WSoRfkK.exe
Classification: Malicious
WSoRfkK.exe is a malicious file sample. Linked to Emotet malware. Reported by 1 threat source, last seen 2020-07-23. Detected by 72 antivirus engines.
Detection summary
- 72 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: EMOTET (S0367)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Heodo | Abuse.ch | 2020-07-23 09:22:08 | 2020-07-23 09:22:08 | S0367 Emotet |
Sample information
- Filenames
- WSoRfkK.exe
- File type
- application/x-dosexec
- MD5
6dcaef4389944d51a498b692b606bc37- SHA-1
521f0ccac8e907b40185ce99579414f95ede402d- SHA-256
69b044ad597baaf67c1853d6962d779bf8281278daf91c770be03e020436706f- First indexed
- 2020-07-23 10:15:12
- Last updated
- 2026-09-03 00:42:52
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetectVM.malware2 |
| McAfee | GenericRXAA-AA!6DCAEF438994 |
| Cylance | Unsafe |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| K7GW | Riskware ( 0040eff71 ) |
| F-Prot | W32/Kryptik.BQX.gen!Eldorado |
| APEX | Malicious |
| Endgame | malicious (high confidence) |
| DrWeb | Trojan.DownLoader34.3170 |
| Fortinet | W32/GenericKDZ.6887!tr |
| ViRobot | Trojan.Win32.Emotet.548864.C |
| AhnLab-V3 | Malware/Win32.Generic.C4167855 |
| Microsoft | Trojan:Win32/Emotet.GKM!MTB |
| ESET-NOD32 | a variant of Win32/GenKryptik.EOTD |
| Malwarebytes | Trojan.Emotet |
| Ikarus | Trojan-Banker.Emotet |
| ALYac | Trojan.Agent.EUBS |
| AVG | Win32:Trojan-gen |
| Alibaba | Trojan:Win32/Emotet.d9f8f935 |
| Antiy-AVL | Trojan/Win32.SGeneric |
| Arcabit | Trojan.Agent.EUBS |
| Avast | Win32:Trojan-gen |
| Avira | HEUR/AGEN.1345724 |
| BitDefender | Trojan.Agent.EUBS |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Emotet.S15140201 |
| CTX | exe.trojan.emotet |
| ClamAV | Win.Trojan.Generickdz-9636359-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | Win32/Emotet.CD |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Emotet (A) |
| F-Secure | Heuristic.HEUR/AGEN.1345724 |
| FireEye | Generic.mg.6dcaef4389944d51 |
| Fortinet | W32/GenKryptik.EPAZ!tr |
| GData | Trojan.Agent.EUBS |
| Detected | |
| Gridinsoft | Trojan.Win32.Emotet.oa!s1 |
| Jiangmin | Backdoor.Emotet.nt |
| K7AntiVirus | Trojan ( 0056c5421 ) |
| K7GW | Trojan ( 0056c5421 ) |
| Kaspersky | HEUR:Backdoor.Win32.Emotet.vho |
| Lionic | Virus.Win32.Virut.mfMF |
| Malwarebytes | Generic.Malware.AI.DDS |
| McAfee | Emotet-FRI!6DCAEF438994 |
| McAfeeD | ti!69B044AD597B |
| MicroWorld-eScan | Trojan.Agent.EUBS |
| Microsoft | Trojan:Win32/Emotet.ARJ!MTB |
| NANO-Antivirus | Trojan.Win32.Emotet.hoquhq |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Kryptik!1.C955 (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Emotet |
| Sangfor | Virus.Win32.Save.a |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | Emotet-FRI!6DCAEF438994 |
| Sophos | Troj/Emotet-CKF |
| Symantec | Trojan.Emotet |
| Tencent | Backdoor.Win32.Agent.ht |
| Trapmine | malicious.moderate.ml.score |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9V |
| VBA32 | BScope.Trojan.Zenpak |
| VIPRE | Trojan.Agent.EUBS |
| Varist | W32/Emotet.AOB.gen!Eldorado |
| VirIT | Trojan.Win32.Emotet.CII |
| Xcitium | Malware@#3b2rjehq27l5u |
| Zillya | Trojan.Emotet.Win32.22491 |
| ZoneAlarm | Troj/Emotet-CKF |
| alibabacloud | Trojan[stealer]:Win/Emotet.CD |
| huorong | Trojan/Emotet.ff |