Sample Icon

NFE_87654.MSI

CLASSIFICATION

Malicious

20

Antivirus detections

0

IDS alerts

0

Processes

0

Contacted hosts

0

DNS Requests
Indicator Context

Blacklist timeline

Malicious
3 years since the last reported activity  
No activityreported afterDec 16, 202108 AM08:1508:3008:45Abuse.chMalwareBazaar Abuse.chGeneric.MalwareGeneric.Malware

Sample information


Hashes
Filename:
NFE_87654.MSI
md5:
c71b4979cdfa8207b81f9f67de37d68c
sha1:
6d7515b63ef2c4cf8644e5c2036a138a2181c3bc
sha256:
e30b091e3162eed18f8c1b6a69bb7a28a4c722128456ee36a326a79a3367f514
In depth details
Filetype:
application/x-msi
Classification:
malicious
Dates
Indexed:
2021-12-16 09:15:19
Last modified:
2021-12-18 08:15:49
Explore our API specification anytime here:

Request:

          
curl -H "Authorization: Bearer <API_KEY>" https://api.maltiverse.com/sample/e30b091e3162eed18f8c1b6a69bb7a28a4c722128456ee36a326a79a3367f514
        

Response:

      
{
    "antivirus": [
        {
            "description": "Trojan.GenericKD.47665530",
            "name": "FireEye"
        },
        {
            "description": "RDN/Generic Downloader.x",
            "name": "McAfee"
        },
        {
            "description": "ISB.Downloader!gen60",
            "name": "Symantec"
        },
        {
            "description": "JS/TrojanDownloader.Agent.YBJ",
            "name": "ESET-NOD32"
        },
        {
            "description": "Other:Malware-gen [Trj]",
            "name": "Avast"
        },
        {
            "description": "Malicious (score: 99)",
            "name": "Cynet"
        },
        {
            "description": "HEUR:Trojan-Downloader.Script.SLoad.gen",
            "name": "Kaspersky"
        },
        {
            "description": "Trojan.GenericKD.47665530",
            "name": "BitDefender"
        },
        {
            "description": "Trojan.GenericKD.47665530",
            "name": "MicroWorld-eScan"
        },
        {
            "description": "Trojan.GenericKD.47665530",
            "name": "Ad-Aware"
        },
        {
            "description": "TrojWare.Win32.Agent.ivulm@0",
            "name": "Comodo"
        },
        {
            "description": "Trojan.DownLoader44.17254",
            "name": "DrWeb"
        },
        {
            "description": "RDN/Generic Downloader.x",
            "name": "McAfee-GW-Edition"
        },
        {
            "description": "Trojan.GenericKD.47665530 (B)",
            "name": "Emsisoft"
        },
        {
            "description": "JS/Dldr.Agent.igrel",
            "name": "Avira"
        },
        {
            "description": "Trojan.GenericKD.47665530",
            "name": "GData"
        },
        {
            "description": "Trojan.GenericKD.47665530",
            "name": "ALYac"
        },
        {
            "description": "malware (ai score=82)",
            "name": "MAX"
        },
        {
            "description": "JS/Agent.YBJ!tr.dldr",
            "name": "Fortinet"
        },
        {
            "description": "Other:Malware-gen [Trj]",
            "name": "AVG"
        }
    ],
    "blacklist": [
        {
            "count": 1,
            "description": "Generic.Malware",
            "first_seen": "2021-12-16 07:57:34",
            "labels": [
                "malicious-activity"
            ],
            "last_seen": "2021-12-16 07:57:34",
            "source": "MalwareBazaar Abuse.ch"
        },
        {
            "count": 1,
            "description": "Generic.Malware",
            "first_seen": "2021-12-16 07:57:34",
            "labels": [
                "malicious-activity"
            ],
            "last_seen": "2021-12-16 07:57:34",
            "source": "Abuse.ch"
        }
    ],
    "classification": "malicious",
    "creation_time": "2021-12-16 09:15:19",
    "filename": [
        "NFE_87654.MSI"
    ],
    "filetype": "application/x-msi",
    "is_alive": false,
    "is_cdn": false,
    "is_cnc": false,
    "is_distributing_malware": false,
    "is_hosting": false,
    "is_iot_threat": false,
    "is_known_attacker": false,
    "is_known_scanner": false,
    "is_mining_pool": false,
    "is_open_proxy": false,
    "is_phishing": false,
    "is_sinkhole": false,
    "is_storing_phishing": false,
    "is_tor_node": false,
    "is_vpn_node": false,
    "md5": "c71b4979cdfa8207b81f9f67de37d68c",
    "modification_time": "2021-12-18 08:15:49",
    "scoring_executed_time": "2025-09-17 17:42:30",
    "sha1": "6d7515b63ef2c4cf8644e5c2036a138a2181c3bc",
    "sha256": "e30b091e3162eed18f8c1b6a69bb7a28a4c722128456ee36a326a79a3367f514",
    "type": "sample"
}