vmware_files.exe

Classification: Malicious

vmware_files.exe is a malicious file sample. Reported by 1 threat source, last seen 2024-02-19. Detected by 21 antivirus engines.

Detection summary

  • 21 antivirus detections
  • 0 IDS alerts
  • 5 processes observed
  • 0 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-02-19 08:00:06 2024-02-19 08:00:06

Tags

evasive

Sample information

Filenames
vmware_files.exe
File type
PE32 executable (console) Intel 80386, for MS Windows
Size
64000 bytes
MD5
5684900a9c99bf35982073c396fd00d9
SHA-1
6dc67d42f852876dc524abea287c2f235333dbfb
SHA-256
5df0c5662e967c799e0f6708228b1cdd5c00ca1721ff50b9bc706928140ecdf2
First indexed
2024-02-19 07:38:33
Last updated
2026-09-03 00:50:12

Antivirus detections

EngineDetection
ArcabitTrojan.Mint.Zard.42
BitDefenderGen:Heur.Mint.Zard.42
BitDefenderThetaGen:NN.ZexaF.36744.dqW@ayzGIKk
BkavW32.AIDetectMalware
CrowdStrikewin/grayware_confidence_60% (D)
CynetMalicious (score: 100)
EmsisoftGen:Heur.Mint.Zard.42 (B)
FireEyeGen:Heur.Mint.Zard.42
GDataGen:Heur.Mint.Zard.42
GoogleDetected
IkarusTrojan.Agent.MZ
KasperskyTrojan.Win32.Khalesi.oxjx
MAXmalware (ai score=83)
McAfeeArtemis!5684900A9C99
MicroWorld-eScanGen:Heur.Mint.Zard.42
MicrosoftTrojan:Win32/Wacatac.B!ml
Rising[email protected] (RDML:KzgFP2wFhuIE3xi9+5NFFg)
SkyhighArtemis
TrendMicro-HouseCallTROJ_GEN.R014H09BJ24
VIPREGen:Heur.Mint.Zard.42
ZoneAlarmTrojan.Win32.Khalesi.oxjx

Process list

NameCommand line
vmware_files.exe
cmd.exe/c cmd.exe /c net user hello123 hellxxx_Hxxx /ADD && net localgroup Administrators hello123 /ADD
cmd.exe/c net user hello123 hellxxx_Hxxx /ADD
net.exenet user hello123 hellxxx_Hxxx /ADD
net1.exe%WINDIR%\system32\net1 user hello123 hellxxx_Hxxx /ADD