rt5.exe
Classification: Malicious
rt5.exe is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-12-17. Detected by 40 antivirus engines.
Detection summary
- 40 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | MalwareBazaar Abuse.ch | 2021-12-17 21:15:09 | 2021-12-17 21:15:09 | malicious-activity | S0382 ServHelper |
| Generic.Malware | MalwareBazaar Abuse.ch | 2021-12-17 21:15:09 | 2021-12-17 21:15:09 | malicious-activity |
Sample information
- Filenames
- rt5.exe
- File type
- application/x-dosexec
- MD5
e7f692b7d820271b640cf6a2520b7409- SHA-1
1eefef95c6ff783712f2d1da26e9cfc7e618c3f7- SHA-256
723fe07654cfbf19c4cbe7b63617f3a5aaf306c11e092841397abaeff80c50c1- First indexed
- 2021-12-17 23:15:04
- Last updated
- 2026-04-08 22:51:54
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Cobalt.trRF |
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.Packed.18626 |
| MicroWorld-eScan | Trojan.GenericKD.47648031 |
| FireEye | Trojan.GenericKD.47648031 |
| McAfee | Artemis!E7F692B7D820 |
| Cylance | Unsafe |
| K7AntiVirus | Trojan ( 00580cbe1 ) |
| K7GW | Trojan ( 00580cbe1 ) |
| Symantec | Trojan.Gen.MBT |
| ESET-NOD32 | a variant of WinGo/GoCLR.B |
| TrendMicro-HouseCall | TROJ_GEN.R002C0WLH21 |
| Kaspersky | Trojan-Dropper.MSIL.Agent.seskre |
| BitDefender | Trojan.GenericKD.47648031 |
| Avast | FileRepMalware |
| Rising | HackTool.GoCLR!1.D71D (CLASSIC) |
| Ad-Aware | Trojan.GenericKD.47648031 |
| Emsisoft | Trojan.GenericKD.47648031 (B) |
| TrendMicro | TROJ_GEN.R002C0WLH21 |
| McAfee-GW-Edition | BehavesLike.Win64.Gravity.rh |
| Sophos | Mal/Generic-S |
| Ikarus | Trojan.WinGo.Goclr |
| GData | Trojan.GenericKD.47648031 |
| eGambit | Unsafe.AI_Score_100% |
| Avira | HEUR/AGEN.1201987 |
| Gridinsoft | Ransom.Win64.Sabsik.sa |
| Arcabit | Trojan.Generic.D2D70D1F |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Generic.R458300 |
| VBA32 | TrojanDropper.MSIL.Agent |
| ALYac | Trojan.GenericKD.47648031 |
| MAX | malware (ai score=83) |
| Malwarebytes | Trojan.MalPack.GO |
| APEX | Malicious |
| Tencent | Win32.Trojan.Goclr.Anpm |
| Fortinet | W64/GoCLR.B!tr |
| AVG | FileRepMalware |
| Panda | Trj/CI.A |
| CrowdStrike | win/malicious_confidence_100% (W) |