7d5fb292b4477237a05a35eb135a13c9f6d1177987217e94c3558b91fa97c285

Classification: Malicious

7d5fb292b4477237a05a35eb135a13c9f6d1177987217e94c3558b91fa97c285 is a malicious file sample. Linked to Remcos malware. Detected by 24 antivirus engines.

Detection summary

  • 24 antivirus detections
  • 1 IDS alerts
  • 7 processes observed
  • 2 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Malware families: REMCOS (S0332)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-02-06 09:15:03 2026-09-02 11:45:07 malicious-activity
RemcosRAT MalwareBazaar Abuse.ch 2024-02-06 08:57:47 2024-02-06 08:57:47 malicious-activity S0332 Remcos

Tags

windows-server-utility infostealer

Sample information

Filenames
7d5fb292b4477237a05a35eb135a13c9f6d1177987217e94c3558b91fa97c285, PRODUCT LIST 80487 2024.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
1179136 bytes
MD5
1f8a3704996a9d31c8be761ed319b429
SHA-1
80cd86b5df31d1fac398eb2872641603888b95be
SHA-256
7d5fb292b4477237a05a35eb135a13c9f6d1177987217e94c3558b91fa97c285
First indexed
2024-02-06 08:59:27
Last updated
2026-09-02 11:45:08

Antivirus detections

EngineDetection
APEXMalicious
AVGFileRepMalware [Trj]
AvastFileRepMalware [Trj]
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (D)
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
Elasticmalicious (high confidence)
FortinetMSIL/GenKryptik.GTLY!tr
GoogleDetected
IkarusWin32.Outbreak
KasperskyUDS:Trojan.MSIL.Taskun.gen
MalwarebytesMachineLearning/Anomalous.100%
MaxSecureTrojan.Malware.300983.susgen
MicrosoftTrojan:Win32/Wacatac.B!ml
RisingMalware.Obfus/[email protected] (RDM.MSIL2:iqUwFh7Qds7j69ljvDHVuQ)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.tc
SophosTroj/Krypt-ABH
SymantecScr.Malcode!gdn33
VBA32TrojanLoader.MSIL.DaVinci.Heur
VirITTrojan.Win32.MSIL_Heur.A
ZoneAlarmUDS:Trojan.MSIL.Taskun.gen

Network contacts

146.70.57.34 178.237.33.50

DNS requests

paygateme.net geoplugin.net

Process list

NameCommand line
PRODUCTLIST804872024.exe
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\cxqcWAYv.exe"
schtasks.exe/Create /TN "Updates\cxqcWAYv" /XML "%TEMP%\tmpD410.tmp"
PRODUCTLIST804872024.exe
PRODUCTLIST804872024.exe/stext "%TEMP%\ksqtlp"
PRODUCTLIST804872024.exe/stext "%TEMP%\vmemliahy"
PRODUCTLIST804872024.exe/stext "%TEMP%\fpjwmslbuegys"