install.cab
Classification: Malicious
install.cab is a malicious file sample. Linked to Konni malware. Reported by 1 threat source, last seen 2024-06-05. Detected by 63 antivirus engines.
Detection summary
- 63 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: KONNI (S0356)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Konni | MalwareBazaar Abuse.ch | 2024-06-05 10:57:39 | 2024-06-05 10:57:39 | malicious-activity | S0356 KONNI |
Sample information
- Filenames
- install.cab
- File type
- application/vnd.ms-cab-compressed
- MD5
66f6a7c5ebbabe401e72c77c6aa5b727- SHA-1
63ee908224dbbc595865725b71772d0269f14b53- SHA-256
51cc96fe79f9bd66651476a6a6fb61232302c74e273f21246ab0a47b51c07fb0- First indexed
- 2024-06-05 12:20:37
- Last updated
- 2026-08-01 01:48:36
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Backdoor.Agent.status |
| AVG | Script:SNH-gen [Trj] |
| Antiy-AVL | Trojan/Win64.Konni |
| Arcabit | Trojan.Barys.D6B282 [many] |
| Avast | Script:SNH-gen [Trj] |
| BitDefender | Gen:Variant.Barys.438914 |
| BitDefenderTheta | Gen:NN.ZedlaF.36744.Ou4@ayss9Th |
| DrWeb | BAT.SvcInstall.3 |
| ESET-NOD32 | multiple detections |
| Emsisoft | Gen:Variant.Barys.438914 (B) |
| FireEye | Gen:Variant.Barys.438914 |
| Fortinet | BASH/Agent.KON!tr |
| GData | Win64.Trojan.Konni.A |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.sa |
| Ikarus | Trojan.BAT.Agent |
| Jiangmin | Trojan.Konni.ab |
| K7AntiVirus | Trojan ( 005aa4511 ) |
| K7GW | Trojan ( 005aa4511 ) |
| Kaspersky | Trojan.Win64.Konni.df |
| Kingsoft | malware.kb.a.966 |
| Lionic | Trojan.ZIP.Konni.4!c |
| MAX | malware (ai score=81) |
| McAfee | Artemis!AE2CC3F595B0 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.Konni!8.10165 (CLOUD) |
| Sangfor | Trojan.BAT.Agent.ulch |
| SentinelOne | Static AI - Malicious Archive |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Gen.NPE |
| Tencent | Malware.Win32.Gencirc.13fcdfce |
| VIPRE | Gen:Variant.Barys.438914 |
| Varist | W32/ABRisk.HSRT-6064 |
| ZoneAlarm | HEUR:Trojan.Win32.Konni.gen |
| ALYac | Trojan.GenericKD.73045116 |
| AhnLab-V3 | Infostealer/Win.Agent.C5592087 |
| Arcabit | Trojan.Generic.D45A9477 [many] |
| Avira | TR/AVI.Agent.ilylq |
| BitDefender | Trojan.GenericKD.73045111 |
| CAT-QuickHeal | Trojan.Ghanarava.1728048102166636 |
| CTX | cab.trojan.konni |
| Cynet | Malicious (score: 99) |
| Emsisoft | Trojan.GenericKD.73045111 (B) |
| F-Secure | Trojan.TR/AVI.Agent.ilylq |
| GData | Win32.Trojan.Konni.A |
| Kaspersky | Trojan-Dropper.BAT.Agent.hk |
| Kingsoft | Win32.Troj.Undef.a |
| Lionic | Trojan.ZIP.Konni.b!c |
| MicroWorld-eScan | Trojan.GenericKD.73045111 |
| NANO-Antivirus | Trojan.Win32.Konni.koixli |
| Rising | Backdoor.[APT37]Agent!1.FCEE (CLASSIC) |
| TrellixENS | Artemis!AE2CC3F595B0 |
| TrendMicro | TROJ_FRS.VSNTBR24 |
| TrendMicro-HouseCall | TROJ_FRS.VSNTBR24 |
| VBA32 | Trojan.Konni |
| VIPRE | Trojan.GenericKD.73045111 |
| Varist | ABRisk.KVPQ-8 |
| VirIT | Trojan.BAT.Agent.GVD |
| Xcitium | Malware@#1gybs7wnbw3ja |
| Zillya | Trojan.Agent.Win32.3861398 |
| alibabacloud | Trojan[dropper]:Win/Malgent.Gen |
| huorong | Trojan/PS.Agent.d |