.exe

Classification: Malicious

.exe is a malicious file sample. Reported by 1 threat source, last seen 2020-07-22. Detected by 58 antivirus engines.

Detection summary

  • 58 antivirus detections
  • 0 IDS alerts
  • 3 processes observed
  • 0 contacted hosts
  • 2 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic.Malware Hybrid-Analysis 2020-07-22 07:45:14 2020-07-22 07:45:14

Sample information

Filenames
.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
167936 bytes
MD5
0a27577e43e0eed9f95ccdf4621485c1
SHA-1
ee24f854350b1aedcbedc6d36d61c412f132742e
SHA-256
278e240ca04128d8dafb8b252e8428dc27b2c7ecce4711f742ac7d52e274efbb
First indexed
2020-07-22 07:45:14
Last updated
2026-09-03 00:42:52

Antivirus detections

EngineDetection
ALYacGen:Variant.Barys.474606
APEXMalicious
AVGWin32:Evo-gen [Trj]
AhnLab-V3Trojan/Win32.KorAd.R50608
AlibabaTrojanDownloader:Win32/Doomne.b2c0ff8e
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Barys.D73DEE
AvastWin32:Evo-gen [Trj]
AviraTR/Crypt.XPACK.Gen7
BaiduWin32.Trojan-Downloader.Agent.kc
BitDefenderGen:Variant.Barys.474606
CAT-QuickHealTrojan.Mauvaise.SL1
CTXexe.unknown.barys
ClamAVWin.Trojan.Agent-1383332
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebTrojan.Click2.61121
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.RPS
Elasticmalicious (high confidence)
EmsisoftGen:Variant.Barys.474606 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
FireEyeGeneric.mg.0a27577e43e0eed9
FortinetW32/Agent.RPS!tr.dldr
GDataGen:Variant.Barys.474606
GoogleDetected
IkarusTrojan-Downloader.Agent
JiangminTrojan/Generic.avnqz
K7AntiVirusTrojan-Downloader ( 0042f5621 )
K7GWTrojan-Downloader ( 0042f5621 )
KasperskyHEUR:Trojan.Win32.Generic
Kingsoftmalware.kb.a.999
LionicTrojan.Win32.Generic.4!c
MalwarebytesMalware.AI.2713566672
MaxSecureTrojan.Malware.300983.susgen
McAfeeAdClicker-FAT!0A27577E43E0
McAfeeDti!278E240CA041
MicroWorld-eScanGen:Variant.Barys.474606
MicrosoftTrojanDownloader:Win32/Doomne!pz
NANO-AntivirusTrojan.Win32.Clicker.dgkdee
PandaTrj/Genetic.gen
RisingDownloader.Agent!8.B23 (CLOUD)
SangforTrojan.Win32.Wacatac.C
SentinelOneStatic AI - Suspicious PE
SkyhighAdClicker-FAT!0A27577E43E0
SophosMal/Generic-S
SymantecTrojan Horse
TencentMalware.Win32.Gencirc.10b2e89f
VBA32BScope.Trojan.Click
VIPREGen:Variant.Barys.474606
VaristW32/Agent.WB.gen!Eldorado
VirITTrojan.Win32.Generic.PH
XcitiumTrojWare.Win32.Agent.RPS@54x40w
YandexTrojan.DL.Agent!eUxMCRsQTCA
ZillyaDownloader.Agent.Win32.228049
alibabacloudTrojan[downloader]:Win/Agent.509f9afd
huorongTrojanDownloader/Agent.yk

DNS requests

doomp3.net me2.do

Process list

NameCommand line
.exe
iexplore.exehttp://me2.do/5UYIrms
iexplore.exeSCODEF:3252 CREDAT:275457 /prefetch:2