ExeFile (69).exe

Classification: Malicious

ExeFile (69).exe is a malicious file sample. Linked to Dok malware. Reported by 2 threat sources, last seen 2026-03-18. Detected by 74 antivirus engines.

Detection summary

  • 74 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: DOK (S0281)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Triage 2026-03-18 01:00:04 2026-03-18 01:00:04 malicious-activity
Retefe ThreatFox Abuse.ch 2024-08-21 00:58:50 2024-08-23 00:22:01 S0281 Dok

Tags

win.retefe tsukuba werdlod discovery dropper

Sample information

Filenames
ExeFile (69).exe
MD5
bbbd7535034d9bb440dd2b71c724b1e9
SHA-1
3cac48e520e29055e37e32823e8e8c1db8c7da4d
SHA-256
146fb98d6e239d844dee837aa55ff873d0599d2af7400a1b6fba74ee0eb5c7c3
SHA-512
f05c6f43182dcd9221dba3bed02214ada5092abbe6a725e8e6cdb092dd587e058c8f69ecd79d5bcc93ae631e9451d2b3a6b4f99f820763aa148c56fa40a32960
First indexed
2024-08-21 01:17:08
Last updated
2026-05-11 06:57:22

Antivirus detections

EngineDetection
ALYacGen:Variant.Jaik.52780
APEXMalicious
AVGWin32:Evo-gen [Trj]
AhnLab-V3Trojan/Win32.Agent.R210910
AlibabaTrojan:JS/Retefe.cc05450f
Antiy-AVLTrojan/Script.Agent
ArcabitTrojan.Jaik.DCE2C
AvastWin32:Evo-gen [Trj]
AviraHEUR/AGEN.1316616
BitDefenderGen:Variant.Jaik.52780
BkavW32.AIDetectMalware
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.5034d9
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebTrojan.MulDrop7.44903
ESET-NOD32JS/Retefe.M
Elasticmalicious (high confidence)
EmsisoftGen:Variant.Jaik.52780 (B)
F-SecureHeuristic.HEUR/AGEN.1316616
FireEyeGeneric.mg.bbbd7535034d9bb4
FortinetW32/Script.AGENT!tr
GDataGen:Variant.Jaik.52780
GoogleDetected
IkarusTrojan.Retefe
JiangminTrojan.Script.arrn
K7AntiVirusTrojan ( 0050713b1 )
K7GWTrojan ( 0050713b1 )
KasperskyHEUR:Trojan.Script.Agent.gen
Kingsoftmalware.kb.a.985
LionicTrojan.Win32.Retefe.4!c
MAXmalware (ai score=100)
MalwarebytesMalware.AI.4160396355
McAfeeGeneric!Emotet.c
McAfeeDti!146FB98D6E23
MicroWorld-eScanGen:Variant.Jaik.52780
MicrosoftTrojan:Win32/Dynamer!rfn
NANO-AntivirusTrojan.Win32.Retefe.etwzps
PandaTrj/CI.A
RisingTrojan.MalCert!1.F6F3 (CLASSIC)
SangforTrojan.Win32.Retefe.V1ay
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
TencentMalware.Win32.Gencirc.114b3f0f
Trapminemalicious.high.ml.score
TrendMicroTROJ_GEN.R06EC0PHL24
TrendMicro-HouseCallTROJ_GEN.R06EC0PHL24
VBA32Trojan.Script
VIPREGen:Variant.Jaik.52780
VirITAdware.Win32.Generic.PD
WebrootW32.Trojan.Gen
XcitiumMalware@#2n1t0mmqc0vlt
YandexTrojan.GenAsa!1tMNwXRaF9w
ZillyaTrojan.Agent.Win32.851480
ZoneAlarmUDS:DangerousObject.Multi.Generic
alibabacloudTrojan:Javascript/Retefe.M
huorongTrojan/JS.Retefe
BkavW32.Common.3D26ABD8
CAT-QuickHealTrojan.Ghanarava.173123304924b1e9
CTXexe.trojan.retefe
KasperskyUDS:DangerousObject.Multi.Generic
KingsoftScript.Trojan.Agent.gen
MalwarebytesMalware.AI.1625783824
MaxSecureTrojan.Malware.9502894.susgen
SangforTrojan.Win32.Retefe.Vazx
SentinelOneStatic AI - Suspicious PE
SkyhighBehavesLike.Win32.Generic.fc
TrellixENSGeneric!Emotet.c
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9h
VaristW32/ABTrojan.OYJX-6100
ViRobotTrojan.Win32.Z.Agent.308388
ZoneAlarmTroj/Agent-AXJX
huorongTrojan/JS.Agent.eo