Classification: Malicious
tmpyx_mdevg is a malicious file sample. Linked to Pwdump malware. Reported by 1 threat source, last seen 2020-02-23. Detected by 47 antivirus engines.
Detection summary
- 47 antivirus detections (64% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| PWDump |
Hybrid-Analysis |
2020-02-23 00:30:17 |
2020-02-23 00:30:17 |
|
S0006 pwdump
|
Tags
anthem
apt
deepanda
fgdump
hacktool
pos
pwdump
Sample information
- Filenames
- tmpyx_mdevg
- File type
- PE32 executable (console) Intel 80386, for MS Windows
- Size
- 345600 bytes
- MD5
a47f07515b09d7afd1b10784e8fb6d14
- SHA-1
ad41f718ad76596314e367d25a2eaaea3e7a7aac
- SHA-256
4ed78e0a69defeac5ae4b38dcea2346e326285a75adf331ef701153c048e59c8
- First indexed
- 2020-02-23 00:30:17
- Last updated
- 2025-10-10 18:17:31
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectVM.malware |
| DrWeb | Tool.Pwdump.189 |
| FireEye | Generic.mg.a47f07515b09d7af |
| CAT-QuickHeal | HackTool.PWDump |
| McAfee | Artemis!A47F07515B09 |
| Zillya | Tool.PWDump.Win32.427 |
| Sangfor | Malware |
| Alibaba | HackTool:Win32/PWDump.8a2a4c54 |
| Cybereason | malicious.8ad765 |
| Invincea | heuristic |
| Cyren | W32/Risk.GDQT-5682 |
| Symantec | ML.Attribute.HighConfidence |
| ClamAV | Win.Trojan.Pwdump-78 |
| Kaspersky | not-a-virus:PSWTool.Win64.PWDump.t |
| NANO-Antivirus | Riskware.Win32.Pwdump.exnvgf |
| AegisLab | Trojan.Multi.Generic.4!c |
| Avast | Win64:Malware-gen |
| Rising | Trojan.Win32.Generic.14B46F00 (C64:YzY0OtLxeS4cafca) |
| Comodo | Malware@#uewe6gg28pob |
| F-Secure | PrivacyRisk.SPR/PWDum.A |
| VIPRE | Trojan.Win32.Generic!BT |
| McAfee-GW-Edition | BehavesLike.Win32.PWSZbot.fh |
| Fortinet | Riskware/PWDump |
| Trapmine | malicious.moderate.ml.score |
| Sophos | PWDump (PUA) |
| Ikarus | HackTool.Win64 |
| F-Prot | W32/MalwareS.BJUN |
| Jiangmin | PSWTool.PWDump.b |
| Avira | SPR/PWDum.A |
| MAX | malware (ai score=96) |
| Antiy-AVL | Trojan[PSWTool]/Win32.PWDump |
| Endgame | malicious (high confidence) |
| Microsoft | HackTool:Win32/PWDump.C |
| ViRobot | PSWTool.PWDump.345600 |
| ZoneAlarm | not-a-virus:PSWTool.Win64.PWDump.t |
| VBA32 | Trojan.Genome.af |
| Cylance | Unsafe |
| APEX | Malicious |
| ESET-NOD32 | a variant of Win32/PSWTool.PWDump6.G potentially unsafe |
| Yandex | Trojan.PWDum!1VGf3lPlzqc |
| SentinelOne | DFI - Malicious PE |
| eGambit | HackTool.Samples |
| MaxSecure | Trojan.Malware.9422136.susgen |
| AVG | Win64:Malware-gen |
| Panda | Trj/Passtealer.LR |
| CrowdStrike | win/malicious_confidence_70% (D) |
| Qihoo-360 | HEUR/QVM19.1.6939.Malware.Gen |
Process list
| Name | Command line |
| tmpyx_mdevg.exe | |