809a49e7d55ccdfb06509fd21a907f12be24c7d43ae6941d35c1a54ba58e549e
Classification: Malicious
809a49e7d55ccdfb06509fd21a907f12be24c7d43ae6941d35c1a54ba58e549e is a malicious file sample. Linked to Darkgate malware. Detected by 48 antivirus engines.
Detection summary
- 48 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: DARKGATE (S1111)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 15:45:04 | 2026-09-02 15:45:04 | malicious-activity | |
| DarkGate | ThreatFox Abuse.ch | 2025-04-13 05:53:30 | 2025-04-15 05:37:07 | S1111 DarkGate |
Tags
win.darkgate meh mehcrypter windows-server-utilitySample information
- Filenames
- 809a49e7d55ccdfb06509fd21a907f12be24c7d43ae6941d35c1a54ba58e549e
- File type
- PE32+ executable for MS Windows 6.00 (GUI), x86-64 ...
- MD5
2a38b751e44881286761a7eb61539726- SHA-1
8903948573b7520dcb5ee06c382cbf024e21c8a0- SHA-256
809a49e7d55ccdfb06509fd21a907f12be24c7d43ae6941d35c1a54ba58e549e- First indexed
- 2025-04-13 07:28:42
- Last updated
- 2026-09-02 15:45:04
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | QD:Trojan.GenericKDQ.404E2240A5 |
| AVG | Win32:MiscX-gen [PUP] |
| Alibaba | Trojan:Win32/ChromeCookiesView.fec6686f |
| Antiy-AVL | Trojan/Win32.Saguaro |
| Arcabit | QD:Trojan.GenericQ.404E2240A5 |
| Avast | Win32:MiscX-gen [PUP] |
| Avira | TR/Lethic.toijn |
| BitDefender | QD:Trojan.GenericKDQ.404E2240A5 |
| Bkav | W32.Common.0B15DE28 |
| CAT-QuickHeal | Trojan.Ghanarava.1741254951539726 |
| CTX | exe.trojan.chromecookiesview |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Win32.HLLW.Autoruner1.14959 |
| ESET-NOD32 | a variant of Win32/ChromeCookiesView.A potentially unsafe |
| Elastic | malicious (moderate confidence) |
| Emsisoft | QD:Trojan.GenericKDQ.404E2240A5 (B) |
| F-Secure | Trojan.TR/Lethic.toijn |
| FireEye | QD:Trojan.GenericKDQ.404E2240A5 |
| Fortinet | Riskware/ChromeCookiesView |
| GData | QD:Trojan.GenericKDQ.404E2240A5 |
| Detected | |
| K7AntiVirus | Unwanted-Program ( 005a56e31 ) |
| K7GW | Unwanted-Program ( 005a56e31 ) |
| Kaspersky | Trojan.Win32.Saguaro.n |
| Kingsoft | Win32.PSWTool.PassView.a |
| Lionic | Trojan.Win32.GenericKDQ.4!c |
| Malwarebytes | RiskWare.GameHack |
| MaxSecure | Trojan.Malware.309146866.susgen |
| McAfee | Artemis!2A38B751E448 |
| MicroWorld-eScan | QD:Trojan.GenericKDQ.404E2240A5 |
| Microsoft | Trojan:Win32/Malgent!MSR |
| Paloalto | generic.ml |
| Panda | Trj/Agent.DG |
| Rising | PUA.ChromeCookiesView!8.17819 (CLOUD) |
| Skyhigh | Artemis |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.142327c6 |
| TrendMicro | TROJ_GEN.R002C0DL324 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DL324 |
| VBA32 | Trojan.Darkgate |
| VIPRE | QD:Trojan.GenericKDQ.404E2240A5 |
| Varist | W64/ABTrojan.JSKR-1013 |
| VirIT | Trojan.Win64.Agent.GAC |
| Xcitium | ApplicUnwnt@#1xdftvzsa2ecz |
| Zillya | Trojan.Saguaro.Win32.25 |
| alibabacloud | Backdoor:Win/Rozena |