bef8327c64ee14576b2f9a800d74b5a6.exe
Classification: Malicious
bef8327c64ee14576b2f9a800d74b5a6.exe is a malicious file sample. Linked to Crimson malware. Reported by 1 threat source, last seen 2022-05-08.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: CRIMSON (S0115)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| CrimsonRAT | MalwareBazaar Abuse.ch | 2022-05-08 05:42:42 | 2022-05-08 05:42:42 | malicious-activity | S0115 Crimson |
Sample information
- Filenames
- bef8327c64ee14576b2f9a800d74b5a6.exe
- File type
- application/x-dosexec
- MD5
bef8327c64ee14576b2f9a800d74b5a6- SHA-1
ea665edb2f4bcc0c630a09f00299b2f034be1127- SHA-256
33efd821e2484eda83e99247859286a78c16be9deea18bc1e563ad91cb789ea5- First indexed
- 2022-05-08 06:15:03
- Last updated
- 2025-02-18 07:29:46
Antivirus detections
| Engine | Detection |
|---|---|
| Elastic | malicious (high confidence) |
| Cylance | Unsafe |
| ESET-NOD32 | a variant of MSIL/Agent.BNY |
| ClamAV | Win.Spyware.CrimsonRat-9859243-0 |
| F-Secure | Trojan.TR/Spy.Gen |
| DrWeb | BackDoor.SpyBotNET.47 |
| Avira | TR/Spy.Gen |
| Cynet | Malicious (score: 99) |
| AhnLab-V3 | Malware/Win32.RL_Generic.C4268806 |
| BitDefenderTheta | Gen:NN.ZemsilF.34606.@p1@aa44LIi |
| SentinelOne | Static AI - Malicious PE |
| ALYac | IL:Trojan.MSILZilla.19272 |
| AVG | Win32:Trojan-gen |
| Alibaba | Ransom:MSIL/Foreign.c5e28fc9 |
| Antiy-AVL | Trojan/MSIL.Agent |
| Arcabit | IL:Trojan.MSILZilla.D4B48 |
| Avast | Win32:Trojan-gen |
| BitDefender | IL:Trojan.MSILZilla.19272 |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.YakbeexMSIL.ZZ4 |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| DeepInstinct | MALICIOUS |
| Emsisoft | IL:Trojan.MSILZilla.19272 (B) |
| FireEye | IL:Trojan.MSILZilla.19272 |
| Fortinet | MSIL/Agent.BNY!tr |
| GData | IL:Trojan.MSILZilla.19272 |
| Detected | |
| Ikarus | Trojan.MSIL.Agent |
| Jiangmin | Trojan.MSIL.amqzv |
| K7AntiVirus | Trojan ( 005393351 ) |
| K7GW | Trojan ( 005393351 ) |
| Kaspersky | HEUR:Trojan-Ransom.MSIL.Foreign.gen |
| Lionic | Trojan.Win32.Foreign.1f!c |
| MaxSecure | Trojan.Malware.73715240.susgen |
| McAfee | Artemis!BEF8327C64EE |
| McAfeeD | ti!33EFD821E248 |
| MicroWorld-eScan | IL:Trojan.MSILZilla.19272 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Paloalto | generic.ml |
| Rising | Ransom.Foreign!8.292 (CLOUD) |
| Sangfor | Ransom.Msil.Agent.Vzoa |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | Trojan Horse |
| Tencent | Msil.Trojan.Foreign.Bdhl |
| TrendMicro | TROJ_FRS.0NA103E922 |
| TrendMicro-HouseCall | TROJ_FRS.0NA103E922 |
| VBA32 | Backdoor.MSIL.Crimson.Heur |
| VIPRE | IL:Trojan.MSILZilla.19272 |
| Varist | W32/ABTrojan.TTJT-2166 |
| Xcitium | Malware@#1ghjp9y0g8jto |
| Yandex | Trojan.Agent!hwQMO4FZ+f8 |
| Zillya | Trojan.Agent.Win32.2776996 |
| ZoneAlarm | HEUR:Trojan-Ransom.MSIL.Foreign.gen |
| alibabacloud | Ransomware:MSIL/Foreign.gyf |
| huorong | Backdoor/MSIL.CrimsonRat.b |