Classification: Malicious
Betaling.exe is a malicious file sample. Linked to Rokrat malware. Reported by 3 threat sources, last seen 2024-07-18. Detected by 25 antivirus engines.
Detection summary
- 25 antivirus detections
- 1 IDS alerts
- 18 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| RokRAT |
ThreatFox Abuse.ch |
2024-07-16 17:51:44 |
2024-07-18 17:20:35 |
|
S0240 ROKRAT
|
| Generic Malware |
Hybrid-Analysis |
2024-07-16 11:45:04 |
2024-07-16 12:15:11 |
|
|
| XenoRAT |
MalwareBazaar Abuse.ch |
2024-07-16 11:20:16 |
2024-07-16 11:20:16 |
malicious-activity
|
|
Tags
evasive
windows-server-utility
win.rokrat
dogcall
Sample information
- Filenames
- Betaling.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 724065 bytes
- MD5
76e42ae7f8be751dc2802f8429acad56
- SHA-1
60b373bcd072ff1f31cb32abcb9f26387cfacb9e
- SHA-256
1bca88ef695a571b209d53645981a5bf0d005491ee35b4bf7fb5890c4f7fb8d5
- First indexed
- 2024-07-16 11:24:02
- Last updated
- 2026-04-26 14:15:24
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Uztuby.37 |
| APEX | Malicious |
| BitDefender | Trojan.Uztuby.37 |
| Bkav | W32.AIDetectMalware |
| Cybereason | malicious.7f8be7 |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Uztuby.37 (B) |
| FireEye | Generic.mg.76e42ae7f8be751d |
| Fortinet | BAT/Runner.EMTH!tr |
| GData | Trojan.Uztuby.37 |
| K7AntiVirus | Trojan ( 005988231 ) |
| K7GW | Trojan ( 005988231 ) |
| Malwarebytes | Generic.Malware.AI.DDS |
| McAfeeD | ti!1BCA88EF695A |
| MicroWorld-eScan | Trojan.Uztuby.37 |
| Microsoft | Trojan:Win32/Leonem |
| Paloalto | generic.ml |
| Skyhigh | BehavesLike.Win32.Backdoor.bc |
| Sophos | Generic ML PUA (PUA) |
| TrendMicro-HouseCall | TROJ_GEN.R06CH09GF24 |
| VIPRE | Trojan.Uztuby.37 |
| Varist | W32/Runner.L.gen!Eldorado |
Process list
| Name | Command line |
| Betaling.exe | |
| cmd.exe | %WINDIR%\system32\cmd.exe /c ""%APPDATA%\ghjostsdf.cmd" " |
| gfdhxdh.sfx.exe | -piujmhngbfvdsdyethnymkdesppodtyuhngfszafugyRhvqxsdfHbgnmeN -d%USERPROFILE%\AppData\Roaming |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| WerFault.exe | -u -p 6620 -s 76 |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| gfdhxdh.exe | |
| schtasks.exe | /Create /TN "bel" /XML "%TEMP%\tmp158D.tmp" /F |
| gfdhxdh.exe | |
| WerFault.exe | -u -p 8488 -s 72 |
| WerFault.exe | -pss -s 392 -p 6620 -ip 6620 |
| WerFault.exe | -pss -s 164 -p 8488 -ip 8488 |