Malware

MSIL/AsyncRAT (file analysis)

Malware Removal

The MSIL/AsyncRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/AsyncRAT virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the AsyncRat malware family

How to determine MSIL/AsyncRAT?


File Info:

name: B26159574B8B5166CF51.mlw
path: /opt/CAPEv2/storage/binaries/de7665ce6f22c1ac64551d94ceb84818f85e673cae5af122773622b6c896734d
crc32: ABFE9194
md5: b26159574b8b5166cf5120bd6760fd4b
sha1: feae105fa3ea1f53398fea8328a07bc1d731722f
sha256: de7665ce6f22c1ac64551d94ceb84818f85e673cae5af122773622b6c896734d
sha512: c20bb5065d3f7363e40c8f1ea0c4798fc3994c98f033cf3f7fe21bcb65bee6d946eac074abaa72e0a224a48524331346e3d9541f1417b235237112dd8919c100
ssdeep: 768:YuSBGTAo1wxWUpdj7mo2qLXMHgh/W96tPIRbR1m0bTi76v7ceFAXupr/4BDZrx:YuSBGTA2g2o/W9LRbBbTi7U7ceAupKdl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122232B003BE8812BF2BE4F74A9F262458677F5637602D58D2CC452D75A13FC68A426FE
sha3_384: 1fb7dd573a23488292f9a57f92d99027f2152314d68fbc25a80c104d38e65ece3ff67711cef734ef690cdabbfced3ef6
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-10-16 21:40:53

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Stub.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Stub.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/AsyncRAT also known as:

BkavW32.AIDetectMalware.CS
DrWebTrojan.Siggen9.56514
MicroWorld-eScanGen:Trojan.Mardom.MN.13
CAT-QuickHealTrojan.IgenericFC.S14890850
SkyhighBehavesLike.Win32.Fareit.pm
ALYacGen:Trojan.Mardom.MN.13
Cylanceunsafe
VIPREGen:Trojan.Mardom.MN.13
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005678321 )
K7GWTrojan ( 005678321 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.36680.cm0@aOysSPp
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Asyncrat
ESET-NOD32a variant of MSIL/AsyncRAT
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9625918-0
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderGen:Trojan.Mardom.MN.13
AvastWin32:DropperX-gen [Drp]
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
EmsisoftGen:Trojan.Mardom.MN.13 (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Agent.Win32.1426391
TrendMicroBackdoor.MSIL.ASYNCRAT.SMXSR
SophosTroj/AsyncRat-B
IkarusTrojan.MSIL.Agent
GDataMSIL.Trojan.PSE.1BITXMO
JiangminBackdoor.MSIL.gguk
VaristW32/Samas.B.gen!Eldorado
AviraTR/Dropper.Gen
ArcabitTrojan.Mardom.MN.13
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
MicrosoftBackdoor:MSIL/AsyncRat.AD!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.R358277
McAfeeFareit-FZT!B26159574B8B
VBA32OScope.Backdoor.MSIL.Crysan
MalwarebytesGeneric.Malware.AI.DDS
TencentTrojan.Msil.Agent.zap
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.CFQ!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.fa3ea1
DeepInstinctMALICIOUS

How to remove MSIL/AsyncRAT?

MSIL/AsyncRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment