00bdb3b40016cf57e926188ce256845c7b17d73f1d95b89d4a19d691cf185242.bin
Classification: Malicious
00bdb3b40016cf57e926188ce256845c7b17d73f1d95b89d4a19d691cf185242.bin is a malicious file sample. Linked to Dcrat malware. Detected by 57 antivirus engines.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: DCRAT (S9017)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-04-25 02:45:04 | 2026-04-25 05:45:08 | ||
| Dcrat | Triage | 2026-04-25 02:17:03 | 2026-04-25 02:17:03 | malicious-activity | S9017 DCRAT |
Tags
evasive windows-server-utility dcrat defense_evasion discovery execution infostealer persistence rat trojanSample information
- Filenames
- 00bdb3b40016cf57e926188ce256845c7b17d73f1d95b89d4a19d691cf185242.bin, x00bdb3b40016cf57e926188ce256845c7b17d73f1d95b89d4a19d691cf185242.exe
- File type
- PE32 executable for MS Windows 5.00 (GUI), Intel i ...
- MD5
b88fc5ba024c2e0745053c74b5b710ad- SHA-1
3ae907127ffbe434da54c0d7c410ec702fcce995- SHA-256
00bdb3b40016cf57e926188ce256845c7b17d73f1d95b89d4a19d691cf185242- First indexed
- 2026-04-25 02:17:03
- Last updated
- 2026-09-03 00:24:13
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.GQAF |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.DCRat.R715971 |
| Alibaba | Trojan:Win32/DCRat.b8d1a200 |
| Antiy-AVL | Trojan/Win32.DCRat |
| Arcabit | Trojan.Agent.GQAF |
| Avast | Win32:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1323984 |
| BitDefender | Trojan.Agent.GQAF |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.dcrat |
| ClamAV | Win.Malware.Gqaf-10058390-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen31.36139 |
| ESET-NOD32 | MSIL/Agent.VRB trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Agent.GQAF (B) |
| F-Secure | Heuristic.HEUR/AGEN.1323984 |
| Fortinet | W32/Agent.VRB!tr |
| GData | Trojan.Agent.GQAF |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0001140e1 ) |
| K7GW | Trojan ( 0001140e1 ) |
| Kaspersky | UDS:Backdoor.MSIL.DcRat |
| Kingsoft | malware.kb.a.990 |
| Malwarebytes | Spyware.Passwordstealer |
| MaxSecure | Trojan.Malware.120990306.susgen |
| McAfeeD | Real Protect-LS!B88FC5BA024C |
| MicroWorld-eScan | Trojan.Agent.GQAF |
| Microsoft | Trojan:Win32/DCRat.MX!MTB |
| Paloalto | generic.ml |
| Rising | Trojan.Agent!8.B1E (CLOUD) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Stealer |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Injector.tc |
| Sophos | Troj/DCRat-AC |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Msil.Agent.16002036 |
| TrellixENS | GenericRXWS-RE!B88FC5BA024C |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9z |
| VBA32 | Trojan.Agent |
| VIPRE | Trojan.Agent.GQAF |
| Varist | W32/Trojan.LOUW-4466 |
| ViRobot | Trojan.Win.Z.Agent.1773568.VLW |
| VirIT | Trojan.Win32.GenusC.IME |
| Webroot | W32.Trojan.Gen |
| ZoneAlarm | Troj/DCRat-AC |
| alibabacloud | Trojan:MSIL/DCRat.MD8PHU |
| huorong | Backdoor/DcRAT.e |
| tehtris | Generic.Malware |