[email protected]
Classification: Malicious
[email protected] is a malicious file sample. Linked to Bad Rabbit, Mimikatz malware. Reported by 6 threat sources, last seen 2026-08-29.
Detection summary
- 88 antivirus detections (91% detection ratio)
- 0 IDS alerts
- 63 processes observed
- 2 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: BAD RABBIT (S0606) MIMIKATZ (S0002)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Badrabbit | Triage | 2026-01-31 23:35:34 | 2026-08-29 01:15:46 | malicious-activity | S0606 Bad Rabbit |
| Generic Malware | Cyber Threat Alliance | 2026-08-26 10:01:44 | 2026-08-27 10:14:54 | malicious-activity | |
| Mimikatz | Triage | 2026-04-08 13:34:41 | 2026-04-17 01:03:28 | malicious-activity | S0002 Mimikatz |
| Generic Malware | Hybrid-Analysis | 2023-07-22 18:30:03 | 2026-04-16 09:45:05 | ||
| MimiKatz | ThreatFox Abuse.ch | 2025-03-17 17:37:28 | 2025-03-19 17:27:37 | S0002 Mimikatz | |
| BadRabbit | MalwareBazaar Abuse.ch | 2022-04-19 16:18:28 | 2022-04-19 16:18:28 | malicious-activity | S0606 Bad Rabbit |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-04-19 16:18:28 | 2022-04-19 16:18:28 | malicious-activity | |
| locky,petya,ransomware,BadRabbit | Maltiverse | 2017-10-26 07:04:40 | 2017-10-26 07:04:40 |
Tags
rootkit locky petya ransomware badrabbit win.mimikatz windows-server-utility mimikatz discovery execution persistence adware spyware android linux macosSample information
- Filenames
- [email protected], BadRabbit.exe, [email protected], UrgentXContractXAction.pdf.exe, Urgent Contract Action.pdf.exe, runbad.exe, [email protected], Urget Contract Action_Urgent Contract Action.pdf.exe, 630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da, Trojan-Ransom.Win32.BadRabbit.e-630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da.bin
- File type
- PE32 executable (console) Intel 80386, for MS Windows
- Size
- 441899 bytes
- MD5
fbbdc39af1139aebba4da004475e8839- SHA-1
de5c8d858e6e41da715dca1c019df0bfb92d32c0- SHA-256
630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da- SHA-512
74eca8c01de215b33d5ceea1fda3f3bef96b513f58a750dba04b0de36f7ef4f7846a6431d52879ca0d8641bfd504d4721a9a96fa2e18c6888fd67fa77686af87- First indexed
- 2017-10-26 07:04:40
- Last updated
- 2026-08-28 06:07:21
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Ransom.BadRabbit |
| APEX | Malicious |
| AVG | Win32:Malware-gen |
| AhnLab-V3 | Trojan/Win32.Diskcoder.R211512 |
| Alibaba | Ransom:Win32/Agent.190220 |
| Antiy-AVL | Trojan[Ransom]/Win32.BadRabbit |
| Arcabit | Trojan.Ransom.BadRabbit.A |
| Avast | Win32:Malware-gen |
| Avira | TR/Diskcoder.ezxim |
| Baidu | Win32.Trojan.Ransom.b |
| BitDefender | Trojan.Ransom.BadRabbit.A |
| Bkav | W32.RsRabND.Worm |
| CAT-QuickHeal | Trojan.Mauvaise.SL1 |
| CTX | exe.trojan.badrabbit |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.BadRabbit.2 |
| ESET-NOD32 | Win32/Diskcoder.D |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan-Ransom.BadRabbit (A) |
| F-Secure | Trojan:W32/Rabbad.A |
| Fortinet | W32/Diskcoder.D!tr.ransom |
| GData | Win32.Trojan-Ransom.BadRabbit.C |
| Detected | |
| Gridinsoft | Trojan.Win32.Gen.zv!s1 |
| Ikarus | Trojan.Win32.Diskcoder |
| Jiangmin | Trojan.BadRabbit.d |
| K7AntiVirus | Trojan ( 0051a3031 ) |
| K7GW | Trojan ( 0051a3031 ) |
| Kaspersky | Trojan-Ransom.Win32.BadRabbit.e |
| Kingsoft | Win32.Troj.Blackmail.lc |
| Lionic | Trojan.Win32.BadRabbit.tp36 |
| Malwarebytes | Ransom.BadRabbit |
| MaxSecure | Trojan.Malware.121218.susgen |
| McAfee | Generic.adp |
| McAfeeD | ti!630325CAC09A |
| MicroWorld-eScan | Trojan.Ransom.BadRabbit.A |
| Microsoft | Ransom:Win32/Tibbar.A |
| NANO-Antivirus | Trojan.Win32.BadRabbit.evwtjg |
| Paloalto | generic.ml |
| Panda | W32/Ransom.G.worm |
| Rising | Ransom.DiskCoder!1.AE39 (CLASSIC) |
| Sangfor | Suspicious.Win32.Save.a |
| Skyhigh | Generic.adp |
| Sophos | Troj/Ransom-ERK |
| Symantec | Ransom.BadRabbit |
| TACHYON | Ransom/W32.BadRabbit.441899 |
| Tencent | Malware.Win32.Gencirc.10b6d41e |
| Trapmine | suspicious.low.ml.score |
| TrendMicro | Ransom_BADRABBIT.A |
| TrendMicro-HouseCall | Ransom_BADRABBIT.A |
| VBA32 | BScope.Trojan.BadRabbit |
| VIPRE | Trojan.Ransom.BadRabbit.A |
| Varist | W32/DiskCoder.A.gen!Eldorado |
| ViRobot | Trojan.Win32.S.Ransom.441899 |
| VirIT | Trojan.Win32.BadRabbit.A |
| Webroot | W32.Adware.Gen |
| Xcitium | Malware@#1khr9uloessgt |
| Yandex | Trojan.GenAsa!ZViGq23r774 |
| Zillya | Trojan.Gen.Win32.1539 |
| ZoneAlarm | Troj/Ransom-ERK |
| Zoner | Trojan.Win32.64391 |
| alibabacloud | RansomWare |
| huorong | Ransom/BadRabbit.a |
| ClamAV | Win.Dropper.Diskcoder-6355411-0 |
| MicroWorld-eScan | Trojan.GenericKD.6139887 |
| Cybereason | malicious.af1139 |
| Cyren | W32/DiskCoder.A.gen!Eldorado |
| BitDefender | Trojan.GenericKD.6139887 |
| Tencent | Malware.Win32.Gencirc.10b9bb5e |
| Ad-Aware | Trojan.GenericKD.6139887 |
| Comodo | Malware@#1khr9uloessgt |
| F-Secure | Trojan.TR/Diskcoder.ezxim |
| McAfee-GW-Edition | Generic.adp |
| FireEye | Trojan.GenericKD.6139887 |
| Sophos | Mal/Generic-S + Troj/Ransom-ERK |
| SentinelOne | Static AI - Suspicious PE |
| Webroot | W32.Badrabbit.Ransom |
| Kingsoft | Win32.Troj.Blackmail.lc.(kcloud) |
| Gridinsoft | Trojan.Win32.Ransom.zv!s1 |
| Arcabit | Trojan.Generic.D5DAFEF |
| Cynet | Malicious (score: 100) |
| MAX | malware (ai score=100) |
| Rising | Ransom.Diskcoder!1.AE39 (CLOUD) |
| Ikarus | Trojan-Ransom.BadRabbit |
| BitDefenderTheta | Gen:NN.ZexaF.34588.Au3@aKppIcai |
Network contacts
Process list
| Name | Command line |
|---|---|
| BadRabbit.exe | |
| rundll32.exe | %WINDIR%\system32\rundll32.exe %WINDIR%\infpub.dat,#1 15 |
| cmd.exe | /c schtasks /Delete /F /TN rhaegal |
| schtasks.exe | schtasks /Delete /F /TN rhaegal |
| cmd.exe | /c schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR "%WINDIR%\system32\cmd.exe /C Start \"\" \"%WINDIR%\dispci.exe\" -id 1030153374 && exit" |
| schtasks.exe | schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR "%WINDIR%\system32\cmd.exe /C Start \"\" \"%WINDIR%\dispci.exe\" -id 1030153374 && exit" |
| cmd.exe | /c schtasks /Create /SC once /TN drogon /RU SYSTEM /TR "%WINDIR%\system32\shutdown.exe /r /t 0 /f" /ST 02:09:00 |
| schtasks.exe | schtasks /Create /SC once /TN drogon /RU SYSTEM /TR "%WINDIR%\system32\shutdown.exe /r /t 0 /f" /ST 02:09:00 |
| 8E66.tmp | \\.\pipe\{65B156F8-F73C-4B42-B512-941DD0FD4AF2} |
| cmd.exe | /c wevtutil cl Setup & wevtutil cl System & wevtutil cl Security & wevtutil cl Application & fsutil usn deletejournal /D C: |
| wevtutil.exe | wevtutil cl Setup |
| wevtutil.exe | wevtutil cl System |
| wevtutil.exe | wevtutil cl Security |
| wevtutil.exe | wevtutil cl Application |
| fsutil.exe | fsutil usn deletejournal /D C: |
| cmd.exe | /c schtasks /Delete /F /TN drogon |
| schtasks.exe | schtasks /Delete /F /TN drogon |
| cmd.exe | /C Start "" "%WINDIR%\dispci.exe" -id 1030153374 && exit |
| dispci.exe | -id 1030153374 |
| cmd.exe | /c schtasks /Delete /F /TN rhaegal |
| schtasks.exe | schtasks /Delete /F /TN rhaegal |
| UrgetContractAction_UrgentContractAction.pdf.exe | |
| rundll32.exe | %WINDIR%\system32\rundll32.exe %WINDIR%\infpub.dat,#1 15 |
| cmd.exe | /c schtasks /Delete /F /TN rhaegal |
| schtasks.exe | schtasks /Delete /F /TN rhaegal |
| cmd.exe | /c schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR "%WINDIR%\system32\cmd.exe /C Start \"\" \"%WINDIR%\dispci.exe\" -id 3700855830 && exit" |
| schtasks.exe | schtasks /Create /RU SYSTEM /SC ONSTART /TN rhaegal /TR "%WINDIR%\system32\cmd.exe /C Start \"\" \"%WINDIR%\dispci.exe\" -id 3700855830 && exit" |
| cmd.exe | /c schtasks /Create /SC once /TN drogon /RU SYSTEM /TR "%WINDIR%\system32\shutdown.exe /r /t 0 /f" /ST 15:01:00 |
| schtasks.exe | schtasks /Create /SC once /TN drogon /RU SYSTEM /TR "%WINDIR%\system32\shutdown.exe /r /t 0 /f" /ST 15:01:00 |
| 47CA.tmp | \\.\pipe\{9C27DEFC-31B9-4848-B186-3AD0608C81F1} |