3cb65016ac6afa32e1a2935e562df289dbfba8e0c3aee9a418759ba2c9f985a6.bin
Classification: Malicious
3cb65016ac6afa32e1a2935e562df289dbfba8e0c3aee9a418759ba2c9f985a6.bin is a malicious file sample. Linked to Dcrat malware. Detected by 52 antivirus engines.
Detection summary
- 52 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: DCRAT (S9017)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-02-06 21:45:06 | 2026-02-06 23:45:25 | ||
| Dcrat | Triage | 2026-02-06 21:14:33 | 2026-02-06 21:14:33 | malicious-activity | S9017 DCRAT |
Tags
downloader evasive windows-server-utility dcrat defense_evasion discovery execution infostealer persistence rat trojanSample information
- Filenames
- 3cb65016ac6afa32e1a2935e562df289dbfba8e0c3aee9a418759ba2c9f985a6.bin, x3cb65016ac6afa32e1a2935e562df289dbfba8e0c3aee9a418759ba2c9f985a6.exe
- File type
- PE32 executable for MS Windows 5.00 (GUI), Intel i ...
- MD5
816c496a3d523929c71eb9abd32439f9- SHA-1
2e462cd7d9bb586365cb3d7b7493bd24148152cc- SHA-256
3cb65016ac6afa32e1a2935e562df289dbfba8e0c3aee9a418759ba2c9f985a6- SHA-512
faeb8e2019f95d130d504cc74691acab9cc8536774c16bd480a4f0348903974ec48305ce335c83fbfa2dd4223ede93c69b9be8bb040562997a195e7ea8a66ddc- First indexed
- 2026-02-06 21:14:33
- Last updated
- 2026-09-02 19:46:50
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.GPZU |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.DCRat.R721234 |
| Antiy-AVL | Trojan[Backdoor]/MSIL.DCRat |
| Arcabit | Trojan.Agent.GPZU |
| Avast | Win32:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1323984 |
| BitDefender | Trojan.Agent.GPZU |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.msil |
| ClamAV | Win.Malware.Gpzu-10058391-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen31.31069 |
| ESET-NOD32 | MSIL/Agent.VRB trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Agent.GPZU (B) |
| F-Secure | Heuristic.HEUR/AGEN.1323984 |
| Fortinet | W32/Agent.VRB!tr |
| GData | Trojan.Agent.GPZU |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0001140e1 ) |
| K7GW | Trojan ( 0001140e1 ) |
| Kaspersky | HEUR:Backdoor.MSIL.DcRat.gen |
| Kingsoft | malware.kb.a.941 |
| Lionic | Trojan.Win32.DCRat.m!c |
| Malwarebytes | Spyware.Passwordstealer |
| McAfeeD | Real Protect-LS!816C496A3D52 |
| MicroWorld-eScan | Trojan.Agent.GPZU |
| Microsoft | Trojan:Win32/Egairtigado!rfn |
| Rising | Trojan.Agent!8.B1E (C64:YzY0OmzpxyYjA/7y) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Stealer |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Troj/DCRat-AC |
| Tencent | Trojan.Msil.Agent.hbf |
| TrellixENS | GenericRXWS-LY!816C496A3D52 |
| VBA32 | Backdoor.MSIL.DcRat |
| VIPRE | Trojan.Agent.GPZU |
| Varist | W32/Trojan.DAIU-7549 |
| VirIT | Trojan.Win32.GenusT.EXYL |
| Webroot | Win.Malware.Gen |
| Zillya | Trojan.Stealer.Win32.199293 |
| ZoneAlarm | Troj/DCRat-AC |
| alibabacloud | Backdoor:MSIL/Egairtigado.Gen |
| huorong | Backdoor/MSIL.DCRat.x |
| tehtris | Generic.Malware |