🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a610ef0e37af408aa49c7296d238796c57ac45aa8b0809ce72bc4d75b23fdf4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 59 File information Comments

SHA256 hash: a610ef0e37af408aa49c7296d238796c57ac45aa8b0809ce72bc4d75b23fdf4f
SHA3-384 hash: 932a255aa6ebd857c1371b0c29da7bf824332e825d544cc18558a3fe6b8bac8d9bf5308e706c1e93bb1dbb54ee6f67e8
SHA1 hash: 44e5206b1b95761ac726a33e5801d7ce58e6fd3d
MD5 hash: a686b29f491b1779cf0e616dbee999e8
humanhash: angel-cat-friend-venus
File name:vbs.vbs
Download: download sample
Signature AsyncRAT
File size:6'198'070 bytes
First seen:2025-10-01 22:33:10 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 49152:SKDiNloyICCodqKCIlJA6hKvFyMY9MPkVA3XkGDszbgH:tCHCh
TLSH T115561A73E75871720793809748D7A3026336921BF2225578B6CDC2986F4A5B9C3F36FA
Magika yaml
Reporter GDHJDSYDH1
Tags:AsyncRAT backdoor Downloader mimikatz TrickBot vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
458
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
trickbot vmdetect mimikatz emotet
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm evasive hacktool javascript macros mimikatz netsh ransomware wmiexec
Verdict:
Malicious
File Type:
hta
First seen:
2025-09-27T10:21:00Z UTC
Last seen:
2025-10-02T05:41:00Z UTC
Hits:
~10000
Detections:
Trojan.Win32.Poweliks.a HEUR:Trojan.Win32.Generic HEUR:Trojan.PowerShell.Generic
Gathering data
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-27 04:16:00 UTC
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BatModifier2
Author:Madhav
Description:This is a bat file which is setup a game. 49509
Rule name:Bolonyokte
Author:Jean-Philippe Teissier / @Jipe_
Description:UnknownDotNet RAT - Bolonyokte
Rule name:Borland
Author:malware-lu
Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Check_Qemu_Description
Rule name:Check_VBox_Description
Rule name:Check_VBox_VideoDrivers
Rule name:ciscotools
Author:Tim Brown @timb_machine
Description:Cisco tools
Rule name:CMD_Shutdown
Author:adm1n_usa32
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique
Rule name:Detect_Zoom_Invite_malware_RAT_C2
Author:daniyyell
Description:Detects Zoom Invite Call Leading to Malware Hosted in Telegram C2
Rule name:dgaaga
Author:Harshit
Description:Detects suspicious PowerShell or registry activity
Rule name:Disable_Defender
Author:iam-py-test
Description:Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen
Rule name:dsc
Author:Aaron DeVera
Description:Discord domains
Rule name:ESXi_Ransomware_Royal_params
Author:albertzsigovits
Description:Detection for Royal ransomware on ESXi
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:HackTool_Producers
Description:Hacktool Producers String
Rule name:Hacktool_Strings_p0wnedShell
Author:Florian Roth
Description:Detects strings found in Runspace Post Exploitation Toolkit
Reference:https://github.com/Cn33liz/p0wnedShell
Rule name:Hacktool_Strings_p0wnedShell_RID3234
Author:Florian Roth
Description:p0wnedShell Runspace Post Exploitation Toolkit - file p0wnedShell.cs
Reference:https://github.com/Cn33liz/p0wnedShell
Rule name:html_auto_download_b64
Author:Tdawg
Description:html auto download
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_fodhelper
Author:ditekSHen
Description:detects Windows exceutables potentially bypassing UAC using fodhelper.exe
Rule name:INDICATOR_SUSPICIOUS_GENRansomware
Author:ditekSHen
Description:Detects command variations typically used by ransomware
Rule name:Invoke_WMIExec_Gen_1
Author:Florian Roth (Nextron Systems)
Description:Detects Invoke-WmiExec or Invoke-SmbExec
Reference:https://github.com/Kevin-Robertson/Invoke-TheHash
Rule name:Invoke_WMIExec_Gen_1_RID2E57
Author:Florian Roth
Description:Detects Invoke-WmiExec or Invoke-SmbExec
Reference:https://github.com/Kevin-Robertson/Invoke-TheHash
Rule name:Jupyter_infostealer
Author:CD_R0M_
Description:Rule for Jupyter Infostealer/Solarmarker malware from september 2021-December 2022
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MALWARE_Win_AsyncRAT
Author:ditekSHen
Description:Detects AsyncRAT
Rule name:Mimikatz_Memory_Rule_1
Author:Florian Roth
Description:Detects password dumper mimikatz in memory
Rule name:Multi_Ransomware_Akira_21842eb3
Author:Elastic Security
Rule name:NET
Author:malware-lu
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RDPWrap
Author:@bartblaze
Description:Identifies RDP Wrapper, sometimes used by attackers to maintain persistence.
Reference:https://github.com/stascorp/rdpwrap
Rule name:Suspicious_PS_Strings
Author:Lucas Acha (http://www.lukeacha.com)
Description:observed set of strings which are likely malicious, observed with Jupyter malware.
Reference:http://security5magics.blogspot.com/2020/12/tracking-jupyter-malware.html
Rule name:SUSP_Disable_ETW_Jun20_1
Author:Florian Roth (Nextron Systems)
Description:Detects method to disable ETW in ENV vars before executing a program
Reference:https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3
Rule name:SUSP_Netsh_PortProxy_Command
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious command line with netsh and the portproxy command
Reference:https://docs.microsoft.com/en-us/windows-server/networking/technologies/netsh/netsh-interface-portproxy
Rule name:SUSP_Netsh_PortProxy_Command_RID3201
Author:Florian Roth
Description:Detects a suspicious command line with netsh and the portproxy command
Reference:https://docs.microsoft.com/en-us/windows-server/networking/technologies/netsh/netsh-interface-portproxy
Rule name:SUSP_PowerShell_Download_Temp_Rundll
Author:SECUINFRA Falcon Team
Description:Detect a Download to %temp% and execution with rundll32.exe
Rule name:SUSP_Scheduled_Tasks_Create_From_Susp_Dir
Author:SECUINFRA Falcon Team
Description:Detects a PowerShell Script that creates a Scheduled Task that runs from an suspicious directory
Rule name:SUSP_Websites
Author:SECUINFRA Falcon Team
Description:Detects the reference of suspicious sites that might be used to download further malware
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:testlumma
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:virustotal
Author:Tracel
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Windows_Trojan_Netwire_1b43df38
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/netwire-dynamic-configuration-extraction
Rule name:WIN_ClickFix_Detection
Author:dogsafetyforeverone
Description:Detects ClickFix social engineering technique using 'Verify you are human' messages and malicious PowerShell commands
Reference:ClickFix social engineering and malicious PowerShell commands
Rule name:WIN_FileFix_Detection
Author:dogsafetyforeverone
Description:Detects FileFix social engineering technique that launches chained PowerShell and PHP commands from file explorer typed paths
Reference:FileFix social engineering with PowerShell and PHP commands
Rule name:WIN_SHADOW_UNPACKED

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AsyncRAT

Visual Basic Script (vbs) vbs a610ef0e37af408aa49c7296d238796c57ac45aa8b0809ce72bc4d75b23fdf4f

(this sample)

Comments