dogsbollocks5.com.exe
Classification: Malicious
dogsbollocks5.com.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-04-26. Detected by 54 antivirus engines.
Detection summary
- 54 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 3 contacted hosts
- 4 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-04-26 05:45:13 | 2026-04-26 05:45:13 | ||
| Generic Malware | Triage | 2026-04-25 12:25:28 | 2026-04-25 12:25:28 | malicious-activity |
Tags
defense_evasion discovery evasion execution impact persistence privilege_escalation ransomware spyware stealer trojan evasive hiddentear infostealer suspiciousSample information
- Filenames
- dogsbollocks5.com.exe, 2026-04-25_0f8a5db186482f3588430ffe1a8284e9_destroyer_elex_glassworm_ngrbot_wannacry
- File type
- PE32 executable for MS Windows 4.00 (GUI), Intel i ...
- MD5
0f8a5db186482f3588430ffe1a8284e9- SHA-1
b6f067af45fe2dca1cde8e619b3ad78de32f1635- SHA-256
5a47b2488abe6b6ebb4840c60005fd55d8b237593eeaeba2b7aeb35eb04cc956- First indexed
- 2026-04-25 12:25:28
- Last updated
- 2026-09-03 01:03:50
Antivirus detections
| Engine | Detection |
|---|---|
| APEX | Malicious |
| AVG | MalwareX-gen [Expl] |
| AhnLab-V3 | Ransomware/Win.HiddenTears.C5871599 |
| Alibaba | Ransom:MSIL/FileCoder.fa942444 |
| Antiy-AVL | Trojan[Exploit]/MSIL.BypassUAC |
| Arcabit | Trojan.Ransom.HiddenTears.1 |
| Avast | MalwareX-gen [Expl] |
| Avira | TR/Dropper.Gen |
| BitDefender | Gen:Heur.Ransom.HiddenTears.1 |
| Bkav | W32.AIDetectMalware.CS |
| CTX | exe.ransomware.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen32.34610 |
| ESET-NOD32 | MSIL/Agent_AGen.EGC trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Heur.Ransom.HiddenTears.1 (B) |
| F-Secure | Trojan.TR/Dropper.Gen |
| Fortinet | MSIL/Agent.EGC!tr |
| GData | Gen:Heur.Ransom.HiddenTears.1 |
| Detected | |
| Gridinsoft | Ransom.Win32.HiddenTear.sa |
| Ikarus | Trojan.MSIL.CryptInject |
| K7AntiVirus | Trojan ( 700000201 ) |
| K7GW | Trojan ( 700000201 ) |
| Kaspersky | HEUR:Exploit.Win32.Convagent.gen |
| Kingsoft | malware.kb.c.998 |
| Malwarebytes | Ransom.HiddenTear |
| McAfeeD | Real Protect-LS!0F8A5DB18648 |
| MicroWorld-eScan | Gen:Heur.Ransom.HiddenTears.1 |
| Microsoft | Ransom:MSIL/FileCoder.MX!MTB |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Ransom.Agent!1.129F5 (CLASSIC) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Infected.qm |
| Sophos | Mal/MSIL-AZ |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Exploit.Convagent.Fajl |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | Artemis!0F8A5DB18648 |
| TrendMicro | Ransom_CRYPTEAR.SMI1 |
| TrendMicro-HouseCall | Ransom_CRYPTEAR.SMI1 |
| VBA32 | Trojan.MSIL.DelShad.Heur |
| VIPRE | Gen:Heur.Ransom.HiddenTears.1 |
| Varist | W32/Hiddentear.A!Eldorado |
| ViRobot | Trojan.Win.Z.Ransom.52736.OB |
| VirIT | Trojan.Win32.MSIL.JMV |
| Webroot | Win.Trojan.Gen |
| ZoneAlarm | Mal/MSIL-AZ |
| alibabacloud | Ransomware:Win/Filecoder.APU |
| huorong | Ransom/LockFile.kg |
Network contacts
DNS requests
dogsbollocks5.com emotet.com mistymay.com wannacry-decryptor.com