4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar
Classification: Malicious
4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar is a malicious file sample. Linked to Xloader malware. Detected by 49 antivirus engines.
Detection summary
- 49 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: XLOADER (S1207)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Formbook | Triage | 2026-05-04 09:31:15 | 2026-05-04 09:31:15 | malicious-activity | S1207 XLoader |
Tags
formbook discovery rat spyware stealer trojanSample information
- Filenames
- 4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar
- SHA-256
4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691- First indexed
- 2026-05-04 09:31:15
- Last updated
- 2026-09-03 00:42:52
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | IL:Trojan.MSILZilla.253495 |
| AVG | Win32:MalwareX-gen [Misc] |
| AhnLab-V3 | Malware/Win.MSILZilla.C5878996 |
| Antiy-AVL | Trojan/MSIL.Kryptik |
| Arcabit | Trojan.Zmutzy.67 |
| Avast | Win32:MalwareX-gen [Misc] |
| Avira | TR/W32.Agent |
| BitDefender | Gen:Variant.Zmutzy.67 |
| Bkav | W32.Malware.F2C97CA7 |
| CTX | rar.trojan.msil |
| ClamAV | Legacy.Trojan.Agent-1388784 |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.PackedNET.3222 |
| ESET-NOD32 | Win32/Formbook.AA trojan |
| Emsisoft | Gen:Variant.Zmutzy.67 (B) |
| F-Secure | Trojan.TR/W32.Agent |
| Fortinet | MSIL/Formbook.AJAP!tr |
| GData | Gen:Variant.Zmutzy.67 |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.sa |
| Ikarus | Trojan.MSIL.Inject |
| K7AntiVirus | Spyware ( 005ce02a1 ) |
| K7GW | Spyware ( 005ce02a1 ) |
| Kaspersky | HEUR:Trojan-Spy.MSIL.Noon.gen |
| Kingsoft | malware.kb.c.996 |
| Lionic | Trojan.ZIP.Noon.l!c |
| Malwarebytes | Trojan.MalPack.PNG.Generic |
| MaxSecure | Trojan.Malware.241401018.susgen |
| McAfeeD | Trojan:Archive/SuspiciousRar.C |
| Microsoft | Trojan:Win32/Suschil!rfn |
| Panda | Trj/Agent.MG |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:aRoBgRQCI+Dw/F59AD1K/w) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious Archive |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/DrodRar-AIC |
| Symantec | Trojan.Gen.NPE |
| Tencent | Malware.Win32.Gencirc.14adf8a1 |
| TrellixENS | Artemis!97D5E486DEC1 |
| TrendMicro | Trojan.MSIL.MSILZILLA.TL0101E526ZY |
| VBA32 | TScope.Trojan.MSIL |
| VIPRE | Gen:Variant.Zmutzy.67 |
| Varist | W32/MSIL_Agent.KXI.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Yandex | Trojan.Igent.b6t11M.2 |
| ZoneAlarm | Mal/DrodRar-AIC |
| Zoner | Trojan.Win32.186409 |
| alibabacloud | Trojan[spy]:MSIL/Noon.gyf |