Asus Webstorage Upate.exe

Classification: Malicious

Asus Webstorage Upate.exe is a malicious file sample. Linked to Blacktech activity. Reported by 2 threat sources, last seen 2026-03-03.

Detection summary

  • 54 antivirus detections (2% detection ratio)
  • 0 IDS alerts
  • 1 processes observed
  • 1 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Intrusion sets: BLACKTECH (G0098)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
BlackTech MalwarePatrol 2026-03-03 18:16:27 2026-03-03 18:16:27 malicious-activity G0098 BlackTech
malicious.moderate.ml Hybrid-Analysis 2019-09-05 01:00:05 2019-09-05 01:00:05

Tags

blacktech temp.overboard palmerworm g0098 t-apt-03 manga taurus circuit panda radio panda red djinn earth hundun huapi

Sample information

Filenames
Asus Webstorage Upate.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
4378624 bytes
MD5
d864d3bf4371dc43bdb5b8c7e24ebd4b
SHA-1
7f107d1145ca1947900fbbb65a1fd689d6f789c3
SHA-256
634839b452e43f28561188a476af462c301b47bddd0468dd8c4f452ae80ea0af
First indexed
2019-09-05 01:00:05
Last updated
2026-07-08 03:10:49

Antivirus detections

EngineDetection
Trapminemalicious.moderate.ml.score
VBA32suspected of Trojan.Downloader.gen.h
ALYacTrojan.Agent.Plead
APEXMalicious
AVGWin32:Trojan-gen
AhnLab-V3Trojan/Win32.Icondown.R319277
AlibabaTrojan:Win32/Plead.bacf093c
Antiy-AVLGrayWare/Win32.Blacktech
ArcabitTrojan.Agent.EGKH
AvastWin32:Trojan-gen
BitDefenderTrojan.Agent.EGKH
BkavW32.AIDetectMalware
CTXexe.trojan.plead
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebTrojan.DownLoader30.29688
ESET-NOD32Win32/Plead.BH trojan
EmsisoftTrojan.Agent.EGKH (B)
FortinetW32/Plead.BH!tr
GDataTrojan.Agent.EGKH
GoogleDetected
JiangminTrojan.Agentb.pgd
K7AntiVirusUnwanted-Program ( 005ce7371 )
K7GWUnwanted-Program ( 005ce7371 )
KasperskyHEUR:Trojan.Win32.Agentb.gen
KingsoftWin32.Trojan.Agentb.a
LionicTrojan.Win32.Plead.4!c
MalwarebytesPlead.Backdoor.Bot.DDS
McAfeeDti!634839B452E4
MicroWorld-eScanTrojan.Agent.EGKH
MicrosoftTrojan:Win32/Casdet!rfn
NANO-AntivirusTrojan.Win32.Plead.gkqoga
Paloaltogeneric.ml
PandaTrj/GdSda.A
RisingRansom.PornoAsset!8.6AA (CLOUD)
SangforTrojan.Win32.Casdet.IOC
SophosMal/Generic-S
SymantecTrojan Horse
TencentMalware.Win32.Gencirc.13f3e628
TrellixENSGenericRXIP-PY!D864D3BF4371
TrendMicroTROJ_ICONDOWN.ZKGL-A
TrendMicro-HouseCallTROJ_ICONDOWN.ZKGL-A
VBA32BScope.Trojan.PLEAD
VIPRETrojan.Agent.EGKH
VaristW32/ABTrojan.KZFQ-2567
ViRobotTrojan.Win32.Z.Plead.4378624
WebrootW32.Trojan.Gen
XcitiumMalware@#150bsugk87o6t
ZillyaTrojan.Plead.Win32.29
alibabacloudTrojan:Win/Plead.BJ
BkavW32.Malware.1E8302C
Elasticmalicious (moderate confidence)
SkyhighGenericRXIP-PY!D864D3BF4371

Network contacts

185.227.153.186

DNS requests

update.panasocin.com

Process list

NameCommand line
AsusWebstorageUpate.exe