7faffbbc90670d57ec7a85b620eb13a4e1117fde0c0a4c12a131105de15a0b40

Classification: Malicious

7faffbbc90670d57ec7a85b620eb13a4e1117fde0c0a4c12a131105de15a0b40 is a malicious file sample. Linked to Xloader malware. Detected by 29 antivirus engines.

Detection summary

  • 29 antivirus detections
  • 0 IDS alerts
  • 2 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: XLOADER (S1207)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-08-15 13:15:04 2026-09-02 14:45:06 malicious-activity
Formbook ThreatFox Abuse.ch 2024-08-15 18:19:50 2024-08-17 18:22:56 S1207 XLoader
Formbook MalwareBazaar Abuse.ch 2024-08-15 13:04:29 2024-08-15 13:04:29 malicious-activity S1207 XLoader

Tags

windows-server-utility win.formbook win.xloader evasive

Sample information

Filenames
7faffbbc90670d57ec7a85b620eb13a4e1117fde0c0a4c12a131105de15a0b40, PO.TURF.BRB.1408.2024.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1399296 bytes
MD5
1c38ab057cd891eae6d4531931cd0221
SHA-1
07e878db922a7a1926baee31f15e80972b4e9b4a
SHA-256
7faffbbc90670d57ec7a85b620eb13a4e1117fde0c0a4c12a131105de15a0b40
First indexed
2024-08-15 13:04:10
Last updated
2026-09-02 14:45:06

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
ClamAVWin.Malware.Silentall-10034109-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32a variant of Win32/Injector.Autoit.GGB
Elasticmalicious (high confidence)
FireEyeGeneric.mg.1c38ab057cd891ea
FortinetAutoIt/Agent.APQ!tr
GoogleDetected
IkarusWin32.Outbreak
KasperskyUDS:DangerousObject.Multi.Generic
KingsoftWin32.Troj.Unknown.a
LionicTrojan.Win64.Injects.ts93
MalwarebytesTrojan.Injector.AutoIt
MaxSecureTrojan.Malware.300983.susgen
McAfeeArtemis!1C38AB057CD8
McAfeeDReal Protect-LS!1C38AB057CD8
MicrosoftTrojan:Win32/Leonem
Paloaltogeneric.ml
SangforTrojan.Win32.Save.a
SkyhighBehavesLike.Win32.TrojanAitInject.tc
SophosGeneric ML PUA (PUA)
TrendMicro-HouseCallTROJ_GEN.F0D1C00HE24
VBA32Trojan-Downloader.Autoit.gen
VaristW32/Autoit.APO.gen!Eldorado
VirITTrojan.Win32.AutoIt_Heur.A
ZoneAlarmUDS:DangerousObject.Multi.Generic

Process list

NameCommand line
PO.TURF.BRB.1408.2024.exe
svchost.exe"C:\PO.TURF.BRB.1408.2024.exe"