869a8a2daa890b414c51af99be794e78d6bd3c60d1450b017e78d421428587c9

Classification: Malicious

869a8a2daa890b414c51af99be794e78d6bd3c60d1450b017e78d421428587c9 is a malicious file sample. Linked to Asyncrat malware. Detected by 54 antivirus engines.

Detection summary

  • 54 antivirus detections (75% detection ratio)
  • 1 IDS alerts
  • 1 processes observed
  • 9 contacted hosts
  • 3 DNS requests

MITRE ATT&CK associations

Malware families: ASYNCRAT (S1087)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-12 02:21:15 2026-09-03 00:45:06 malicious-activity
AsyncRAT MalwareBazaar Abuse.ch 2023-11-12 02:07:27 2023-11-12 02:07:27 malicious-activity S1087 AsyncRAT

Tags

evasive

Sample information

Filenames
869a8a2daa890b414c51af99be794e78d6bd3c60d1450b017e78d421428587c9, bRxV.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
48640 bytes
MD5
a79872d39f5825629cac340e09b28f1a
SHA-1
15abd6b104e8eaf6af18cce3fec85efd5f5c133e
SHA-256
869a8a2daa890b414c51af99be794e78d6bd3c60d1450b017e78d421428587c9
First indexed
2023-11-12 02:08:03
Last updated
2026-09-03 00:45:06

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKDZ.74543
CAT-QuickHealBackdoor.MsilFC.S13564499
SkyhighBehavesLike.Win32.Fareit.pm
McAfeePWS-FDHM!A79872D39F58
MalwarebytesGeneric.Trojan.MSIL.DDS
ZillyaTrojan.Agent.Win32.2058189
SangforSuspicious.Win32.Save.a
BitDefenderTrojan.GenericKDZ.74543
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.DCRat
ESET-NOD32a variant of MSIL/Agent.CFQ
APEXMalicious
ClamAVWin.Malware.Generickdz-9865912-0
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
RisingBackdoor.AsyncRAT!1.C3F4 (CLASSIC)
SophosTroj/AsyncRat-B
F-SecureHeuristic.HEUR/AGEN.1307404
DrWebBackDoor.AsyncRATNET.2
VIPRETrojan.GenericKDZ.74543
TrendMicroBackdoor.MSIL.ASYNCRAT.SMYXDGUZ
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a79872d39f582562
EmsisoftTrojan.GenericKDZ.74543 (B)
IkarusTrojan.MSIL.Agent
JiangminBackdoor.MSIL.epln
GoogleDetected
AviraHEUR/AGEN.1307404
VaristW32/MSIL_Agent.BTI.gen!Eldorado
Antiy-AVLTrojan/MSIL.Agent
Kingsoftmalware.kb.c.1000
MicrosoftBackdoor:MSIL/AsyncRAT.X!MTB
ArcabitTrojan.Generic.D1232F
SUPERAntiSpywareTrojan.Agent/GenericKD
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
GDataMSIL.Backdoor.DCRat.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C4526491
VBA32Trojan.MSIL.DarkCrystal.Heur
ALYacTrojan.GenericKDZ.74543
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/GdSda.A
TencentBackdoor.MSIL.Crysan.hb
YandexTrojan.Agent!stQsINrL6bU
SentinelOneStatic AI - Malicious PE
MaxSecureTrojan.Malware.74418669.susgen
FortinetMSIL/Agent.CFQ!tr
BitDefenderThetaGen:NN.ZemsilF.36792.cm0@aShtBmj
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.104e8e
AvastWin32:BackdoorX-gen [Trj]

Network contacts

172.66.171.73 3.66.38.117 3.69.157.220 52.28.247.255 3.69.115.178 18.197.239.109 3.68.171.119 104.20.67.143 3.132.159.158

DNS requests

6.tcp.eu.ngrok.io pastebin.com 6.tcp.ngrok.io

Process list

NameCommand line
bRxV.exe