rftg.msi
Classification: Malicious
rftg.msi is a malicious file sample. Linked to Bitter activity. Reported by 1 threat source, last seen 2022-05-13. Detected by 32 antivirus engines.
Detection summary
- 32 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BITTER (G1002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitter | MalwareBazaar Abuse.ch | 2022-05-13 08:17:30 | 2022-05-13 08:17:30 | malicious-activity | G1002 BITTER |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-05-13 08:17:30 | 2022-05-13 08:17:30 | malicious-activity |
Sample information
- Filenames
- rftg.msi
- File type
- application/x-msi
- MD5
72ff5729200a86d7d0e83dbfca87721b- SHA-1
272cf1e2c08f3ea4efd6b94bc9940f7c9c72aaf4- SHA-256
17b11e00f1fe31caeaa269e5e54c5ff0fe2a8a5d5cae79718cd4c3ca64e5b0a4- First indexed
- 2022-05-13 09:15:03
- Last updated
- 2026-04-04 18:53:29
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Agent.a!c |
| ClamAV | Win.Downloader.ZxxZ-9944378-0 |
| McAfee | Trojan-FTXR!59B043A91301 |
| Sangfor | Trojan.Win32.Agent.gen |
| K7AntiVirus | Trojan ( 005916701 ) |
| K7GW | Trojan ( 005916701 ) |
| Cyren | ABRisk.GXNS-8 |
| Symantec | Trojan.Gen.2 |
| ESET-NOD32 | a variant of Win32/TrojanDownloader.Small.BJH |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DE422 |
| Avast | Win32:Trojan-gen |
| Kaspersky | HEUR:Trojan-Downloader.Win32.Agent.gen |
| BitDefender | Trojan.GenericKD.49018128 |
| MicroWorld-eScan | Trojan.GenericKD.49018128 |
| Rising | Downloader.Agent!8.B23 (CLOUD) |
| Ad-Aware | Trojan.GenericKD.49018128 |
| Sophos | Mal/Generic-S |
| Zillya | Downloader.Agent.Win32.432146 |
| TrendMicro | TROJ_GEN.R002C0DE422 |
| McAfee-GW-Edition | Trojan-FTXR!59B043A91301 |
| FireEye | Trojan.GenericKD.49018128 |
| Emsisoft | Trojan.GenericKD.49018128 (B) |
| GData | Trojan.GenericKD.49018128 |
| MAX | malware (ai score=80) |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Arcabit | Trojan.Doina.D5A21 |
| Microsoft | TrojanDownloader:Win32/FraudLoad.AN!MTB |
| VBA32 | BScope.TrojanDownloader.Agent |
| ALYac | Gen:Variant.Doina.23073 |
| Ikarus | Trojan-Downloader.Win32.Small |
| Fortinet | W32/Agent!tr.dldr |
| AVG | Win32:Trojan-gen |