Asus Webstorage Upate.exe
Classification: Malicious
Asus Webstorage Upate.exe is a malicious file sample. Linked to Blacktech activity. Reported by 2 threat sources, last seen 2026-03-03.
Detection summary
- 54 antivirus detections (2% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| BlackTech |
MalwarePatrol |
2026-03-03 18:16:27 |
2026-03-03 18:16:27 |
malicious-activity
|
G0098 BlackTech
|
| malicious.moderate.ml |
Hybrid-Analysis |
2019-09-05 01:00:05 |
2019-09-05 01:00:05 |
|
|
Tags
blacktech
temp.overboard
palmerworm
g0098
t-apt-03
manga taurus
circuit panda
radio panda
red djinn
earth hundun
huapi
Sample information
- Filenames
- Asus Webstorage Upate.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 4378624 bytes
- MD5
d864d3bf4371dc43bdb5b8c7e24ebd4b
- SHA-1
7f107d1145ca1947900fbbb65a1fd689d6f789c3
- SHA-256
634839b452e43f28561188a476af462c301b47bddd0468dd8c4f452ae80ea0af
- First indexed
- 2019-09-05 01:00:05
- Last updated
- 2026-07-08 03:10:49
Antivirus detections
| Engine | Detection |
| Trapmine | malicious.moderate.ml.score |
| VBA32 | suspected of Trojan.Downloader.gen.h |
| ALYac | Trojan.Agent.Plead |
| APEX | Malicious |
| AVG | Win32:Trojan-gen |
| AhnLab-V3 | Trojan/Win32.Icondown.R319277 |
| Alibaba | Trojan:Win32/Plead.bacf093c |
| Antiy-AVL | GrayWare/Win32.Blacktech |
| Arcabit | Trojan.Agent.EGKH |
| Avast | Win32:Trojan-gen |
| BitDefender | Trojan.Agent.EGKH |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.plead |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.DownLoader30.29688 |
| ESET-NOD32 | Win32/Plead.BH trojan |
| Emsisoft | Trojan.Agent.EGKH (B) |
| Fortinet | W32/Plead.BH!tr |
| GData | Trojan.Agent.EGKH |
| Google | Detected |
| Jiangmin | Trojan.Agentb.pgd |
| K7AntiVirus | Unwanted-Program ( 005ce7371 ) |
| K7GW | Unwanted-Program ( 005ce7371 ) |
| Kaspersky | HEUR:Trojan.Win32.Agentb.gen |
| Kingsoft | Win32.Trojan.Agentb.a |
| Lionic | Trojan.Win32.Plead.4!c |
| Malwarebytes | Plead.Backdoor.Bot.DDS |
| McAfeeD | ti!634839B452E4 |
| MicroWorld-eScan | Trojan.Agent.EGKH |
| Microsoft | Trojan:Win32/Casdet!rfn |
| NANO-Antivirus | Trojan.Win32.Plead.gkqoga |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Ransom.PornoAsset!8.6AA (CLOUD) |
| Sangfor | Trojan.Win32.Casdet.IOC |
| Sophos | Mal/Generic-S |
| Symantec | Trojan Horse |
| Tencent | Malware.Win32.Gencirc.13f3e628 |
| TrellixENS | GenericRXIP-PY!D864D3BF4371 |
| TrendMicro | TROJ_ICONDOWN.ZKGL-A |
| TrendMicro-HouseCall | TROJ_ICONDOWN.ZKGL-A |
| VBA32 | BScope.Trojan.PLEAD |
| VIPRE | Trojan.Agent.EGKH |
| Varist | W32/ABTrojan.KZFQ-2567 |
| ViRobot | Trojan.Win32.Z.Plead.4378624 |
| Webroot | W32.Trojan.Gen |
| Xcitium | Malware@#150bsugk87o6t |
| Zillya | Trojan.Plead.Win32.29 |
| alibabacloud | Trojan:Win/Plead.BJ |
| Bkav | W32.Malware.1E8302C |
| Elastic | malicious (moderate confidence) |
| Skyhigh | GenericRXIP-PY!D864D3BF4371 |
Process list
| Name | Command line |
| AsusWebstorageUpate.exe | |