RFQ678903423_PROD_INQHASUE_de_mexico.exe

Classification: Malicious

RFQ678903423_PROD_INQHASUE_de_mexico.exe is a malicious file sample. Linked to Ecipekac malware. Reported by 2 threat sources, last seen 2024-05-16.

Detection summary

  • 58 antivirus detections
  • 0 IDS alerts
  • 1 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: ECIPEKAC (S0624)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SigLoader ThreatFox Abuse.ch 2024-05-14 17:19:03 2024-05-16 17:25:53 S0624 Ecipekac
Generic Malware Hybrid-Analysis 2024-05-10 21:29:49 2024-05-10 22:30:09

Tags

win.sigloader

Sample information

Filenames
RFQ678903423_PROD_INQHASUE_de_mexico.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows, ...
Size
418763 bytes
MD5
e42f23139213daac41b211dfe7e1061e
SHA-1
46ce0d34ca8bda9891de099a895fe02b07dc0214
SHA-256
422e9bb54dde7e8664eef1f1e4c132beed0a0499587db423de19a3981ae53004
First indexed
2024-05-10 21:11:44
Last updated
2026-08-22 03:16:28

Antivirus detections

EngineDetection
ALYacGen:Variant.Ransom.Loki.1608
APEXMalicious
AVGWin32:Malware-gen
Antiy-AVLTrojan/Generic.ASMalwNS.F48D7
ArcabitTrojan.Generic.D4554C6C
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.72698988
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32NSIS/Injector.ASH
Elasticmalicious (high confidence)
EmsisoftTrojan.GenericKD.72698988 (B)
FireEyeGeneric.mg.e42f23139213daac
GDataTrojan.GenericKD.72698988
GoogleDetected
KasperskyHEUR:Trojan.Win32.Makoob.gen
MAXmalware (ai score=88)
MicroWorld-eScanTrojan.GenericKD.72698988
MicrosoftTrojan:Win32/GuLoader.KUYE!MTB
Paloaltogeneric.ml
SentinelOneStatic AI - Suspicious PE
SophosGeneric ML PUA (PUA)
TrendMicro-HouseCallTROJ_GEN.F0D1C00E924
VIPRETrojan.GenericKD.72698988
VaristW32/Injector.AUUY-8722
ZoneAlarmHEUR:Trojan.Win32.Makoob.gen
ALYacTrojan.GenericKD.72698988
AhnLab-V3Downloader/Win.GuLoader.C5622419
AlibabaTrojan:Win32/GuLoader.ab842deb
Antiy-AVLTrojan/Win32.Makoob.gen
AviraTR/W32.Malware
CTXexe.trojan.makoob
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
ESET-NOD32NSIS/Injector.ASH trojan
F-SecureTrojan.TR/W32.Malware
FortinetNSIS/Injector.C7R0!tr
K7AntiVirusTrojan ( 005ce14e1 )
K7GWTrojan ( 005ce14e1 )
KingsoftWin32.Trojan.Makoob.gen
LionicTrojan.Win32.Makoob.4!c
MaxSecureTrojan.Malware.698398649.susgen
McAfeeDti!422E9BB54DDE
PandaTrj/CI.A
RisingTrojan.Injector/NSIS!8.1294D (CLOUD)
SangforTrojan.Win32.Injector.Vvym
SophosMal/Generic-S
SymantecScr.NSISHeur!gen3
TencentWin32.Trojan.Makoob.Wmhl
TrellixENSArtemis!E42F23139213
TrendMicroTrojan.Win32.MAKOOB.TL0101F526ZZ
TrendMicro-HouseCallTrojan.Win32.VSX.PE04CA5
VBA32Malware-Cryptor.NSISex.Heur
ViRobotTrojan.Win.Z.Makoob.418763
VirITTrojan.Win32.GenusT.DWGB
YandexTrojan.Igent.b2iy8v.1
alibabacloudTrojan:Win/GuLoader.KCTZ3DGW
huorongTrojan/NSIS.Injector.r!crit

Process list

NameCommand line
RFQ678903423_PROD_INQHASUE_de_mexico.exe