IM-vL5WWvBl.msi
Classification: Malicious
IM-vL5WWvBl.msi is a malicious file sample. Linked to Metamorfo malware. Reported by 1 threat source, last seen 2022-03-18. Detected by 27 antivirus engines.
Detection summary
- 27 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: METAMORFO (S0455)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Metamorfo | MalwareBazaar Abuse.ch | 2022-03-18 14:35:06 | 2022-03-18 14:35:06 | malicious-activity | S0455 Metamorfo |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-03-18 14:35:06 | 2022-03-18 14:35:06 | malicious-activity |
Sample information
- Filenames
- IM-vL5WWvBl.msi
- File type
- application/x-msi
- MD5
b374d94b1056b98d603ebe65913fe349- SHA-1
d9dfe18a29de5948845f135f45844bd68658b945- SHA-256
614c970bb776bad75d7b79488a591a5a9954cfd3835817246ce544ddb4a1fd83- First indexed
- 2022-03-18 15:15:04
- Last updated
- 2025-12-06 00:16:18
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.GenericKD.39282366 |
| AVG | Win32:Agent-BCYT [Drp] |
| Ad-Aware | Trojan.GenericKD.39282366 |
| Arcabit | Trojan.Generic.D25766BE |
| Avast | Win32:Agent-BCYT [Drp] |
| Avira | TR/Agent.thoku |
| BitDefender | Trojan.GenericKD.39282366 |
| Cynet | Malicious (score: 99) |
| ESET-NOD32 | a variant of Win32/Spy.Ousaban.B |
| Emsisoft | Trojan.GenericKD.39282366 (B) |
| FireEye | Trojan.GenericKD.39282366 |
| Fortinet | W32/Numando.AL!tr |
| GData | Trojan.GenericKD.39282366 |
| Ikarus | Trojan-Spy.Agent |
| K7AntiVirus | Spyware ( 0057394a1 ) |
| Kaspersky | UDS:Trojan-Banker.Win32.Javali.gen |
| MAX | malware (ai score=85) |
| McAfee | Artemis!E39592C0B83C |
| McAfee-GW-Edition | Artemis!Trojan |
| MicroWorld-eScan | Trojan.GenericKD.39282366 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Rising | Spyware.Ousaban!8.11EBD (CLOUD) |
| Sophos | Mal/Generic-S |
| Tencent | Win32.Trojan-spy.Ousaban.Pefk |
| TrendMicro-HouseCall | TROJ_GEN.R002H0CCG22 |
| VBA32 | TScope.Trojan.Delf |
| ZoneAlarm | HEUR:Trojan-Banker.Win32.Javali.gen |