x2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.exe

Classification: Malicious

x2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.exe is a malicious file sample. Linked to Dcrat malware. Detected by 53 antivirus engines.

Detection summary

  • 53 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: DCRAT (S9017)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2026-03-11 10:45:05 2026-03-11 10:45:05
Dcrat Triage 2026-03-11 10:00:44 2026-03-11 10:00:44 malicious-activity S9017 DCRAT

Tags

evasive windows-server-utility dcrat defense_evasion discovery execution infostealer persistence rat trojan

Sample information

Filenames
x2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.exe, 2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.bin
File type
PE32 executable for MS Windows 5.00 (GUI), Intel i ...
MD5
8d5f46f42a6bf42cfb4bb0a9c1a657fc
SHA-1
965c20ecec749594a1f47e6cea99210202ad686c
SHA-256
2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c
SHA-512
3846a06736064f1a2ac91337dedbe74011c1cfd1af6c18f0164c0babac3fc8c61ba52f2da098636e711d9924b8dc31b2097a1edd56ce2732fad3c4fdb6ccce8c
First indexed
2026-03-11 10:00:44
Last updated
2026-09-02 23:06:52

Antivirus detections

EngineDetection
ALYacTrojan.Agent.GPZU
APEXMalicious
AVGWin32:Evo-gen [Trj]
AhnLab-V3Backdoor/Win.DCRat.R729785
Antiy-AVLTrojan[Backdoor]/MSIL.DCRat
ArcabitTrojan.Agent.GPZU
AvastWin32:Evo-gen [Trj]
AviraHEUR/AGEN.1323984
BitDefenderTrojan.Agent.GPZU
BkavW32.AIDetectMalware
CTXexe.trojan.gpzu
ClamAVWin.Malware.Gpzu-10058391-0
CrowdStrikewin/malicious_confidence_100% (D)
CylanceUnsafe
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebTrojan.Siggen31.31069
ESET-NOD32MSIL/Agent.VRB trojan
Elasticmalicious (high confidence)
EmsisoftTrojan.Agent.GPZU (B)
F-SecureHeuristic.HEUR/AGEN.1323984
FortinetW32/Agent.VRB!tr
GDataTrojan.Agent.GPZU
GoogleDetected
GridinsoftTrojan.Win32.Agent.oa!s1
IkarusTrojan.MSIL.Agent
K7AntiVirusTrojan ( 0001140e1 )
K7GWTrojan ( 0001140e1 )
KasperskyHEUR:Backdoor.MSIL.DcRat.pef
Kingsoftmalware.kb.a.948
MalwarebytesSpyware.Passwordstealer
MaxSecureTrojan.Malware.592349324.susgen
McAfeeDReal Protect-LS!8D5F46F42A6B
MicroWorld-eScanTrojan.Agent.GPZU
MicrosoftTrojan:Win32/DCRat.MX!MTB
RisingTrojan.Loader!1.13B97 (CLASSIC)
SUPERAntiSpywareTrojan.Agent/Gen-Stealer
SangforSuspicious.Win32.Save.pkr
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Spyware.tc
SophosTroj/DCRat-AC
TencentTrojan.Msil.Agent.hbf
TrellixENSGenericRXWS-LY!8D5F46F42A6B
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9z
VBA32Backdoor.MSIL.DcRat
VIPRETrojan.Agent.GPZU
VaristW32/Trojan.DAIU-7549
VirITTrojan.Win32.GenusT.EXYL
WebrootWin.Malware.Gen
ZillyaTrojan.Stealer.Win32.199293
ZoneAlarmTroj/DCRat-AC
huorongBackdoor/MSIL.DCRat.x
tehtrisGeneric.Malware