MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 57b20a754a8bc0d551bbcf7d94e4767f0bb29c1e3996301d2a92cd9f309d7bfc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AsyncRAT
Vendor detections: 19
| SHA256 hash: | 57b20a754a8bc0d551bbcf7d94e4767f0bb29c1e3996301d2a92cd9f309d7bfc |
|---|---|
| SHA3-384 hash: | 988ab9844155f184e115e58855151dc307b9c2e085c718cb97fd54ee8e11aafbf1fc2ca49ae0bcd731d72ae77320953f |
| SHA1 hash: | 321d077348140dd7967ce6d0832bab582dce3990 |
| MD5 hash: | 365062334429339b5aa3610d7aa69552 |
| humanhash: | foxtrot-carolina-river-saturn |
| File name: | Google Play Games.exe |
| Download: | download sample |
| Signature | AsyncRAT |
| File size: | 65'536 bytes |
| First seen: | 2026-01-22 08:10:09 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'003 x AgentTesla, 19'907 x Formbook, 12'332 x SnakeKeylogger) |
| ssdeep | 768:HWFePSZ85fiPERIi49JSI8/56/8tB7Jdl1+YSCv7mqb2nppwH1obFdIYBJ8G5UKI:2Et5HCU6SlHlWGbbowMH/MGGKVclN |
| Threatray | 2'375 similar samples on MalwareBazaar |
| TLSH | T1E1536B002798C926E2AD8AB4BCF2554006B5D5732106DB5E7CC814DBAB9FFC64A137FE |
| TrID | 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 9.7% (.EXE) Win64 Executable (generic) (10522/11/4) 6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 4.1% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| Reporter | Anonymous |
| Tags: | AsyncRAT botnet c2 DCRat exe |
Anonymous
The submitted file with SHA-256 hash57b20a754a8bc0d551bbcf7d94e4767f0bb29c1e3996301d2a92cd9f309d7bfc
(filename: GooglePlayGame.exe, PE .NET executable, 64 KB) is confirmed as malicious.
According to VirusTotal analysis, 50 out of 71 security vendors currently detect this file as malware. The predominant detections classify it as AsyncRAT / DcRAT family, including labels such as MSIL/AsyncRAT, Backdoor.AsyncRAT, and MSIL.Backdoor.DcRAT.
Multiple reputable vendors (Microsoft, ESET, Fortinet, Kaspersky, Sophos, BitDefender, CrowdStrike, Trend Micro, Rising, etc.) consistently identify this sample as a remote access trojan (RAT) / backdoor, indicating high confidence malicious behavior.
VirusTotal report:
https://www.virustotal.com/gui/file/57b20a754a8bc0d551bbcf7d94e4767f0bb29c1e3996301d2a92cd9f309d7bfc
Intelligence
File Origin
ESVendor Threat Intelligence
Details
Malware Config
PORT: 80,443,1337,1604,4444,5555,6666,8080,8848
Result
Behaviour
Malware Config
ledlighting.uk.com:80
ledlighting.uk.com:443
ledlighting.uk.com:1337
ledlighting.uk.com:1604
ledlighting.uk.com:4444
ledlighting.uk.com:5555
ledlighting.uk.com:6666
ledlighting.uk.com:8080
i0qens8.uk.com:8848
i0qens8.uk.com:80
i0qens8.uk.com:443
i0qens8.uk.com:1337
i0qens8.uk.com:1604
i0qens8.uk.com:4444
i0qens8.uk.com:5555
i0qens8.uk.com:6666
i0qens8.uk.com:8080
www.i0qens8.uk.com:8848
www.i0qens8.uk.com:80
www.i0qens8.uk.com:443
www.i0qens8.uk.com:1337
www.i0qens8.uk.com:1604
www.i0qens8.uk.com:4444
www.i0qens8.uk.com:5555
www.i0qens8.uk.com:6666
www.i0qens8.uk.com:8080
www.ledlighting.uk.com:8848
www.ledlighting.uk.com:80
www.ledlighting.uk.com:443
www.ledlighting.uk.com:1337
www.ledlighting.uk.com:1604
www.ledlighting.uk.com:4444
www.ledlighting.uk.com:5555
www.ledlighting.uk.com:6666
www.ledlighting.uk.com:8080
kkj.uk.com:8848
kkj.uk.com:80
kkj.uk.com:443
kkj.uk.com:1337
kkj.uk.com:1604
kkj.uk.com:4444
kkj.uk.com:5555
kkj.uk.com:6666
kkj.uk.com:8080
www.kkj.uk.com:8848
www.kkj.uk.com:80
www.kkj.uk.com:443
www.kkj.uk.com:1337
www.kkj.uk.com:1604
www.kkj.uk.com:4444
www.kkj.uk.com:5555
www.kkj.uk.com:6666
www.kkj.uk.com:8080
shj.uk.com:8848
shj.uk.com:80
shj.uk.com:443
shj.uk.com:1337
shj.uk.com:1604
shj.uk.com:4444
shj.uk.com:5555
shj.uk.com:6666
shj.uk.com:8080
www.shj.uk.com:8848
www.shj.uk.com:80
www.shj.uk.com:443
www.shj.uk.com:1337
www.shj.uk.com:1604
www.shj.uk.com:4444
www.shj.uk.com:5555
www.shj.uk.com:6666
www.shj.uk.com:8080
mongodb.uk.com:8848
mongodb.uk.com:80
mongodb.uk.com:443
mongodb.uk.com:1337
mongodb.uk.com:1604
mongodb.uk.com:4444
mongodb.uk.com:5555
mongodb.uk.com:6666
mongodb.uk.com:8080
www.mongodb.uk.com:8848
www.mongodb.uk.com:80
www.mongodb.uk.com:443
www.mongodb.uk.com:1337
www.mongodb.uk.com:1604
www.mongodb.uk.com:4444
www.mongodb.uk.com:5555
www.mongodb.uk.com:6666
www.mongodb.uk.com:8080
liv.it.com:8848
liv.it.com:80
liv.it.com:443
liv.it.com:1337
liv.it.com:1604
liv.it.com:4444
liv.it.com:5555
liv.it.com:6666
liv.it.com:8080
www.liv.it.com:8848
www.liv.it.com:80
www.liv.it.com:443
www.liv.it.com:1337
www.liv.it.com:1604
www.liv.it.com:4444
www.liv.it.com:5555
www.liv.it.com:6666
www.liv.it.com:8080
Unpacked files
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AcRat |
|---|---|
| Author: | Nikos 'n0t' Totosis |
| Description: | AcRat Payload (based on AsyncRat) |
| Rule name: | dcrat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | dcrat_kingrat |
|---|---|
| Author: | jeFF0Falltrades |
| Rule name: | dcrat_rkp |
|---|---|
| Author: | jeFF0Falltrades |
| Description: | Detects DCRat payloads |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DcRatBy |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables containing the string DcRatBy |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_WMI_EnumerateVideoDevice |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables attemping to enumerate video devices using WMI |
| Rule name: | MAL_AsnycRAT |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detects AsnycRAT based on it's config decryption routine |
| Rule name: | MAL_AsyncRAT_Config_Decryption |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detects AsnycRAT based on it's config decryption routine |
| Rule name: | Mal_WIN_AsyncRat_RAT_PE |
|---|---|
| Author: | Phatcharadol Thangplub |
| Description: | Use to detect AsyncRAT implant. |
| Rule name: | Multifamily_RAT_Detection |
|---|---|
| Author: | Lucas Acha (http://www.lukeacha.com) |
| Description: | Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | Njrat |
|---|---|
| Author: | botherder https://github.com/botherder |
| Description: | Njrat |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | SUSP_DOTNET_PE_List_AV |
|---|---|
| Author: | SECUINFRA Falcon Team |
| Description: | Detecs .NET Binary that lists installed AVs |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | Windows_Generic_Threat_ce98c4bc |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_asyncrat_unobfuscated |
|---|---|
| Author: | Matthew @ Embee_Research |
| Description: | Detects strings present in unobfuscated AsyncRat Samples. Rule may also pick up on other Asyncrat-derived malware (Dcrat/venom etc) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.