Classification: Malicious
AdventureQuest.exe is a malicious file sample. Linked to Menupass activity. Reported by 4 threat sources, last seen 2026-08-31.
Detection summary
- 22 antivirus detections (63% detection ratio)
- 0 IDS alerts
- 12 processes observed
- 2 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-07 10:09:26 |
2026-08-31 10:09:11 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2023-08-31 16:15:04 |
2023-08-31 16:15:04 |
|
|
| Stone Panda |
Maltiverse |
2023-08-18 04:16:02 |
2023-08-19 20:21:53 |
malicious-activity
|
G0045 menuPass
|
| Hacktool |
VM-Ray |
2023-05-11 10:22:51 |
2023-05-11 10:22:51 |
|
|
Sample information
- Filenames
- AdventureQuest.exe, 43fb2d2e7596bed395bba6e012d0ee13ed61856cd63db47bf94160881d3e3ac7
- File type
- PE32+ executable (GUI) x86-64 Mono/.Net assembly, ...
- Size
- 1043760 bytes
- MD5
f050c9fa2cab55097a1e037c7df0c10f
- SHA-1
6e9592920cdce90a7c03155ef8b113911c20bb3a
- SHA-256
43fb2d2e7596bed395bba6e012d0ee13ed61856cd63db47bf94160881d3e3ac7
- First indexed
- 2023-05-11 10:03:03
- Last updated
- 2026-07-04 16:09:06
Antivirus detections
| Engine | Detection |
| Cynet | Malicious (score: 99) |
| CAT-QuickHeal | Trojan.YakbeexMSIL.ZZ4 |
| ALYac | Gen:Trojan.Heur.@i2@vTJkDgaan |
| VIPRE | Gen:Trojan.Heur.@i2@vTJkDgaan |
| Cybereason | malicious.a2cab5 |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | a variant of MSIL/Agent.VMI |
| Kaspersky | VHO:Trojan.MSIL.Exnet.gen |
| BitDefender | Gen:Trojan.Heur.@i2@vTJkDgaan |
| MicroWorld-eScan | Gen:Trojan.Heur.@i2@vTJkDgaan |
| Avast | Win64:UnwantedSig [PUP] |
| Emsisoft | Gen:Trojan.Heur.@i2@vTJkDgaan (B) |
| F-Secure | Heuristic.HEUR/AGEN.1304167 |
| FireEye | Gen:Trojan.Heur.@i2@vTJkDgaan |
| Avira | HEUR/AGEN.1304167 |
| Arcabit | Trojan.Heur.E0E991 |
| ZoneAlarm | VHO:Trojan.MSIL.Exnet.gen |
| GData | Gen:Trojan.Heur.@i2@vTJkDgaan |
| MAX | malware (ai score=81) |
| BitDefenderTheta | AI:Packer.16CC91331D |
| AVG | Win64:UnwantedSig [PUP] |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| 43fb2d2e7596bed395bba6e012d0ee13ed61856cd63db47bf94160881d3e3ac7.exe | |
| cmd.exe | "cmd" /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender" /v "DisableAntiSpyware" |
| reg.exe | reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender" /v "DisableAntiSpyware" |
| cmd.exe | "cmd" /c reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\360Hvm" /v "Start" |
| reg.exe | reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\360Hvm" /v "Start" |
| cmd.exe | "cmd" /c tasklist | findstr "360Tray" |
| tasklist.exe | |
| findstr.exe | findstr "360Tray" |
| cmd.exe | "cmd" /c sc query 360hvm |
| sc.exe | sc query 360hvm |
| cmd.exe | "cmd" /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender" /v "DisableAntiSpyware" |
| reg.exe | reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender" /v "DisableAntiSpyware" |