4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar

Classification: Malicious

4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar is a malicious file sample. Linked to Xloader malware. Detected by 49 antivirus engines.

Detection summary

  • 49 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: XLOADER (S1207)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Formbook Triage 2026-05-04 09:31:15 2026-05-04 09:31:15 malicious-activity S1207 XLoader

Tags

formbook discovery rat spyware stealer trojan

Sample information

Filenames
4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691.rar
SHA-256
4b2621a8fec5428bcec870cac4e032f230d046a58107b1b84fda180dd905a691
First indexed
2026-05-04 09:31:15
Last updated
2026-09-03 00:42:52

Antivirus detections

EngineDetection
ALYacIL:Trojan.MSILZilla.253495
AVGWin32:MalwareX-gen [Misc]
AhnLab-V3Malware/Win.MSILZilla.C5878996
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitTrojan.Zmutzy.67
AvastWin32:MalwareX-gen [Misc]
AviraTR/W32.Agent
BitDefenderGen:Variant.Zmutzy.67
BkavW32.Malware.F2C97CA7
CTXrar.trojan.msil
ClamAVLegacy.Trojan.Agent-1388784
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebTrojan.PackedNET.3222
ESET-NOD32Win32/Formbook.AA trojan
EmsisoftGen:Variant.Zmutzy.67 (B)
F-SecureTrojan.TR/W32.Agent
FortinetMSIL/Formbook.AJAP!tr
GDataGen:Variant.Zmutzy.67
GoogleDetected
GridinsoftTrojan.Win32.Agent.sa
IkarusTrojan.MSIL.Inject
K7AntiVirusSpyware ( 005ce02a1 )
K7GWSpyware ( 005ce02a1 )
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
Kingsoftmalware.kb.c.996
LionicTrojan.ZIP.Noon.l!c
MalwarebytesTrojan.MalPack.PNG.Generic
MaxSecureTrojan.Malware.241401018.susgen
McAfeeDTrojan:Archive/SuspiciousRar.C
MicrosoftTrojan:Win32/Suschil!rfn
PandaTrj/Agent.MG
RisingMalware.Obfus/[email protected] (RDM.MSIL2:aRoBgRQCI+Dw/F59AD1K/w)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious Archive
SkyhighArtemis!Trojan
SophosMal/DrodRar-AIC
SymantecTrojan.Gen.NPE
TencentMalware.Win32.Gencirc.14adf8a1
TrellixENSArtemis!97D5E486DEC1
TrendMicroTrojan.MSIL.MSILZILLA.TL0101E526ZY
VBA32TScope.Trojan.MSIL
VIPREGen:Variant.Zmutzy.67
VaristW32/MSIL_Agent.KXI.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A
YandexTrojan.Igent.b6t11M.2
ZoneAlarmMal/DrodRar-AIC
ZonerTrojan.Win32.186409
alibabacloudTrojan[spy]:MSIL/Noon.gyf