file

Classification: Malicious

file is a malicious file sample. Reported by 1 threat source, last seen 2024-09-28. Detected by 52 antivirus engines.

Detection summary

  • 52 antivirus detections
  • 1 IDS alerts
  • 90 processes observed
  • 23 contacted hosts
  • 19 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-09-28 06:00:03 2024-09-28 07:45:12

Sample information

Filenames
file
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1372160 bytes
MD5
cdfc92c8da9fa833c0423eb80fbe97d7
SHA-1
b202c5955d4683ef3fde5ab4f7c19df0ae3e18e0
SHA-256
59db0c319dd810c824b039ab1376637fc3ddd2f9afe6a306dafbbc520aa92255
First indexed
2024-09-28 05:42:11
Last updated
2026-09-03 00:19:03

Antivirus detections

EngineDetection
ALYacAdware.Agent.NLP
APEXMalicious
AVGFileRepMalware [Misc]
AlibabaAdWare:PHP/Clicker.beabced7
ArcabitAdware.Agent.NLP
AvastFileRepMalware [Misc]
BitDefenderAdware.Agent.NLP
BkavW32.DownloaderATTc.Worm
CrowdStrikewin/grayware_confidence_70% (W)
Cybereasonmalicious.8da9fa
CylanceUnsafe
DeepInstinctMALICIOUS
Elasticmalicious (high confidence)
EmsisoftAdware.Agent.NLP (B)
FireEyeAdware.Agent.NLP
FortinetAdware/PHP_Clicker
GDataAdware.Agent.NLP
GoogleDetected
IkarusAdWare.Agent
JiangminTrojan/Script.Gen
Kasperskynot-a-virus:AdWare.PHP.Clicker.a
KingsoftWin32.Troj.Unknown.a
LionicAdware.Win32.Clicker.2!c
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.2588.susgen
McAfeeGenDownloader.kw
McAfeeDti!59DB0C319DD8
MicroWorld-eScanAdware.Agent.NLP
MicrosoftPUA:Win32/Presenoker
NANO-AntivirusTrojan.Win32.RiskGen.zlxcs
RisingTrojan.Clicker.Win32.StartPage.e (CLASSIC)
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
SangforAdware.Win32.Clicker.Vm08
SentinelOneStatic AI - Suspicious PE
SkyhighGenDownloader.kw
SophosGeneric Reputation PUA (PUA)
SymantecML.Attribute.HighConfidence
TACHYONRansom/W32.Encoder.1372160.B
TrendMicro-HouseCallTROJ_PAM_000001078E.T3
VBA32Adware.PHP.Clicker
VIPREAdware.Agent.NLP
VaristW32/AdAgent.AK.gen!Eldorado
WebrootW32.Malware.Gen
XcitiumApplicUnwnt@#2rmveu7xihx7a
ZoneAlarmnot-a-virus:AdWare.PHP.Clicker.a
CAT-QuickHealTrojan.Ghanarava.1725711433be97d7
CTXexe.adware.clicker
Elasticmalicious (moderate confidence)
IkarusTrojan.Win32.CoinMiner
MaxSecureTrojan.Malware.11740449.susgen
SangforTrojan.Win32.Save.a
YandexAdware.Agent!8O6rcoob9NA

Network contacts

76.223.54.146 142.250.65.196 104.22.74.216 142.250.176.206 142.251.35.166 104.26.2.70 34.202.54.159 142.251.40.194 142.251.40.97 13.248.169.48 192.229.211.108 192.124.249.41 192.124.249.31 142.250.64.99 192.124.249.23 23.44.133.38 172.67.41.60 104.26.3.70 3.221.216.4 142.251.41.10 192.124.249.36 192.124.249.22 104.22.75.216

DNS requests

ad-delivery.net ad.doubleclick.net afs.googleusercontent.com api.aws.parking.godaddy.com btloader.com contrev.net partner.googleadservices.com syndicatedsearch.goog www.google.com c.pki.goog crl.godaddy.com crl.starfieldtech.com o.pki.goog ocsp.digicert.com ocsp.godaddy.com ocsp.pki.goog ocsp.starfieldtech.com bzib.nelreports.net chromewebstore.googleapis.com

Process list

NameCommand line
file.exe
msedge.exe--single-argument http://contrev.net/redir476.html
msedge.exe--type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xc8,0xcc,0xd0,0xa4,0x144,0x7ff891a4b208,0x7ff891a4b218,0x7ff891a4b228
msedge.exe--type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1824 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:2
msedge.exe--type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:3
msedge.exe--type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2192 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=6 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3136343360 --mojo-platform-channel-handle=2804 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=5 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3136630837 --mojo-platform-channel-handle=2820 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3596 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=8 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3138387606 --mojo-platform-channel-handle=4124 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=9 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3141083113 --mojo-platform-channel-handle=4396 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5180 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5188 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3660 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2520 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5800 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1816 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1768 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4280 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1280 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5756 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.16299.192 --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=5316 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:2
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5596 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1604 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5740 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5772 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4296 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5712 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8
file.exe
iexplore.exehttp://contrev.net/redir476.html