MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5373ab86ceeab08fabe076737f4dfc00362048c6bbf329604bdfbe97497a4fab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AsyncRAT
Vendor detections: 22
| SHA256 hash: | 5373ab86ceeab08fabe076737f4dfc00362048c6bbf329604bdfbe97497a4fab |
|---|---|
| SHA3-384 hash: | f1441d10dc590421eab49f5757c42c69c69e83da3e6f88a57bd13dabf508b86540def66b61d91f887638870357dfcd67 |
| SHA1 hash: | 147ef0bd21d5332b98a31e00f9e652f4780dd0e5 |
| MD5 hash: | 396e2739a2375723afeaa8b6172121ac |
| humanhash: | black-magnesium-network-jig |
| File name: | vertexedge.exe |
| Download: | download sample |
| Signature | AsyncRAT |
| File size: | 65'536 bytes |
| First seen: | 2026-01-11 15:46:31 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'126 x AgentTesla, 20'150 x Formbook, 12'362 x SnakeKeylogger) |
| ssdeep | 768:qWdwIms4SiPsbRiH9J8ID3l9R29pnXwQ1+ASCvAmqb2nIFpwH1ox82DGz8G1DVcD:q64BdLV9k/XwQGnbbPwoQQG1DVclN |
| Threatray | 2'279 similar samples on MalwareBazaar |
| TLSH | T152536B002798CA66E1AE4AB4ACF2560046B5D5772102DB5E7CC814CB6B9FFC646237FF |
| TrID | 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 9.7% (.EXE) Win64 Executable (generic) (10522/11/4) 6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 4.1% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| Reporter | Anonymous |
| Tags: | AsyncRAT c2 DCRat exe RAT |
Anonymous
The sample vertexedge.exe is a confirmed malicious Windows PE (.NET) executable exhibiting Remote Access Trojan (RAT) behavior, supported by both static and dynamic evidence.Detection & classification evidence:
Detected as malicious by 49/71 security vendors on VirusTotal.
Multiple sandboxes (CAPE Sandbox, Zenbox) classify the file as MALWARE / TROJAN / RAT / EVADER.
MITRE ATT&CK mapping shows extensive coverage across Execution, Persistence, Defense Evasion, Privilege Escalation, and Credential Access tactics.
Persistence mechanisms observed:
Creates a scheduled task named vertexedge configured to run at logon with highest privileges using schtasks.exe.
Copies itself to %APPDATA%\vertexedge.exe and executes from that location.
Drops and executes temporary batch scripts to establish persistence.
Defense evasion techniques:
Detects debugging and sandbox environments (IsDebuggerPresent, virtualization checks).
Uses long sleep delays and obfuscation.
Performs indirect command execution via CMD and BAT files.
Attempts indicator removal and registry manipulation.
Execution & system interaction:
Executes commands via cmd.exe and batch files.
Enumerates system and security-related information.
Modifies registry keys associated with Explorer policies and system configuration.
Performs process injection–related activity consistent with RAT implants.
Network & C2 indicators:
Communicates with multiple suspicious external domains and IPs, including:
789bet-trangchu.vip
open88top1.com
alloparentsbebe.org
Uses uncommon destination ports (8080, 8443, 6606).
Network traffic matches malicious JA3 SSL fingerprints associated with AsyncRAT.
Conclusion:
Based on high AV detection rates, confirmed sandbox verdicts, persistence via scheduled tasks, defense evasion techniques, and suspicious C2 communications, this sample is conclusively identified as a Remote Access Trojan (RAT). The behavior and network patterns are consistent with AsyncRAT-like malware, posing a significant security risk.
Intelligence
File Origin
HKVendor Threat Intelligence
Details
Result
Behaviour
Malware Config
PORT: 80,443,1604,4444,5555,6606,6666,8080,8443
Result
Behaviour
Malware Config
alloparentsbebe.org:8080
alloparentsbebe.org:80
alloparentsbebe.org:443
alloparentsbebe.org:5555
alloparentsbebe.org:1604
alloparentsbebe.org:4444
alloparentsbebe.org:6606
alloparentsbebe.org:8443
www.alloparentsbebe.org:6666
www.alloparentsbebe.org:8080
www.alloparentsbebe.org:80
www.alloparentsbebe.org:443
www.alloparentsbebe.org:5555
www.alloparentsbebe.org:1604
www.alloparentsbebe.org:4444
www.alloparentsbebe.org:6606
www.alloparentsbebe.org:8443
okvip168th.net:6666
okvip168th.net:8080
okvip168th.net:80
okvip168th.net:443
okvip168th.net:5555
okvip168th.net:1604
okvip168th.net:4444
okvip168th.net:6606
okvip168th.net:8443
www.okvip168th.net:6666
www.okvip168th.net:8080
www.okvip168th.net:80
www.okvip168th.net:443
www.okvip168th.net:5555
www.okvip168th.net:1604
www.okvip168th.net:4444
www.okvip168th.net:6606
www.okvip168th.net:8443
xacmgm.za.com:6666
xacmgm.za.com:8080
xacmgm.za.com:80
xacmgm.za.com:443
xacmgm.za.com:5555
xacmgm.za.com:1604
xacmgm.za.com:4444
xacmgm.za.com:6606
xacmgm.za.com:8443
www.xacmgm.za.com:6666
www.xacmgm.za.com:8080
www.xacmgm.za.com:80
www.xacmgm.za.com:443
www.xacmgm.za.com:5555
www.xacmgm.za.com:1604
www.xacmgm.za.com:4444
www.xacmgm.za.com:6606
www.xacmgm.za.com:8443
www.open88top1.com:6666
www.open88top1.com:8080
www.open88top1.com:80
www.open88top1.com:443
www.open88top1.com:5555
www.open88top1.com:1604
www.open88top1.com:4444
www.open88top1.com:6606
www.open88top1.com:8443
www.789bet-trangchu.vip:6666
www.789bet-trangchu.vip:8080
www.789bet-trangchu.vip:80
www.789bet-trangchu.vip:443
www.789bet-trangchu.vip:5555
www.789bet-trangchu.vip:1604
www.789bet-trangchu.vip:4444
www.789bet-trangchu.vip:6606
www.789bet-trangchu.vip:8443
789bet-trangchu.vip:6666
789bet-trangchu.vip:8080
789bet-trangchu.vip:80
789bet-trangchu.vip:443
789bet-trangchu.vip:5555
789bet-trangchu.vip:1604
789bet-trangchu.vip:4444
789bet-trangchu.vip:6606
789bet-trangchu.vip:8443
open88top1.com:6666
open88top1.com:8080
open88top1.com:80
open88top1.com:443
open88top1.com:5555
open88top1.com:1604
open88top1.com:4444
open88top1.com:6606
open88top1.com:8443
Unpacked files
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AcRat |
|---|---|
| Author: | Nikos 'n0t' Totosis |
| Description: | AcRat Payload (based on AsyncRat) |
| Rule name: | dcrat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | dcrat_kingrat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | dcrat_rkp |
|---|---|
| Author: | jeFF0Falltrades |
| Description: | Detects DCRat payloads |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DcRatBy |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables containing the string DcRatBy |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_WMI_EnumerateVideoDevice |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables attemping to enumerate video devices using WMI |
| Rule name: | MAL_AsnycRAT |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detects AsnycRAT based on it's config decryption routine |
| Rule name: | MAL_AsyncRAT_Config_Decryption |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detects AsnycRAT based on it's config decryption routine |
| Rule name: | Mal_WIN_AsyncRat_RAT_PE |
|---|---|
| Author: | Phatcharadol Thangplub |
| Description: | Use to detect AsyncRAT implant. |
| Rule name: | Multifamily_RAT_Detection |
|---|---|
| Author: | Lucas Acha (http://www.lukeacha.com) |
| Description: | Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | Njrat |
|---|---|
| Author: | botherder https://github.com/botherder |
| Description: | Njrat |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | SUSP_DOTNET_PE_List_AV |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detecs .NET Binary that lists installed AVs |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | Windows_Generic_Threat_ce98c4bc |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_asyncrat_unobfuscated |
|---|---|
| Author: | Matthew @ Embee_Research |
| Description: | Detects strings present in unobfuscated AsyncRat Samples. Rule may also pick up on other Asyncrat-derived malware (Dcrat/venom etc) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.RAT King Parser (https://github.com/jeFF0Falltrades/rat_king_parser) Output:
{
"sha256": "5373ab86ceeab08fabe076737f4dfc00362048c6bbf329604bdfbe97497a4fab",
"yara_possible_family": "dcrat",
"key": "daa120aebc3752b944e3e78714739e0443ed5e8838121f860b4441ce295beb94",
"salt": "4463526174427971777164616e6368756e",
"config": {
"Ports": [
"6666",
"8080",
"80",
"443",
"5555",
"1604",
"4444",
"6606",
"8443"
],
"Hosts": [
"alloparentsbebe.org",
"www.alloparentsbebe.org",
"okvip168th.net",
"www.okvip168th.net",
"xacmgm.za.com",
"www.xacmgm.za.com",
"www.open88top1.com",
"www.789bet-trangchu.vip",
"789bet-trangchu.vip",
"open88top1.com"
],
"Version": " 1.0.7",
"Install": "true",
"InstallFolder": "%AppData%",
"InstallFile": "vertexedge.exe",
"Key": "M0JHamRLblFlY1ZCcmpWdHRHTDdYbXY1RDg1bHBEaW8=",
"Mutex": "Download",
"Certificate": "MIICMDCCAZmgAwIBAgIVAKLFT7KAMfd661OUJo25Zv9Os1U1MA0GCSqGSIb3DQEBDQUAMGQxFTATBgNVBAMMDERjUmF0IFNlcnZlcjETMBEGA1UECwwKcXdxZGFuY2h1bjEcMBoGA1UECgwTRGNSYXQgQnkgcXdxZGFuY2h1bjELMAkGA1UEBwwCU0gxCzAJBgNVBAYTAkNOMB4XDTI1MDMyNzE0MTAyMFoXDTM2MDEwNDE0MTAyMFowEDEOMAwGA1UEAwwFRGNSYXQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAIgpnX2soUg4sV1SWCHlfsgfzvf90ztXr9RZe+LhN+2SgmAwE+AjfDfg8BFeBD/h3OFXKufG8PH75iUfL/Ld+gtZKrJdbfJWIViIUi5DFUHGoXYWAOlyoWpAvtkROhm0kgwJH13C6EjpykTxJO9WDHF15WZz2yb8XW+4Pw6qKmVVAgMBAAGjMjAwMB0GA1UdDgQWBBSKWpEwblg9BFzY1ec9fIUZrdPDTTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDQUAA4GBAFjRDXncETVy5S5IO69VGDwc9bp5ZfVt2k9h2PXJ6IXCoKCGr2gqd3bNTJp+Nge10/VwHbBQll2f53wWxHASveiYP/hxIKgMFdYO09gCkW3gkU5+K6lwbj2JIK3EX1gvhv/okaosWXyXz2P29tlm7wlbYlem1ozUo+vUSIIlbYmY",
"Serversignature": "aQwtzx02ENPvVzbImBhjMYvDM2R5nvtUs9hSKhJ2n2xlOe5axBZ60hjwrLv/fmqNZbhS1nK+IHKUARrYf1sz1vflaPyKjMsR1xYN0ui5ex8XRMH7yzqvphGSaJh+EULie2D6/xBVOO1B0r42BUtjU0pDZx21McnfJT0j3BA2hOA=",
"Pastebin": "null",
"BSOD": "false",
"Hwid": "null",
"Delay": "1",
"Group": "Vertex",
"AntiProcess": "false",
"Anti": "false"
}
}