MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d10d4b157d350bbd510bd8890d9a89140ea06e2bb63a575e14ef02a52fc47eba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AsyncRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: d10d4b157d350bbd510bd8890d9a89140ea06e2bb63a575e14ef02a52fc47eba
SHA3-384 hash: e8850b2a24f44db289a51115bd00af49f82fc3c4117f4bc2e172fd3e9637943c26947f68f83b60fbf49635a4980da90d
SHA1 hash: 3c53877558ca5947343488c390bf4dff61bc995e
MD5 hash: 20899afa62b1560b786ec37e122f631f
humanhash: london-alabama-jupiter-kitten
File name:OBLIGACION PENDIENTE - ACUERDO_infected.zip
Download: download sample
Signature AsyncRAT
File size:169'702 bytes
First seen:2026-08-20 14:28:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:tPaJFxFM9YJdMae2HFtwP0pXut86I3GQEQ9yAGHP0qzwZGQLYGlv62BLS:tiFRJJ1FtPpXut86rxXZpQL1lvJBLS
TLSH T14FF322D44A5E226B644C3A0273B37688C932355A11F74C826CCF19AB4FB68C7FF119B9
Magika zip
Reporter cypherpunk472
Tags:AsyncRAT colombia zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
CO CO
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:OBLIGACION PENDIENTE - ACUERDO.js
File size:301'033 bytes
SHA256 hash: b781b07429a51a7a9b786160ad9ac0bc037b7ee062d1f88b9aff2e42b292270b
MD5 hash: ead85a744bafcc55e094668ce2e43cb0
MIME type:text/plain
Signature AsyncRAT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
downloader encrypted obfuscated repaired
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Zip Archive
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-20 14:29:29 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via e-mail link

Comments