5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680

Classification: Malicious

5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680 is a malicious file sample. Linked to Xloader malware. Detected by 52 antivirus engines.

Detection summary

  • 52 antivirus detections
  • 0 IDS alerts
  • 1 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: XLOADER (S1207)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-07-29 11:30:04 2025-07-29 12:30:22
Formbook MalwareBazaar Abuse.ch 2024-03-05 13:11:53 2024-03-05 13:11:53 malicious-activity S1207 XLoader

Sample information

Filenames
5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680, factura pendiente.exe
File type
application/x-dosexec
Size
620784 bytes
MD5
0a22c338bb24f710b19b09e76094eb32
SHA-1
e42fba70554d2ad795e01f28adbe63c180c474dc
SHA-256
5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680
First indexed
2024-03-05 14:18:20
Last updated
2026-09-03 00:19:51

Antivirus detections

EngineDetection
ALYacGen:Variant.Application.Tedy.16869
AVGNSIS:MalwareX-gen [Misc]
AhnLab-V3Trojan/Win.Generic.R637917
AlibabaTrojan:Win32/GuLoader.76ad2679
Antiy-AVLTrojan[Injector]/NSIS.Agent
ArcabitTrojan.Application.Tedy.D41E5
AvastNSIS:MalwareX-gen [Misc]
AviraTR/W32.Evo
BitDefenderGen:Variant.Application.Tedy.16869
CTXexe.trojan.guloader
CrowdStrikewin/malicious_confidence_90% (W)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebTrojan.Siggen31.27404
ESET-NOD32NSIS/Injector.CJP trojan
Elasticmalicious (high confidence)
EmsisoftGen:Variant.Application.Tedy.16869 (B)
F-SecureTrojan.TR/Agent
FortinetNSIS/Injector.1539!tr
GDataGen:Variant.Application.Tedy.16869
GoogleDetected
K7AntiVirusTrojan ( 005b28561 )
K7GWTrojan ( 005b28561 )
KasperskyHEUR:Trojan.Win32.GuLoader.gen
KingsoftWin32.Trojan.GuLoader.gen
LionicTrojan.Win32.GuLoader.4!c
MaxSecureTrojan.Malware.700423237.susgen
McAfeeDti!5F04C6FCA105
MicroWorld-eScanGen:Variant.Application.Tedy.16869
MicrosoftTrojan:Win32/Etset!rfn
NANO-AntivirusTrojan.Win32.Inject5.kkgpbp
Paloaltogeneric.ml
RisingTrojan.Injector/NSIS!8.1294D (CLOUD)
SangforSuspicious.Win32.Save.ins
SentinelOneStatic AI - Suspicious PE
SophosMal/Generic-S
SymantecTrojan Horse
TencentWin32.Trojan.FalseSign.Kajl
TrellixENSArtemis!0A22C338BB24
TrendMicroTrojan.Win32.GULOADER.USBLH226
TrendMicro-HouseCallTrojan.Win32.GULOADER.USBLH226
VBA32Trojan.GuLoader
VIPREGen:Variant.Application.Tedy.16869
VaristW32/Ninjector.MA.gen!Eldorado
VirITTrojan.Win32.NSISDrp.CHQF
WebrootW32.Trojan.Guloader
XcitiumMalware@#lzicznpe8jet
YandexTrojan.Igent.b1Sx8J.23
ZillyaTrojan.Guloader.Win32.1961
alibabacloudTrojan:Win/Etset.Gen
huorongTrojan/Injector.bhy

Process list

NameCommand line
5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680.exe