Classification: Malicious
000.exe is a malicious file sample. Linked to Wiper malware. Reported by 4 threat sources, last seen 2026-08-08. Detected by 24 antivirus engines.
Detection summary
- 24 antivirus detections (85% detection ratio)
- 0 IDS alerts
- 7 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-08-01 20:40:43 |
2026-08-08 23:01:27 |
anomalous-activity
|
|
| Generic Malware |
Triage |
2026-02-12 18:11:50 |
2026-07-10 23:38:16 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2023-08-02 00:45:04 |
2023-08-02 00:45:04 |
|
|
| Keylogger |
VM-Ray |
2023-05-20 16:19:58 |
2023-05-20 16:19:58 |
|
|
| Wiper |
VM-Ray |
2023-05-20 16:19:58 |
2023-05-20 16:19:58 |
|
S0041 Wiper
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2023-05-20 14:47:18 |
2023-05-20 14:47:18 |
malicious-activity
|
|
| Gen:Variant.Razy |
Hybrid-Analysis |
2019-04-15 04:15:14 |
2019-04-15 04:15:14 |
|
|
Tags
banker
evasive
windows-server-utility
defense_evasion
discovery
persistence
ransomware
execution
Sample information
- Filenames
- 000.exe, 4a900b344ef765a66f98cf39ac06273d565ca0f5d19f7ea4ca183786155d4a47.exe, DDoS Attack Server, IP, URL.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 6983680 bytes
- MD5
d5671758956b39e048680b6a8275e96a
- SHA-1
33c341130bf9c93311001a6284692c86fec200ef
- SHA-256
4a900b344ef765a66f98cf39ac06273d565ca0f5d19f7ea4ca183786155d4a47
- SHA-512
972e89ed8b7b4d75df0a05c53e71fb5c29edaa173d7289656676b9d2a1ed439be1687beddc6fb1fbf068868c3da9c3d2deb03b55e5ab5e7968858b5efc49fbe7
- First indexed
- 2019-04-15 04:15:14
- Last updated
- 2026-08-08 23:55:44
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Gen:Variant.Razy.280786 |
| Malwarebytes | Trojan.Agent.MSIL |
| BitDefender | Gen:Variant.Razy.280786 |
| ESET-NOD32 | a variant of BAT/Agent.ONI |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| Rising | Trojan.Agent!8.B1E (CLOUD) |
| Ad-Aware | Gen:Variant.Razy.280786 |
| Sophos | Mal/Generic-S |
| Invincea | heuristic |
| Emsisoft | Gen:Variant.Razy.280786 (B) |
| GData | Gen:Variant.Razy.280786 |
| Avira | TR/Crypt.XPACK.Gen7 |
| MAX | malware (ai score=88) |
| Microsoft | Trojan:Win32/Azden.A!cl |
| Endgame | malicious (high confidence) |
| Arcabit | Trojan.Razy.D448D2 |
| Acronis | suspicious |
| VBA32 | Trojan.Downloader |
| ALYac | Gen:Variant.Razy.280786 |
| Fortinet | BAT/Agent.ONI!tr |
| AVG | FileRepMalware |
| Cybereason | malicious.8956b3 |
| CrowdStrike | win/malicious_confidence_70% (D) |
| Qihoo-360 | HEUR/QVM03.0.E823.Malware.Gen |
Process list
| Name | Command line |
| 000.exe | |
| DDoSAttackServer_IP_URL.exe | |
| cmd.exe | %WINDIR%\system32\cmd.exe /c ""%TEMP%\windl.bat"" |
| taskkill.exe | taskkill /f /im explorer.exe |
| taskkill.exe | taskkill /f /im taskmgr.exe |
| WMIC.exe | wmic useraccount where name='%OSUSER%' set FullName='UR NEXT' |
| WMIC.exe | wmic useraccount where name='%OSUSER%' rename 'UR NEXT' |