MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1b413f8c96547f9abefecddea7d864fdc60146d9a0b12659de973eeff1caa92. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 18


Intelligence 18 IOCs YARA 4 File information Comments

SHA256 hash: c1b413f8c96547f9abefecddea7d864fdc60146d9a0b12659de973eeff1caa92
SHA3-384 hash: 50a154fb8b85996c30217c95dddd62b2c2d28ccff1023ceeaa5ba7a1f45e6574099e3dea858e29b979eccb9084d9c063
SHA1 hash: f51d138388b56ad24a34d8b03ec8a343d0fc3d22
MD5 hash: a86f0bd0f3fc40986bfe060a49359513
humanhash: mirror-comet-cat-delta
File name:c1b413f8c96547f9abefecddea7d864fdc60146d9a0b12659de973eeff1caa92
Download: download sample
Signature AsyncRAT
File size:814'080 bytes
First seen:2026-06-08 08:47:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'066 x AgentTesla, 20'011 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 12288:BUw0zjeWU+fF5RI2GDoazHmuROdoU9TF6jNYbcJHa2LOHsn9vfAJRkVj8GirD1:mUuQHzHNOdx9TFHct9MsntAEFT0D
Threatray 50 similar samples on MalwareBazaar
TLSH T18F05F190231AD903C4DA5FF40A61E2B517745ED9E822D3139FEABDEFF8BA21119053C6
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:AsyncRAT exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
30d949714952979d30b072797d252ba3bc4febc84736eb25e08810595e827357.zip
Verdict:
Malicious activity
Analysis date:
2026-05-28 11:34:33 UTC
Tags:
arch-exec netreactor xworm remote

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
micro shell virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Creating a file
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-28T03:58:00Z UTC
Last seen:
2026-06-07T22:08:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.SnakeKeylogger
Status:
Malicious
First seen:
2026-05-28 07:14:14 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery execution persistence rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Detect Xworm Payload
Family: Xworm
Malware Config
C2 Extraction:
104.168.7.219:8823
frBvNnnFYR6XR622pBE0NQ==:23
Unpacked files
SH256 hash:
c1b413f8c96547f9abefecddea7d864fdc60146d9a0b12659de973eeff1caa92
MD5 hash:
a86f0bd0f3fc40986bfe060a49359513
SHA1 hash:
f51d138388b56ad24a34d8b03ec8a343d0fc3d22
SH256 hash:
a37f009dcc35a6fb7ad5266c085dbb2dede2a724e8e8b44603f17bd7051f8c87
MD5 hash:
f4c7b7302c8fbd0c6a313720a09e2fb2
SHA1 hash:
67c0afdcd2e54f5ccbab60f8a8495a439ff70b55
SH256 hash:
407a4bc41fac6b393b2c95b1a376d8cc87580e259f1875bf4505465d21a1270e
MD5 hash:
289a89bc527d79972c5fabc7d95d1679
SHA1 hash:
cba5b617e25a12c863cd2f041263e093c52898b2
Detections:
win_xworm_a0 win_xworm_w0 XWorm
SH256 hash:
5aef543f2aaa09031143ed0b9734dd693fa81b56dfe75f546df36ea394210131
MD5 hash:
706cd7eac9f2ec43307b7b4538a39a95
SHA1 hash:
e31f3775922f260fc3ba943eb2f2770f7b3b1112
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments