1.exe
Classification: Malicious
1.exe is a malicious file sample. Linked to Runningrat malware. Reported by 1 threat source, last seen 2022-02-15. Detected by 46 antivirus engines.
Detection summary
- 46 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: RUNNINGRAT (S0253)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RunningRAT | MalwareBazaar Abuse.ch | 2022-02-15 16:48:27 | 2022-02-15 16:48:27 | malicious-activity | S0253 RunningRAT |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-02-15 16:48:27 | 2022-02-15 16:48:27 | malicious-activity |
Sample information
- Filenames
- 1.exe
- File type
- application/x-dosexec
- MD5
e3ca4aeabe1a66897e064a9a1bcd61f6- SHA-1
6c160bc11c5e45e317012b4832a7b48d6478bd9a- SHA-256
4a954f2b0d13c4916fb79c5b78e60979871b1ded51c0fe80bc9e636585a5bd06- First indexed
- 2022-02-15 18:15:09
- Last updated
- 2026-02-17 16:18:54
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.SlaviaC.Trojan |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Heur.RI.1 |
| FireEye | Generic.mg.e3ca4aeabe1a6689 |
| ALYac | Gen:Heur.RI.1 |
| Cylance | Unsafe |
| Zillya | Trojan.Injector.Win32.995112 |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 005565491 ) |
| K7GW | Trojan ( 005565491 ) |
| CrowdStrike | win/malicious_confidence_90% (D) |
| BitDefenderTheta | Gen:NN.ZexaF.34758.eqW@aK6ty4pb |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Injector.EGZV |
| Avast | Win32:BackdoorX-gen [Trj] |
| ClamAV | Win.Trojan.Farfli-9755023-0 |
| Kaspersky | Backdoor.Win64.Winnti.wd |
| BitDefender | Gen:Heur.RI.1 |
| NANO-Antivirus | Trojan.Win32.RI.hmkkqx |
| Rising | [email protected] (RDML:cHjl4BJ7CNLSdjqyE7/d0w) |
| Ad-Aware | Gen:Heur.RI.1 |
| Emsisoft | Gen:Heur.RI.1 (B) |
| DrWeb | Trojan.DownLoader33.59527 |
| VIPRE | Trojan.Win32.Generic!BT |
| McAfee-GW-Edition | GenericRXKR-ZE!E3CA4AEABE1A |
| Sophos | ML/PE-A |
| APEX | Malicious |
| GData | Gen:Heur.RI.1 |
| Jiangmin | Heur:Backdoor/Huigezi |
| eGambit | Trojan.Generic |
| Avira | HEUR/AGEN.1138550 |
| MAX | malware (ai score=81) |
| Antiy-AVL | Trojan/Generic.ASMalwS.305A526 |
| Microsoft | Trojan:Win32/Caynamer.A!ml |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Malware/Win32.RL_Generic.R356011 |
| Acronis | suspicious |
| McAfee | GenericRXKR-ZE!E3CA4AEABE1A |
| VBA32 | BScope.Backdoor.Win64.Winnti |
| Malwarebytes | Malware.AI.2390728088 |
| Tencent | Malware.Win32.Gencirc.10ce4153 |
| SentinelOne | Static AI - Suspicious PE |
| MaxSecure | Trojan.Malware.102770177.susgen |
| AVG | Win32:BackdoorX-gen [Trj] |
| Cybereason | malicious.abe1a6 |
| Panda | Trj/Genetic.gen |