Classification: Malicious
.exe is a malicious file sample. Reported by 1 threat source, last seen 2020-07-22. Detected by 58 antivirus engines.
Detection summary
- 58 antivirus detections
- 0 IDS alerts
- 3 processes observed
- 0 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic.Malware |
Hybrid-Analysis |
2020-07-22 07:45:14 |
2020-07-22 07:45:14 |
|
|
Sample information
- Filenames
- .exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 167936 bytes
- MD5
0a27577e43e0eed9f95ccdf4621485c1
- SHA-1
ee24f854350b1aedcbedc6d36d61c412f132742e
- SHA-256
278e240ca04128d8dafb8b252e8428dc27b2c7ecce4711f742ac7d52e274efbb
- First indexed
- 2020-07-22 07:45:14
- Last updated
- 2026-09-03 00:42:52
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Barys.474606 |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Trojan/Win32.KorAd.R50608 |
| Alibaba | TrojanDownloader:Win32/Doomne.b2c0ff8e |
| Antiy-AVL | Trojan/Win32.AGeneric |
| Arcabit | Trojan.Barys.D73DEE |
| Avast | Win32:Evo-gen [Trj] |
| Avira | TR/Crypt.XPACK.Gen7 |
| Baidu | Win32.Trojan-Downloader.Agent.kc |
| BitDefender | Gen:Variant.Barys.474606 |
| CAT-QuickHeal | Trojan.Mauvaise.SL1 |
| CTX | exe.unknown.barys |
| ClamAV | Win.Trojan.Agent-1383332 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Click2.61121 |
| ESET-NOD32 | a variant of Win32/TrojanDownloader.Agent.RPS |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Barys.474606 (B) |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen7 |
| FireEye | Generic.mg.0a27577e43e0eed9 |
| Fortinet | W32/Agent.RPS!tr.dldr |
| GData | Gen:Variant.Barys.474606 |
| Google | Detected |
| Ikarus | Trojan-Downloader.Agent |
| Jiangmin | Trojan/Generic.avnqz |
| K7AntiVirus | Trojan-Downloader ( 0042f5621 ) |
| K7GW | Trojan-Downloader ( 0042f5621 ) |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| Kingsoft | malware.kb.a.999 |
| Lionic | Trojan.Win32.Generic.4!c |
| Malwarebytes | Malware.AI.2713566672 |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | AdClicker-FAT!0A27577E43E0 |
| McAfeeD | ti!278E240CA041 |
| MicroWorld-eScan | Gen:Variant.Barys.474606 |
| Microsoft | TrojanDownloader:Win32/Doomne!pz |
| NANO-Antivirus | Trojan.Win32.Clicker.dgkdee |
| Panda | Trj/Genetic.gen |
| Rising | Downloader.Agent!8.B23 (CLOUD) |
| Sangfor | Trojan.Win32.Wacatac.C |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | AdClicker-FAT!0A27577E43E0 |
| Sophos | Mal/Generic-S |
| Symantec | Trojan Horse |
| Tencent | Malware.Win32.Gencirc.10b2e89f |
| VBA32 | BScope.Trojan.Click |
| VIPRE | Gen:Variant.Barys.474606 |
| Varist | W32/Agent.WB.gen!Eldorado |
| VirIT | Trojan.Win32.Generic.PH |
| Xcitium | TrojWare.Win32.Agent.RPS@54x40w |
| Yandex | Trojan.DL.Agent!eUxMCRsQTCA |
| Zillya | Downloader.Agent.Win32.228049 |
| alibabacloud | Trojan[downloader]:Win/Agent.509f9afd |
| huorong | TrojanDownloader/Agent.yk |
Process list
| Name | Command line |
| .exe | |
| iexplore.exe | http://me2.do/5UYIrms |
| iexplore.exe | SCODEF:3252 CREDAT:275457 /prefetch:2 |