44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce.exe
Classification: Malicious
44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce.exe is a malicious file sample. Linked to Poisonivy malware.
Detection summary
- 62 antivirus detections (75% detection ratio)
- 0 IDS alerts
- 3 processes observed
- 0 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Poisonivy |
Triage |
2026-02-21 02:10:12 |
2026-02-21 02:10:12 |
malicious-activity
|
S0012 PoisonIvy
|
| Generic Malware |
Hybrid-Analysis |
2023-12-19 13:33:14 |
2025-02-08 15:00:24 |
|
|
| backdoor,banker,dridex,plugx |
Maltiverse |
2018-02-04 02:41:04 |
2018-02-04 02:41:04 |
|
|
Tags
backdoor
banker
dridex
plugx
windows-server-utility
poisonivy
discovery
rat
Sample information
- Filenames
- 44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce.exe, 4f505ca0ea4540e6662def1c1ddadd03
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 61440 bytes
- MD5
4f505ca0ea4540e6662def1c1ddadd03
- SHA-1
b23d698df6594f690f3462e238e1e9f2ec029bbf
- SHA-256
44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce
- SHA-512
faa09372c6e2d7dd9fd323dad5a8f528e51d51d16c0f117e829ad01bdba51a31eaa06a5a2bb8f7dd896b33bb53a27ff4cac23728225ca24d377715f4db851353
- First indexed
- 2018-02-04 02:41:04
- Last updated
- 2026-04-15 15:44:57
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Symmi.4437 |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| Alibaba | Backdoor:Win32/Poison.436b9313 |
| Antiy-AVL | Trojan[APT]/Win32.APT10 |
| Arcabit | Trojan.Symmi.D1155 |
| Avast | Win32:Evo-gen [Trj] |
| Avira | TR/Crypt.ZPACK.Gen |
| BitDefender | Gen:Variant.Symmi.4437 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Injector.S7380560 |
| CTX | exe.trojan.poison |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.DownLoader9.39293 |
| ESET-NOD32 | Win32/Poison.NLC |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Symmi.4437 (B) |
| F-Secure | Trojan.TR/Crypt.ZPACK.Gen |
| FireEye | Generic.mg.4f505ca0ea4540e6 |
| Fortinet | W32/Malware_fam.NB |
| GData | Gen:Variant.Symmi.4437 |
| Google | Detected |
| Ikarus | Trojan.Win32.Agent |
| Jiangmin | TrojanDropper.Injector.bqva |
| K7AntiVirus | Trojan ( 004ecbb71 ) |
| K7GW | Trojan ( 004ecbb71 ) |
| Kaspersky | Trojan-Dropper.Win32.Injector.juwy |
| Kingsoft | malware.kb.a.987 |
| Lionic | Trojan.Win32.Poison.b!c |
| Malwarebytes | Generic.Malware/Suspicious |
| MaxSecure | Trojan.Malware.8769756.susgen |
| McAfee | BackDoor-FBSQ!4F505CA0EA45 |
| McAfeeD | ti!44A7BEA8A08F |
| MicroWorld-eScan | Gen:Variant.Symmi.4437 |
| Microsoft | Backdoor:Win32/Poison.CE |
| NANO-Antivirus | Trojan.Win32.Inject.cwizra |
| Paloalto | generic.ml |
| Panda | Generic Malware |
| Rising | Dropper.Injector!8.DC (TFE:5:VaRVn489Ks) |
| Sangfor | Backdoor.Win32.Poison.Vt3b |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | BackDoor-FBSQ!4F505CA0EA45 |
| Sophos | Mal/Generic-S |
| Symantec | Backdoor.Trojan |
| Tencent | Malware.Win32.Gencirc.13c186b9 |
| Trapmine | malicious.moderate.ml.score |
| TrendMicro | BKDR_POISON.TUHE |
| TrendMicro-HouseCall | BKDR_POISON.TUHE |
| VBA32 | Backdoor.Win32.Hupigon.dguz |
| VIPRE | Gen:Variant.Symmi.4437 |
| Varist | W32/Trojan.DJLU-2710 |
| ViRobot | Trojan.Win32.Z.Injector.61440.AH |
| VirIT | Trojan.Win32.Dnldr9.CGDH |
| Xcitium | Malware@#3mt4cwxcsi0y7 |
| Yandex | Trojan.DR.Injector!MistrLQCzag |
| Zillya | Dropper.Injector.Win32.66142 |
| alibabacloud | Backdoor:Win/Poison.NEI |
| huorong | HVM:Trojan/Injector.gen!A |
| tehtris | Generic.Malware |
Process list
| Name | Command line |
| 44a7bea8a08f4c2feb74c6a00ff1114ba251f3dc6922ea5ffab9e749c98cbdce.exe | |
| 4f505ca0ea4540e6662def1c1ddadd03.exe | |
| 4f505ca0ea4540e6662def1c1ddadd03.exe | |