file
Classification: Malicious
file is a malicious file sample. Reported by 1 threat source, last seen 2024-09-28. Detected by 52 antivirus engines.
Detection summary
- 52 antivirus detections
- 1 IDS alerts
- 90 processes observed
- 23 contacted hosts
- 19 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-09-28 06:00:03 | 2024-09-28 07:45:12 |
Sample information
- Filenames
- file
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 1372160 bytes
- MD5
cdfc92c8da9fa833c0423eb80fbe97d7- SHA-1
b202c5955d4683ef3fde5ab4f7c19df0ae3e18e0- SHA-256
59db0c319dd810c824b039ab1376637fc3ddd2f9afe6a306dafbbc520aa92255- First indexed
- 2024-09-28 05:42:11
- Last updated
- 2026-09-03 00:19:03
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Adware.Agent.NLP |
| APEX | Malicious |
| AVG | FileRepMalware [Misc] |
| Alibaba | AdWare:PHP/Clicker.beabced7 |
| Arcabit | Adware.Agent.NLP |
| Avast | FileRepMalware [Misc] |
| BitDefender | Adware.Agent.NLP |
| Bkav | W32.DownloaderATTc.Worm |
| CrowdStrike | win/grayware_confidence_70% (W) |
| Cybereason | malicious.8da9fa |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| Emsisoft | Adware.Agent.NLP (B) |
| FireEye | Adware.Agent.NLP |
| Fortinet | Adware/PHP_Clicker |
| GData | Adware.Agent.NLP |
| Detected | |
| Ikarus | AdWare.Agent |
| Jiangmin | Trojan/Script.Gen |
| Kaspersky | not-a-virus:AdWare.PHP.Clicker.a |
| Kingsoft | Win32.Troj.Unknown.a |
| Lionic | Adware.Win32.Clicker.2!c |
| Malwarebytes | Generic.Malware/Suspicious |
| MaxSecure | Trojan.Malware.2588.susgen |
| McAfee | GenDownloader.kw |
| McAfeeD | ti!59DB0C319DD8 |
| MicroWorld-eScan | Adware.Agent.NLP |
| Microsoft | PUA:Win32/Presenoker |
| NANO-Antivirus | Trojan.Win32.RiskGen.zlxcs |
| Rising | Trojan.Clicker.Win32.StartPage.e (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Downloader |
| Sangfor | Adware.Win32.Clicker.Vm08 |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | GenDownloader.kw |
| Sophos | Generic Reputation PUA (PUA) |
| Symantec | ML.Attribute.HighConfidence |
| TACHYON | Ransom/W32.Encoder.1372160.B |
| TrendMicro-HouseCall | TROJ_PAM_000001078E.T3 |
| VBA32 | Adware.PHP.Clicker |
| VIPRE | Adware.Agent.NLP |
| Varist | W32/AdAgent.AK.gen!Eldorado |
| Webroot | W32.Malware.Gen |
| Xcitium | ApplicUnwnt@#2rmveu7xihx7a |
| ZoneAlarm | not-a-virus:AdWare.PHP.Clicker.a |
| CAT-QuickHeal | Trojan.Ghanarava.1725711433be97d7 |
| CTX | exe.adware.clicker |
| Elastic | malicious (moderate confidence) |
| Ikarus | Trojan.Win32.CoinMiner |
| MaxSecure | Trojan.Malware.11740449.susgen |
| Sangfor | Trojan.Win32.Save.a |
| Yandex | Adware.Agent!8O6rcoob9NA |
Network contacts
76.223.54.146 142.250.65.196 104.22.74.216 142.250.176.206 142.251.35.166 104.26.2.70 34.202.54.159 142.251.40.194 142.251.40.97 13.248.169.48 192.229.211.108 192.124.249.41 192.124.249.31 142.250.64.99 192.124.249.23 23.44.133.38 172.67.41.60 104.26.3.70 3.221.216.4 142.251.41.10 192.124.249.36 192.124.249.22 104.22.75.216
DNS requests
ad-delivery.net ad.doubleclick.net afs.googleusercontent.com api.aws.parking.godaddy.com btloader.com contrev.net partner.googleadservices.com syndicatedsearch.goog www.google.com c.pki.goog crl.godaddy.com crl.starfieldtech.com o.pki.goog ocsp.digicert.com ocsp.godaddy.com ocsp.pki.goog ocsp.starfieldtech.com bzib.nelreports.net chromewebstore.googleapis.com
Process list
| Name | Command line |
|---|---|
| file.exe | |
| msedge.exe | --single-argument http://contrev.net/redir476.html |
| msedge.exe | --type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xc8,0xcc,0xd0,0xa4,0x144,0x7ff891a4b208,0x7ff891a4b218,0x7ff891a4b228 |
| msedge.exe | --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1824 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:2 |
| msedge.exe | --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:3 |
| msedge.exe | --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2192 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=6 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3136343360 --mojo-platform-channel-handle=2804 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=5 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3136630837 --mojo-platform-channel-handle=2820 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1 |
| msedge.exe | --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3596 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=8 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3138387606 --mojo-platform-channel-handle=4124 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1 |
| msedge.exe | --type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=9 --time-ticks-at-unix-epoch=-1727525085032773 --launch-time-ticks=3141083113 --mojo-platform-channel-handle=4396 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:1 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5180 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5188 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3660 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2520 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5800 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1816 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1768 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4280 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1280 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5756 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.16299.192 --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=5316 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:2 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5596 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1604 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5740 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=5772 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4296 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| msedge.exe | --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=5712 --field-trial-handle=1964,i,5253278012044667415,14544264101508345530,131072 /prefetch:8 |
| file.exe | |
| iexplore.exe | http://contrev.net/redir476.html |