6f94623e6eb111a24a6a7f862f0c708

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments