Betaling.exe

Classification: Malicious

Betaling.exe is a malicious file sample. Linked to Rokrat malware. Reported by 3 threat sources, last seen 2024-07-18. Detected by 25 antivirus engines.

Detection summary

  • 25 antivirus detections
  • 1 IDS alerts
  • 18 processes observed
  • 1 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: ROKRAT (S0240)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
RokRAT ThreatFox Abuse.ch 2024-07-16 17:51:44 2024-07-18 17:20:35 S0240 ROKRAT
Generic Malware Hybrid-Analysis 2024-07-16 11:45:04 2024-07-16 12:15:11
XenoRAT MalwareBazaar Abuse.ch 2024-07-16 11:20:16 2024-07-16 11:20:16 malicious-activity

Tags

evasive windows-server-utility win.rokrat dogcall

Sample information

Filenames
Betaling.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
724065 bytes
MD5
76e42ae7f8be751dc2802f8429acad56
SHA-1
60b373bcd072ff1f31cb32abcb9f26387cfacb9e
SHA-256
1bca88ef695a571b209d53645981a5bf0d005491ee35b4bf7fb5890c4f7fb8d5
First indexed
2024-07-16 11:24:02
Last updated
2026-04-26 14:15:24

Antivirus detections

EngineDetection
ALYacTrojan.Uztuby.37
APEXMalicious
BitDefenderTrojan.Uztuby.37
BkavW32.AIDetectMalware
Cybereasonmalicious.7f8be7
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
Elasticmalicious (high confidence)
EmsisoftTrojan.Uztuby.37 (B)
FireEyeGeneric.mg.76e42ae7f8be751d
FortinetBAT/Runner.EMTH!tr
GDataTrojan.Uztuby.37
K7AntiVirusTrojan ( 005988231 )
K7GWTrojan ( 005988231 )
MalwarebytesGeneric.Malware.AI.DDS
McAfeeDti!1BCA88EF695A
MicroWorld-eScanTrojan.Uztuby.37
MicrosoftTrojan:Win32/Leonem
Paloaltogeneric.ml
SkyhighBehavesLike.Win32.Backdoor.bc
SophosGeneric ML PUA (PUA)
TrendMicro-HouseCallTROJ_GEN.R06CH09GF24
VIPRETrojan.Uztuby.37
VaristW32/Runner.L.gen!Eldorado

Network contacts

91.92.248.167

Process list

NameCommand line
Betaling.exe
cmd.exe%WINDIR%\system32\cmd.exe /c ""%APPDATA%\ghjostsdf.cmd" "
gfdhxdh.sfx.exe-piujmhngbfvdsdyethnymkdesppodtyuhngfszafugyRhvqxsdfHbgnmeN -d%USERPROFILE%\AppData\Roaming
gfdhxdh.exe
gfdhxdh.exe
WerFault.exe-u -p 6620 -s 76
gfdhxdh.exe
gfdhxdh.exe
gfdhxdh.exe
gfdhxdh.exe
gfdhxdh.exe
gfdhxdh.exe
gfdhxdh.exe
schtasks.exe/Create /TN "bel" /XML "%TEMP%\tmp158D.tmp" /F
gfdhxdh.exe
WerFault.exe-u -p 8488 -s 72
WerFault.exe-pss -s 392 -p 6620 -ip 6620
WerFault.exe-pss -s 164 -p 8488 -ip 8488