7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c

Classification: Malicious

7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 51 antivirus detections
  • 0 IDS alerts
  • 10 processes observed
  • 0 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-01-05 05:00:04 2026-09-02 13:45:06 malicious-activity
Generic.Malware MalwareBazaar Abuse.ch 2024-10-19 22:28:19 2024-10-19 22:28:19 malicious-activity

Tags

evasive infostealer njrat

Sample information

Filenames
7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c, JJSPLOIT.V2.exe
File type
application/x-dosexec
Size
3266048 bytes
MD5
d4a776ea55e24d3124a6e0759fb0ac44
SHA-1
f5932d234baccc992ca910ff12044e8965229852
SHA-256
7ef4d0236c81894178a6cfc6c27920217bea42a3602ad7a6002834718ba7b93c
First indexed
2024-10-19 23:21:16
Last updated
2026-09-02 13:45:06

Antivirus detections

EngineDetection
ALYacGeneric.MSIL.PasswordStealerA.703EC6F9
APEXMalicious
AVGMSIL:Quasar-A [Rat]
AhnLab-V3Backdoor/Win32.QuasarRAT.R341693
ArcabitGeneric.MSIL.PasswordStealerA.703EC6F9
AvastMSIL:Quasar-A [Rat]
AviraHEUR/AGEN.1365341
BitDefenderGeneric.MSIL.PasswordStealerA.703EC6F9
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.Generic.TRFH927
CTXexe.unknown.msil
ClamAVWin.Malware.Generic-9883083-0
CrowdStrikewin/malicious_confidence_100% (D)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebBackDoor.QuasarNET.3
ESET-NOD32a variant of MSIL/Agent.CLQ
ElasticWindows.Generic.Threat
EmsisoftGeneric.MSIL.PasswordStealerA.703EC6F9 (B)
F-SecureHeuristic.HEUR/AGEN.1365341
FireEyeGeneric.mg.d4a776ea55e24d31
FortinetMSIL/Agent.BPH!tr
GDataMSIL.Backdoor.Quasar.A
GoogleDetected
IkarusTrojan-Spy.Agent
JiangminTrojan.MSIL.aogzw
K7AntiVirusTrojan ( 005b1c021 )
K7GWTrojan ( 005b1c021 )
KasperskyHEUR:Trojan.MSIL.Quasar.gen
Kingsoftmalware.kb.c.870
MalwarebytesGeneric.Trojan.MSIL.DDS
MaxSecureTrojan.Malware.300983.susgen
McAfeeGenericRXLX-DS!D4A776EA55E2
McAfeeDti!7EF4D0236C81
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.703EC6F9
MicrosoftBackdoor:MSIL/Quasar!atmn
RisingBackdoor.Quasar!1.E5F1 (CLASSIC)
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.wh
SophosTroj/Quasar-AF
SymantecML.Attribute.HighConfidence
TACHYONBackdoor/W32.DN-Agent.3266048.C
TencentBackdoor.Msil.Quasar.16001301
VBA32Trojan.MSIL.Quasar.Heur
VIPREGeneric.MSIL.PasswordStealerA.703EC6F9
VaristW32/MSIL_Troj.BTX.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.B
ZoneAlarmHEUR:Trojan.MSIL.Quasar.gen
alibabacloudBackdoor:MSIL/Quasar.server
huorongTrojanSpy/Agent.cq

DNS requests

LETSQOOO-62766.portmap.host

Process list

NameCommand line
JJSPLOIT.V2.exe
schtasks.exe"schtasks" /create /tn "windows background updater" /sc ONLOGON /tr "%APPDATA%\windows updater\windows 3543.exe" /rl HIGHEST /f
windows 3543.exe
schtasks.exe"schtasks" /create /tn "windows background updater" /sc ONLOGON /tr "%APPDATA%\windows updater\windows 3543.exe" /rl HIGHEST /f
cmd.exe/c ""%TEMP%\kxufVWewSNtH.bat" "
chcp.comchcp 65001
PING.EXEping -n 10 localhost
windows 3543.exe
schtasks.exe"schtasks" /create /tn "windows background updater" /sc ONLOGON /tr "%APPDATA%\windows updater\windows 3543.exe" /rl HIGHEST /f
JJSPLOIT.V2.exe