b921d48d992e073c5b641071b28984f6.exe
Classification: Malicious
b921d48d992e073c5b641071b28984f6.exe is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-07-13.
Detection summary
- 85 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | Abuse.ch | 2021-07-13 06:24:51 | 2021-07-13 06:24:51 | malicious-activity | S0382 ServHelper |
Sample information
- Filenames
- b921d48d992e073c5b641071b28984f6.exe
- File type
- application/x-dosexec
- MD5
b921d48d992e073c5b641071b28984f6- SHA-1
c02f4616d42612057ad062768a6fdf54bd6c5564- SHA-256
64797d37b57cc5a503f914a94995b7c830e4b2b52e535b8b53363355b739b38f- First indexed
- 2021-07-13 08:15:08
- Last updated
- 2026-06-21 01:16:34
Antivirus detections
| Engine | Detection |
|---|---|
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.MulDrop17.61507 |
| MicroWorld-eScan | MemScan:Trojan.GenericKDZ.76333 |
| FireEye | MemScan:Trojan.GenericKDZ.76333 |
| McAfee | Artemis!B921D48D992E |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 0054c4a01 ) |
| Alibaba | Trojan:Win32/Crypzip.72c18d59 |
| K7GW | Trojan ( 0054c4a01 ) |
| Cybereason | malicious.6d4261 |
| BitDefenderTheta | Gen:NN.ZexaF.34790.wuW@am!rPBNG |
| Cyren | W32/Emotet.BCR.gen!Eldorado |
| ESET-NOD32 | multiple detections |
| APEX | Malicious |
| Paloalto | generic.ml |
| ClamAV | Win.Packed.Filerepmalware-9864117-0 |
| Kaspersky | Trojan.Win32.Crypzip.yb |
| BitDefender | MemScan:Trojan.GenericKDZ.76333 |
| Avast | Win32:PWSX-gen [Trj] |
| Tencent | Win32.Trojan.Zenpak.Pepd |
| Ad-Aware | MemScan:Trojan.GenericKDZ.76333 |
| Emsisoft | Trojan.Crypt (A) |
| TrendMicro | TROJ_GEN.R011C0WGC21 |
| McAfee-GW-Edition | BehavesLike.Win32.FakeRena.tc |
| Sophos | Mal/Generic-S |
| SentinelOne | Static AI - Malicious PE |
| GData | Win32.Trojan.BSE.15ZSUEQ |
| Avira | HEUR/AGEN.1140896 |
| MAX | malware (ai score=100) |
| Antiy-AVL | Trojan/Generic.ASMalwS.332AC76 |
| Arcabit | Trojan.Generic.D12A2D |
| ZoneAlarm | HEUR:Trojan-PSW.Win32.Coins.gen |
| Microsoft | Trojan:Win32/Glupteba!ml |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Agent.C4544191 |
| VBA32 | BScope.Trojan.Wacatac |
| ALYac | MemScan:Trojan.GenericKDZ.76333 |
| Malwarebytes | Malware.AI.4230390294 |
| TrendMicro-HouseCall | TROJ_GEN.R011C0WGC21 |
| Rising | Trojan.HiddenRun/SFX!1.D57B (CLASSIC) |
| Ikarus | Trojan.Win32.Krypt |
| Fortinet | W32/Coins!tr.pws |
| AVG | Win32:PWSX-gen [Trj] |
| Panda | Trj/CI.A |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Qihoo-360 | Win32/Trojan.Zenpak.HyoDgRMA |
| ALYac | Backdoor.Agent.ServHelper |
| AVG | NSIS:PWSX-gen [Trj] |
| Alibaba | Trojan:Win32/Crypzip.da4fefa5 |
| Antiy-AVL | Trojan[Backdoor]/Win32.Agent |
| Arcabit | Dump:Trojan.Generic.D12A2D |
| Avast | NSIS:PWSX-gen [Trj] |
| Avira | HEUR/AGEN.1366082 |
| BitDefender | Dump:Trojan.GenericKDZ.76333 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.16823339728984f6 |
| CTX | exe.trojan.dump |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| F-Secure | Trojan.TR/Crypt.Agent.nvpdu |
| FireEye | Generic.mg.b921d48d992e073c |
| Fortinet | W32/Kryptik.HLVY!tr |
| GData | Dump:Trojan.GenericKDZ.76333 |
| Detected | |
| Ikarus | Packed.Win32.Crypt |
| Kingsoft | malware.kb.a.946 |
| Lionic | Trojan.Win32.Crypzip.4!c |
| Malwarebytes | Generic.Trojan.Malicious.DDS |
| McAfeeD | ti!64797D37B57C |
| MicroWorld-eScan | Dump:Trojan.GenericKDZ.76333 |
| Microsoft | Trojan:Win32/Azorult!rfn |
| NANO-Antivirus | Trojan.Win32.Zenpak.ixinxo |
| SUPERAntiSpyware | Trojan.Agent/Gen-Crypzip |
| Sangfor | Trojan.Win32.Crypzip.Vti1 |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | BehavesLike.Win32.Dropper.tc |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.Zenpak.Qgil |
| VIPRE | Dump:Trojan.GenericKDZ.76333 |
| Varist | W32/Kryptik.KZS.gen!Eldorado |
| Xcitium | Malware@#18stb5psajfbk |
| Zillya | Trojan.Coins.Win32.6558 |
| alibabacloud | Trojan[stealer]:Win/Coins.gen |
| huorong | Trojan/ClipBanker.e |