MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6f1fe93e7b7018d9ef446ef2d75d387364355ae2a8919cc24e2e5c3c8696d9d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 16


Intelligence 16 IOCs YARA 5 File information Comments

SHA256 hash: c6f1fe93e7b7018d9ef446ef2d75d387364355ae2a8919cc24e2e5c3c8696d9d
SHA3-384 hash: 2e723b904e6cba55eb808cba26a9cb91c44e90353d6f98d269a9a941c26876785b3e0fda4f6a61935be0974039f81967
SHA1 hash: 2f63dc179ed5be3d21720abc1b97a6879f738d14
MD5 hash: e6948aa43cfb86c862b937312150204f
humanhash: massachusetts-south-wisconsin-pluto
File name:c6f1fe93e7b7018d9ef446ef2d75d387364355ae2a8919cc24e2e5c3c8696d9d
Download: download sample
Signature AsyncRAT
File size:869'888 bytes
First seen:2026-08-10 14:04:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'190 x AgentTesla, 20'337 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:y9T+3hApneuKetD+gw58CniRDbrKSeqO:iC3hAprtDBwERDjnO
TLSH T1990512185B88CD11E4E6473A9070F3B503F2BE8DA921C35A8FECAED73D26B05AD14761
TrID 70.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.2% (.EXE) Win64 Executable (generic) (6522/11/2)
4.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 00c4d48cdcccd464 (3 x Formbook, 2 x AgentTesla, 2 x AsyncRAT)
Reporter adrian__luca
Tags:AsyncRAT exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
63e886ec997acafb0c0372a08d8ba05aedf0c31b4e547e83fa54f4b0a085eead.zip
Verdict:
Malicious activity
Analysis date:
2026-07-08 15:24:24 UTC
Tags:
arch-exec auto-startup xworm

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Creating a process with a hidden window
Blocking the Windows Defender launch
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bitmap packed packed stego
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-08T01:50:00Z UTC
Last seen:
2026-08-06T17:41:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-08 15:24:25 UTC
File Type:
PE (.Net Exe)
Extracted files:
8
AV detection:
28 of 36 (77.78%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xworm discovery evasion execution persistence privilege_escalation rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
Creates a file in the Startup directory
Checks computer location settings
Command and Scripting Interpreter: PowerShell
Detect Xworm Payload
Family: Xworm
Modifies Windows Defender DisableAntiSpyware settings
Unpacked files
SH256 hash:
c6f1fe93e7b7018d9ef446ef2d75d387364355ae2a8919cc24e2e5c3c8696d9d
MD5 hash:
e6948aa43cfb86c862b937312150204f
SHA1 hash:
2f63dc179ed5be3d21720abc1b97a6879f738d14
SH256 hash:
b857821ade3427a9fd9d83f42150344bc905bda8328fa66ba49d499af64f23ee
MD5 hash:
7842d12d9e37c75076133be5b9904cb2
SHA1 hash:
425f1edac0b53d62a20749a6a69e5a3b260c595f
SH256 hash:
8b69fd101481636315dcbb430dd7380acae7e2bf763a00333b2e9ac165a0e126
MD5 hash:
d4e73bc40e749b7533ca19c77270249e
SHA1 hash:
589d580e330d7fb94501429b1bba8adee499210d
Detections:
win_xworm_a0 win_xworm_w0 XWorm
SH256 hash:
3e33a52a96eacddb794983ce4b003642b75e9bb68bb950bb0db22f2aff77d57a
MD5 hash:
7a3a549e6bf7ec3e76b783f64b9914ec
SHA1 hash:
e99494c3c324379506ca9fe08bc9d0a9aa723406
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments