1610d005e2af505e573a49eecd7dadb7.exe

Classification: Malicious

1610d005e2af505e573a49eecd7dadb7.exe is a malicious file sample. Linked to Dcrat malware. Reported by 3 threat sources, last seen 2024-05-25.

Detection summary

  • 70 antivirus detections
  • 1 IDS alerts
  • 22 processes observed
  • 2 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Malware families: DCRAT (S9017)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DCRat ThreatFox Abuse.ch 2024-05-23 15:22:41 2024-05-25 15:22:36 S9017 DCRAT
Generic Malware Hybrid-Analysis 2024-05-23 05:15:03 2024-05-23 06:15:07
DCRat MalwareBazaar Abuse.ch 2024-05-23 04:55:11 2024-05-23 04:55:11 malicious-activity S9017 DCRAT

Tags

evasive windows-server-utility win.dcrat darkcrystal rat

Sample information

Filenames
1610d005e2af505e573a49eecd7dadb7.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
1342976 bytes
MD5
1610d005e2af505e573a49eecd7dadb7
SHA-1
a1ddc7111c710191d364cfba6943d8be87d4f454
SHA-256
0f0009550ad8a696b79efaddb21f8ce26236c5c302c5159e0af3d7fe75b57fd3
First indexed
2024-05-23 04:58:29
Last updated
2026-09-02 19:15:21

Antivirus detections

EngineDetection
ALYacGen:Variant.Ransom.Prometheus.2
APEXMalicious
Acronissuspicious
AhnLab-V3Trojan/Win.FUJL.C5119684
ArcabitTrojan.Ransom.Prometheus.2
AviraHEUR/AGEN.1323984
BitDefenderThetaGen:NN.ZemsilF.36804.rr0@ay5ykkoi
BkavW32.AIDetectMalware
ClamAVWin.Packed.Msilmamut-9950860-0
Cylanceunsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/Spy.Agent.DTP
EmsisoftGen:Variant.Ransom.Prometheus.2 (B)
FireEyeGeneric.mg.1610d005e2af505e
FortinetMSIL/Agent.DVA!tr
IkarusTrojan.MSIL.Injector
K7AntiVirusSpyware ( 0058ebd51 )
K7GWSpyware ( 0058ebd51 )
LionicVirus.Generic.AI.1!c
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
McAfeeDReal Protect-LS!1610D005E2AF
MicroWorld-eScanGen:Variant.Ransom.Prometheus.2
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SymantecML.Attribute.HighConfidence
TencentTrojan.Msil.Dcrat.xa
VIPREGen:Variant.Ransom.Prometheus.2
VirITTrojan.Win32.MSIL_Heur.A
tehtrisGeneric.Malware
AVGWin32:MalwareX-gen [Rat]
AlibabaBackdoor:MSIL/DCRat.e74017ac
AvastWin32:MalwareX-gen [Rat]
BitDefenderGen:Variant.Ransom.Prometheus.2
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.DCRat.S29707587
CTXexe.trojan.msil
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DrWebTrojan.PWS.StealerNET.124
ESET-NOD32MSIL/Spy.Agent.DTP trojan
Elasticmalicious (high confidence)
F-SecureHeuristic.HEUR/AGEN.1323984
FortinetMSIL/Agent.DTP!tr.spy
GDataGen:Variant.Ransom.Prometheus.2
GoogleDetected
IkarusTrojan-Spy.Agent
K7AntiVirusTrojan ( 005c37eb1 )
KasperskyHEUR:Backdoor.MSIL.DCRat.gen
KingsoftMSIL.Backdoor.DCRat.gen
LionicTrojan.Win32.DCRat.m!c
MalwarebytesGeneric.Malware.Gen.DDS
MaxSecureTrojan.Malware.121218.susgen
MicrosoftBackdoor:MSIL/DCRat!MTB
NANO-AntivirusTrojan.Win32.DCRat.kqpbuj
Paloaltogeneric.ml
PandaTrj/GdSda.A
RisingBackdoor.DcRat!8.129D9 (CLOUD)
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
SkyhighBehavesLike.Win32.Generic.tc
SophosTroj/DCRat-N
SymantecTrojan.Whispergate
TrellixENSTrojan-FUJL!1610D005E2AF
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9t
VBA32TScope.Trojan.MSIL
VaristW32/MSIL_Agent.LQ.gen!Eldorado
ZillyaTrojan.BasicGen.Win32.4
ZoneAlarmTroj/DCRat-N
alibabacloudBackdoor:MSIL/DCRat.gyf
huorongTrojanSpy/MSIL.Stealer.n

Network contacts

141.8.192.26 20.211.142.183

DNS requests

a0985859.xsph.ru

Process list

NameCommand line
1610d005e2af505e573a49eecd7dadb7.exe
backgroundTaskHost.exe
taskhostw.exe
WinStore.App.exe
csrss.exe
backgroundTaskHost.exe
backgroundTaskHost.exe
WinStore.App.exe
csrss.exe
backgroundTaskHost.exe
WinStore.App.exe
csrss.exe
backgroundTaskHost.exe
csrss.exe
backgroundTaskHost.exe
WinStore.App.exe
csrss.exe
taskhostw.exe
backgroundTaskHost.exe
WinStore.App.exe
csrss.exe
WinStore.App.exe