MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4743e163a2bb13cacf0f76fb2a035af295cf6021a4f590573f0fa6b19d5e2aed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 5


Intelligence 5 IOCs YARA 14 File information Comments

SHA256 hash: 4743e163a2bb13cacf0f76fb2a035af295cf6021a4f590573f0fa6b19d5e2aed
SHA3-384 hash: ffaa772feebb682fc2bfa0835edb8cf9a024757aca6fbfe804c4c877cf21689b3a554b07cf7b7680ec29929778483d16
SHA1 hash: 1fca2965e2c83406a1346caea7a6188f2b5d8214
MD5 hash: a2baadcae4ab82f6b32dfe0fdcb1a5d7
humanhash: fish-social-mississippi-cat
File name:XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXITDENF2026-4281.zip
Download: download sample
Signature AsyncRAT
File size:323'181 bytes
First seen:2026-07-24 12:15:13 UTC
Last seen:2026-07-24 12:39:21 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:zOI4PD7Y20YnN7KXYyD0FEaKEpwf62Hv78F3L921ur:z6b7YfokoLF2f62PCB2A
TLSH T1286423EDCBA469C9E2CA44D4BAD47DE95CF920170355A106DB9E68C008BA00FCB6E5F3
Magika zip
Reporter TomU
Tags:AsyncRAT zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
42
Origin country :
CH CH
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Tax_Notice_89574.exe
File size:294'024 bytes
SHA256 hash: 93694473622f770d539263ae211dde4715264b0f23c858ba69796adca76cae35
MD5 hash: c9afda4f027fc9510134cffcc4d54da3
MIME type:application/x-dosexec
Signature AsyncRAT
File name:nvml.dll
File size:340'907 bytes
SHA256 hash: e1fdf4b2de8a2c811edda6e36daab874edff4822070f60fe9a9110d28911e161
MD5 hash: b6acbe89f3c5e4ab4e4a79891ed263e8
MIME type:application/x-dosexec
Signature AsyncRAT
Vendor Threat Intelligence
Gathering data
Threat name:
Win64.Trojan.Suschil
Status:
Malicious
First seen:
2026-07-24 12:17:42 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
asyncrat
Score:
  10/10
Tags:
family:asyncrat botnet:default discovery persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Uses Task Scheduler COM API
Checks installed software on the system
Executes dropped EXE
Loads dropped DLL
Adds Run key to start application
Async RAT payload
Family: AsyncRat
Malware Config
C2 Extraction:
192.252.180.45:4449
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AsyncRAT

zip 4743e163a2bb13cacf0f76fb2a035af295cf6021a4f590573f0fa6b19d5e2aed

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments