x2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.exe
Classification: Malicious
x2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.exe is a malicious file sample. Linked to Dcrat malware. Detected by 53 antivirus engines.
Detection summary
- 53 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: DCRAT (S9017)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-03-11 10:45:05 | 2026-03-11 10:45:05 | ||
| Dcrat | Triage | 2026-03-11 10:00:44 | 2026-03-11 10:00:44 | malicious-activity | S9017 DCRAT |
Tags
evasive windows-server-utility dcrat defense_evasion discovery execution infostealer persistence rat trojanSample information
- Filenames
- x2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.exe, 2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c.bin
- File type
- PE32 executable for MS Windows 5.00 (GUI), Intel i ...
- MD5
8d5f46f42a6bf42cfb4bb0a9c1a657fc- SHA-1
965c20ecec749594a1f47e6cea99210202ad686c- SHA-256
2bbd647144ffe221dbe3fba7bd18685c451ecf219abf283433759dcb0edc8d9c- SHA-512
3846a06736064f1a2ac91337dedbe74011c1cfd1af6c18f0164c0babac3fc8c61ba52f2da098636e711d9924b8dc31b2097a1edd56ce2732fad3c4fdb6ccce8c- First indexed
- 2026-03-11 10:00:44
- Last updated
- 2026-09-02 23:06:52
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.GPZU |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.DCRat.R729785 |
| Antiy-AVL | Trojan[Backdoor]/MSIL.DCRat |
| Arcabit | Trojan.Agent.GPZU |
| Avast | Win32:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1323984 |
| BitDefender | Trojan.Agent.GPZU |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.gpzu |
| ClamAV | Win.Malware.Gpzu-10058391-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen31.31069 |
| ESET-NOD32 | MSIL/Agent.VRB trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Agent.GPZU (B) |
| F-Secure | Heuristic.HEUR/AGEN.1323984 |
| Fortinet | W32/Agent.VRB!tr |
| GData | Trojan.Agent.GPZU |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0001140e1 ) |
| K7GW | Trojan ( 0001140e1 ) |
| Kaspersky | HEUR:Backdoor.MSIL.DcRat.pef |
| Kingsoft | malware.kb.a.948 |
| Malwarebytes | Spyware.Passwordstealer |
| MaxSecure | Trojan.Malware.592349324.susgen |
| McAfeeD | Real Protect-LS!8D5F46F42A6B |
| MicroWorld-eScan | Trojan.Agent.GPZU |
| Microsoft | Trojan:Win32/DCRat.MX!MTB |
| Rising | Trojan.Loader!1.13B97 (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Stealer |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Spyware.tc |
| Sophos | Troj/DCRat-AC |
| Tencent | Trojan.Msil.Agent.hbf |
| TrellixENS | GenericRXWS-LY!8D5F46F42A6B |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9z |
| VBA32 | Backdoor.MSIL.DcRat |
| VIPRE | Trojan.Agent.GPZU |
| Varist | W32/Trojan.DAIU-7549 |
| VirIT | Trojan.Win32.GenusT.EXYL |
| Webroot | Win.Malware.Gen |
| Zillya | Trojan.Stealer.Win32.199293 |
| ZoneAlarm | Troj/DCRat-AC |
| huorong | Backdoor/MSIL.DCRat.x |
| tehtris | Generic.Malware |