7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c
Classification: Malicious
7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 51 antivirus detections
- 0 IDS alerts
- 10 processes observed
- 0 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-01-05 05:00:04 |
2026-09-02 13:45:06 |
malicious-activity
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2024-10-19 22:28:19 |
2024-10-19 22:28:19 |
malicious-activity
|
|
Tags
evasive
infostealer
njrat
Sample information
- Filenames
- 7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c, JJSPLOIT.V2.exe
- File type
- application/x-dosexec
- Size
- 3266048 bytes
- MD5
d4a776ea55e24d3124a6e0759fb0ac44
- SHA-1
f5932d234baccc992ca910ff12044e8965229852
- SHA-256
7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c
- First indexed
- 2024-10-19 23:21:16
- Last updated
- 2026-09-02 13:45:06
Antivirus detections
| Engine | Detection |
| ALYac | Generic.MSIL.PasswordStealerA.703EC6F9 |
| APEX | Malicious |
| AVG | MSIL:Quasar-A [Rat] |
| AhnLab-V3 | Backdoor/Win32.QuasarRAT.R341693 |
| Arcabit | Generic.MSIL.PasswordStealerA.703EC6F9 |
| Avast | MSIL:Quasar-A [Rat] |
| Avira | HEUR/AGEN.1365341 |
| BitDefender | Generic.MSIL.PasswordStealerA.703EC6F9 |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Generic.TRFH927 |
| CTX | exe.unknown.msil |
| ClamAV | Win.Malware.Generic-9883083-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.QuasarNET.3 |
| ESET-NOD32 | a variant of MSIL/Agent.CLQ |
| Elastic | Windows.Generic.Threat |
| Emsisoft | Generic.MSIL.PasswordStealerA.703EC6F9 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1365341 |
| FireEye | Generic.mg.d4a776ea55e24d31 |
| Fortinet | MSIL/Agent.BPH!tr |
| GData | MSIL.Backdoor.Quasar.A |
| Google | Detected |
| Ikarus | Trojan-Spy.Agent |
| Jiangmin | Trojan.MSIL.aogzw |
| K7AntiVirus | Trojan ( 005b1c021 ) |
| K7GW | Trojan ( 005b1c021 ) |
| Kaspersky | HEUR:Trojan.MSIL.Quasar.gen |
| Kingsoft | malware.kb.c.870 |
| Malwarebytes | Generic.Trojan.MSIL.DDS |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | GenericRXLX-DS!D4A776EA55E2 |
| McAfeeD | ti!7EF4D0236C81 |
| MicroWorld-eScan | Generic.MSIL.PasswordStealerA.703EC6F9 |
| Microsoft | Backdoor:MSIL/Quasar!atmn |
| Rising | Backdoor.Quasar!1.E5F1 (CLASSIC) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.wh |
| Sophos | Troj/Quasar-AF |
| Symantec | ML.Attribute.HighConfidence |
| TACHYON | Backdoor/W32.DN-Agent.3266048.C |
| Tencent | Backdoor.Msil.Quasar.16001301 |
| VBA32 | Trojan.MSIL.Quasar.Heur |
| VIPRE | Generic.MSIL.PasswordStealerA.703EC6F9 |
| Varist | W32/MSIL_Troj.BTX.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.B |
| ZoneAlarm | HEUR:Trojan.MSIL.Quasar.gen |
| alibabacloud | Backdoor:MSIL/Quasar.server |
| huorong | TrojanSpy/Agent.cq |
Process list
| Name | Command line |
| JJSPLOIT.V2.exe | |
| schtasks.exe | "schtasks" /create /tn "windows background updater" /sc ONLOGON /tr "%APPDATA%\windows updater\windows 3543.exe" /rl HIGHEST /f |
| windows 3543.exe | |
| schtasks.exe | "schtasks" /create /tn "windows background updater" /sc ONLOGON /tr "%APPDATA%\windows updater\windows 3543.exe" /rl HIGHEST /f |
| cmd.exe | /c ""%TEMP%\kxufVWewSNtH.bat" " |
| chcp.com | chcp 65001 |
| PING.EXE | ping -n 10 localhost |
| windows 3543.exe | |
| schtasks.exe | "schtasks" /create /tn "windows background updater" /sc ONLOGON /tr "%APPDATA%\windows updater\windows 3543.exe" /rl HIGHEST /f |
| JJSPLOIT.V2.exe | |