7fd6a6403f2ad4e6f878924e00ac7d72f5855969276284ee7a9459f6f8c9b26a
Classification: Malicious
7fd6a6403f2ad4e6f878924e00ac7d72f5855969276284ee7a9459f6f8c9b26a is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 38 antivirus detections (54% detection ratio)
- 2 IDS alerts
- 5 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-11-01 04:21:51 |
2026-09-02 14:45:04 |
malicious-activity
|
|
| Loki |
MalwareBazaar Abuse.ch |
2023-11-01 04:00:10 |
2023-11-01 04:00:10 |
malicious-activity
|
|
Tags
banker
lokibot
infostealer
stealer
Sample information
- Filenames
- 7fd6a6403f2ad4e6f878924e00ac7d72f5855969276284ee7a9459f6f8c9b26a, gunzipped.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 862720 bytes
- MD5
d4bc1a116cb96991aa3181d45a4cd46f
- SHA-1
4839e63edc029d5d28f42607b2c0f5eb360fd350
- SHA-256
7fd6a6403f2ad4e6f878924e00ac7d72f5855969276284ee7a9459f6f8c9b26a
- First indexed
- 2023-11-01 04:03:26
- Last updated
- 2026-09-02 14:45:04
Antivirus detections
| Engine | Detection |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Variant.MSILHeracles.109663 |
| Skyhigh | BehavesLike.Win32.Generic.cc |
| ALYac | Gen:Variant.MSILHeracles.109663 |
| BitDefender | Gen:Variant.MSILHeracles.109663 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| BitDefenderTheta | Gen:NN.ZemsilF.36792.0m0@ayLpc3g |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Symantec | Scr.Malcode!gdn34 |
| tehtris | Generic.Malware |
| APEX | Malicious |
| Cynet | Malicious (score: 100) |
| Kaspersky | UDS:Backdoor.MSIL.Androm.gen |
| Sophos | ML/PE-A |
| F-Secure | Heuristic.HEUR/AGEN.1309843 |
| VIPRE | Gen:Variant.MSILHeracles.109663 |
| Trapmine | malicious.moderate.ml.score |
| FireEye | Generic.mg.d4bc1a116cb96991 |
| Emsisoft | Gen:Variant.MSILHeracles.109663 (B) |
| Ikarus | Trojan.MSIL.Crypt |
| Varist | W32/MSIL_Agent.FPI.gen!Eldorado |
| Avira | HEUR/AGEN.1309843 |
| Kingsoft | malware.kb.c.998 |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| Arcabit | Trojan.MSILHeracles.D1AC5F |
| ZoneAlarm | UDS:Backdoor.MSIL.Androm.gen |
| GData | Gen:Variant.MSILHeracles.109663 |
| Google | Detected |
| MAX | malware (ai score=88) |
| DeepInstinct | MALICIOUS |
| VBA32 | CIL.HeapOverride.Heur |
| Cylance | unsafe |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:AlnwXngekdv73V1v83xo8w) |
| SentinelOne | Static AI - Malicious PE |
| Fortinet | MSIL/Kryptik.AJMV!tr |
| AVG | PWSX-gen [Trj] |
| Cybereason | malicious.edc029 |
| Avast | PWSX-gen [Trj] |
Process list
| Name | Command line |
| gunzipped.exe | |
| gunzipped.exe | |
| gunzipped.exe | |
| gunzipped.exe | |
| gunzipped.exe | |