5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680
Classification: Malicious
5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680 is a malicious file sample. Linked to Xloader malware. Detected by 52 antivirus engines.
Detection summary
- 52 antivirus detections
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-07-29 11:30:04 |
2025-07-29 12:30:22 |
|
|
| Formbook |
MalwareBazaar Abuse.ch |
2024-03-05 13:11:53 |
2024-03-05 13:11:53 |
malicious-activity
|
S1207 XLoader
|
Sample information
- Filenames
- 5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680, factura pendiente.exe
- File type
- application/x-dosexec
- Size
- 620784 bytes
- MD5
0a22c338bb24f710b19b09e76094eb32
- SHA-1
e42fba70554d2ad795e01f28adbe63c180c474dc
- SHA-256
5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680
- First indexed
- 2024-03-05 14:18:20
- Last updated
- 2026-09-03 00:19:51
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Application.Tedy.16869 |
| AVG | NSIS:MalwareX-gen [Misc] |
| AhnLab-V3 | Trojan/Win.Generic.R637917 |
| Alibaba | Trojan:Win32/GuLoader.76ad2679 |
| Antiy-AVL | Trojan[Injector]/NSIS.Agent |
| Arcabit | Trojan.Application.Tedy.D41E5 |
| Avast | NSIS:MalwareX-gen [Misc] |
| Avira | TR/W32.Evo |
| BitDefender | Gen:Variant.Application.Tedy.16869 |
| CTX | exe.trojan.guloader |
| CrowdStrike | win/malicious_confidence_90% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen31.27404 |
| ESET-NOD32 | NSIS/Injector.CJP trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Application.Tedy.16869 (B) |
| F-Secure | Trojan.TR/Agent |
| Fortinet | NSIS/Injector.1539!tr |
| GData | Gen:Variant.Application.Tedy.16869 |
| Google | Detected |
| K7AntiVirus | Trojan ( 005b28561 ) |
| K7GW | Trojan ( 005b28561 ) |
| Kaspersky | HEUR:Trojan.Win32.GuLoader.gen |
| Kingsoft | Win32.Trojan.GuLoader.gen |
| Lionic | Trojan.Win32.GuLoader.4!c |
| MaxSecure | Trojan.Malware.700423237.susgen |
| McAfeeD | ti!5F04C6FCA105 |
| MicroWorld-eScan | Gen:Variant.Application.Tedy.16869 |
| Microsoft | Trojan:Win32/Etset!rfn |
| NANO-Antivirus | Trojan.Win32.Inject5.kkgpbp |
| Paloalto | generic.ml |
| Rising | Trojan.Injector/NSIS!8.1294D (CLOUD) |
| Sangfor | Suspicious.Win32.Save.ins |
| SentinelOne | Static AI - Suspicious PE |
| Sophos | Mal/Generic-S |
| Symantec | Trojan Horse |
| Tencent | Win32.Trojan.FalseSign.Kajl |
| TrellixENS | Artemis!0A22C338BB24 |
| TrendMicro | Trojan.Win32.GULOADER.USBLH226 |
| TrendMicro-HouseCall | Trojan.Win32.GULOADER.USBLH226 |
| VBA32 | Trojan.GuLoader |
| VIPRE | Gen:Variant.Application.Tedy.16869 |
| Varist | W32/Ninjector.MA.gen!Eldorado |
| VirIT | Trojan.Win32.NSISDrp.CHQF |
| Webroot | W32.Trojan.Guloader |
| Xcitium | Malware@#lzicznpe8jet |
| Yandex | Trojan.Igent.b1Sx8J.23 |
| Zillya | Trojan.Guloader.Win32.1961 |
| alibabacloud | Trojan:Win/Etset.Gen |
| huorong | Trojan/Injector.bhy |
Process list
| Name | Command line |
| 5f04c6fca105284e0be8855f6e8413af947b2e8159396c945e49f62749c5f680.exe | |