80edcbb7fe7717412d44ce9de1c35f8ff32a904668780ceda77578068b6c2d1f
Classification: Malicious
80edcbb7fe7717412d44ce9de1c35f8ff32a904668780ceda77578068b6c2d1f is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 26 antivirus detections
- 1 IDS alerts
- 11 processes observed
- 2 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-06-04 14:00:02 |
2026-09-02 16:45:06 |
malicious-activity
|
|
| Remcos |
ThreatFox Abuse.ch |
2024-06-04 16:07:31 |
2024-06-06 15:33:02 |
|
|
| RemcosRAT |
MalwareBazaar Abuse.ch |
2024-06-04 13:47:58 |
2024-06-04 13:47:58 |
malicious-activity
|
|
Tags
evasive
windows-server-utility
win.remcos
remcosrat
remvio
socmer
Sample information
- Filenames
- 80edcbb7fe7717412d44ce9de1c35f8ff32a904668780ceda77578068b6c2d1f, New PO for Project - 00775 00875 02195.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 71168 bytes
- MD5
a86be739b88c4383313d081143ee51d9
- SHA-1
6f5b145c0a226a71cec35a289659d23b3287f1e0
- SHA-256
80edcbb7fe7717412d44ce9de1c35f8ff32a904668780ceda77578068b6c2d1f
- First indexed
- 2024-06-04 13:47:50
- Last updated
- 2026-09-02 16:45:07
Antivirus detections
| Engine | Detection |
| ALYac | IL:Trojan.MSILZilla.117818 |
| AVG | FileRepMalware [Rat] |
| Arcabit | IL:Trojan.MSILZilla.D1CC3A |
| Avast | FileRepMalware [Rat] |
| BitDefender | IL:Trojan.MSILZilla.117818 |
| Cybereason | malicious.9b88c4 |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| Emsisoft | IL:Trojan.MSILZilla.117818 (B) |
| FireEye | IL:Trojan.MSILZilla.117818 |
| GData | IL:Trojan.MSILZilla.117818 |
| Ikarus | Win32.Outbreak |
| Kaspersky | UDS:Backdoor.MSIL.Remcos.gen |
| MAX | malware (ai score=82) |
| Malwarebytes | Trojan.Crypt.MSIL |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | Real Protect-LS!A86BE739B88C |
| MicroWorld-eScan | IL:Trojan.MSILZilla.117818 |
| Microsoft | Trojan:Win32/Sonbokli.A!cl |
| Paloalto | generic.ml |
| Sangfor | Trojan.Win32.Agent.Vu3g |
| Skyhigh | Artemis |
| Sophos | Mal/Generic-S |
| VIPRE | IL:Trojan.MSILZilla.117818 |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| ZoneAlarm | UDS:Backdoor.MSIL.Remcos.gen |
Process list
| Name | Command line |
| NewPOforProject-007750087502195.exe | |
| cmd.exe | cmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "NewPOforProject-007750087502195" /t REG_SZ /F /D "%USERPROFILE%\Documents\NewPOforProject-007750087502195.pif" |
| reg.exe | REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "NewPOforProject-007750087502195" /t REG_SZ /F /D "%USERPROFILE%\Documents\NewPOforProject-007750087502195.pif" |
| cmd.exe | cmd /c Copy "C:\NewPOforProject-007750087502195.exe" "%USERPROFILE%\Documents\NewPOforProject-007750087502195.pif" |
| NewPOforProject-007750087502195.exe | |
| NewPOforProject-007750087502195.exe | |
| cmd.exe | cmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "NewPOforProject-007750087502195" /t REG_SZ /F /D "%USERPROFILE%\Documents\NewPOforProject-007750087502195.pif" |
| reg.exe | REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "NewPOforProject-007750087502195" /t REG_SZ /F /D "%USERPROFILE%\Documents\NewPOforProject-007750087502195.pif" |
| cmd.exe | cmd /c Copy "C:\NewPOforProject-007750087502195.exe" "%USERPROFILE%\Documents\NewPOforProject-007750087502195.pif" |
| NewPOforProject-007750087502195.exe | |
| NewPOforProject-007750087502195.exe | |