608b93e344bd3dbb09d0af9da6856061
Classification: Malicious
608b93e344bd3dbb09d0af9da6856061 is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-09-14.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | Abuse.ch | 2021-09-14 13:22:46 | 2021-09-14 13:22:46 | malicious-activity | S0382 ServHelper |
Sample information
- Filenames
- 608b93e344bd3dbb09d0af9da6856061
- File type
- application/x-dosexec
- MD5
608b93e344bd3dbb09d0af9da6856061- SHA-1
b7c8bd7bace350d3c9c054ebb58f25535d22ee95- SHA-256
5d45cef43fb4c150c33337fb369a89800f9d235eee1dbdac13a8f6fd13bc1ee4- First indexed
- 2021-09-14 14:15:05
- Last updated
- 2026-09-03 00:34:46
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Generic.MSIL.Starter.1.19937776 |
| APEX | Malicious |
| AVG | Win32:DropperX-gen [Drp] |
| AhnLab-V3 | Trojan/Win.Trojan-gen.R442877 |
| Alibaba | TrojanDropper:MSIL/DropperX.82e49538 |
| Antiy-AVL | Trojan[Dropper]/MSIL.Agent |
| Arcabit | Generic.MSIL.Starter.1.19937776 |
| Avast | Win32:DropperX-gen [Drp] |
| Avira | HEUR/AGEN.1363259 |
| BitDefender | Generic.MSIL.Starter.1.19937776 |
| Bkav | W32.AIDetectMalware |
| ClamAV | Win.Downloader.Powershell-9883640-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cybereason | malicious.344bd3 |
| Cylance | unsafe |
| Cynet | Malicious (score: 99) |
| Cyren | W32/Agent.DLP.gen!Eldorado |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop18.40686 |
| ESET-NOD32 | a variant of MSIL/TrojanDropper.Agent.FDD |
| Elastic | malicious (high confidence) |
| Emsisoft | Generic.MSIL.Starter.1.19937776 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1363259 |
| FireEye | Generic.mg.608b93e344bd3dbb |
| Fortinet | MSIL/Agent.FDD!tr |
| GData | Generic.MSIL.Starter.1.19937776 |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan-Dropper.MSIL.Agent |
| Jiangmin | Trojan.PowerShell.mj |
| K7AntiVirus | Trojan ( 00580b5a1 ) |
| K7GW | Trojan ( 00580b5a1 ) |
| Kaspersky | Trojan-Dropper.MSIL.Agent.seskpc |
| Lionic | Trojan.MSIL.Agent.b!c |
| MAX | malware (ai score=100) |
| Malwarebytes | Trojan.Dropper |
| MaxSecure | Trojan.Malware.1728101.susgen |
| McAfee | GenericRXQE-DZ!608B93E344BD |
| McAfee-GW-Edition | GenericRXQE-DZ!608B93E344BD |
| MicroWorld-eScan | Generic.MSIL.Starter.1.19937776 |
| Microsoft | Trojan:Win32/Sabsik.TE.B!ml |
| NANO-Antivirus | Trojan.Win32.Ric.jxmmdx |
| Panda | Trj/GdSda.A |
| Rising | Dropper.Agent!8.2F (TFE:5:BzLwMnP4nhH) |
| Sangfor | Trojan.MSIL.Agent.FDD |
| SentinelOne | Static AI - Suspicious PE |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Gen.MBT |
| Tencent | Msil.Trojan-Dropper.Agent.Iajl |
| Trapmine | malicious.moderate.ml.score |
| VBA32 | TrojanDropper.MSIL.Agent |
| VIPRE | Generic.MSIL.Starter.1.19937776 |
| Webroot | W32.Trojan.Gen |
| Xcitium | Malware@#12c2lmv45nrqk |
| Yandex | Trojan.DR.Agent!7/Y53ZxhQzg |
| Zillya | Dropper.Agent.Win32.462674 |
| ZoneAlarm | Trojan-Dropper.MSIL.Agent.seskpc |