80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7

Classification: Malicious

80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 82 antivirus detections (68% detection ratio)
  • 1 IDS alerts
  • 15 processes observed
  • 1 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-10-09 11:30:04 2026-09-02 16:45:06 malicious-activity
Generic.Malware MalwareBazaar Abuse.ch 2023-10-09 06:46:52 2023-10-09 06:46:52 malicious-activity

Tags

evasive

Sample information

Filenames
80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7, 80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.exe, 1712.exe, 0e0b669d90c80cea6398e81d139d7d29
File type
application/x-dosexec
Size
225280 bytes
MD5
0e0b669d90c80cea6398e81d139d7d29
SHA-1
fc8014c4c916af6556e677402dfe8ebfd55cd9ef
SHA-256
80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7
First indexed
2023-10-09 07:18:12
Last updated
2026-09-02 16:45:06

Antivirus detections

EngineDetection
ALYacIL:Trojan.MSILMamut.12916
APEXMalicious
AVGWin32:MalwareX-gen [Inj]
AhnLab-V3Trojan/Win.Generic.C5501036
AlibabaBackdoor:MSIL/AsyncRat.03db3d89
ArcabitIL:Trojan.MSILMamut.D3274
AvastWin32:MalwareX-gen [Inj]
AviraTR/Injector.xlrfu
BitDefenderIL:Trojan.MSILMamut.12916
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.Ghanarava.17340696399d7d29
CTXexe.trojan.msilmamut
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
ESET-NOD32a variant of MSIL/Injector.WIQ
Elasticmalicious (high confidence)
EmsisoftIL:Trojan.MSILMamut.12916 (B)
F-SecureTrojan.TR/Injector.xlrfu
FortinetPossibleThreat.MU
GDataIL:Trojan.MSILMamut.12916
GoogleDetected
IkarusTrojan.MSIL.Injector
JiangminBackdoor.MSIL.ggrw
K7AntiVirusTrojan ( 005ac3ad1 )
K7GWTrojan ( 005ac3ad1 )
KasperskyHEUR:Backdoor.MSIL.Androm.gen
KingsoftMSIL.Backdoor.Androm.gen
LionicTrojan.Win32.MSILMamut.m!c
MalwarebytesTrojan.Crypt.MSIL
McAfeeArtemis!0E0B669D90C8
McAfeeDti!80F3AA803D69
MicroWorld-eScanIL:Trojan.MSILMamut.12916
MicrosoftTrojan:MSIL/AsyncRat.CCCL!MTB
NANO-AntivirusTrojan.Win32.Androm.kmlszt
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingMalware.Obfus/[email protected] (RDM.MSIL2:ty5/O6I7m15cgPGyhY1CLw)
SangforBackdoor.Msil.Injector.V944
SkyhighBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
SymantecTrojan Horse
TencentMalware.Win32.Gencirc.13f17714
TrendMicroTROJ_GEN.R002C0DBD25
TrendMicro-HouseCallTROJ_GEN.R002C0DBD25
VBA32TScope.Trojan.MSIL
VIPREIL:Trojan.MSILMamut.12916
VaristW32/MSIL_Agent.ISE.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A
YandexTrojan.Injector!YOyJwTSLoJI
ZillyaBackdoor.Androm.Win32.111694
alibabacloudBackdoor:MSIL/AsyncRat.CWIM3DGW
LionicTrojan.Win32.Androm.4!c
MicroWorld-eScanGen:Variant.Marsilia.77633
FireEyeGeneric.mg.0e0b669d90c80cea
VIPREGen:Variant.Marsilia.77633
SangforBackdoor.Msil.Injector.Vfqp
BitDefenderGen:Variant.Marsilia.77633
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.WHJ
CynetMalicious (score: 100)
AlibabaBackdoor:MSIL/Androm.febcb641
ViRobotTrojan.Win.Z.Marsilia.225280.A
RisingTrojan.Injector!8.C4 (CLOUD)
TrendMicroBackdoor.Win32.ASYNCRAT.YXDJGZ
EmsisoftGen:Variant.Marsilia.77633 (B)
IkarusTrojan-Spy.Agent
GDataGen:Variant.Marsilia.77633
VaristW32/ABRisk.JHKN-3727
MAXmalware (ai score=89)
Antiy-AVLTrojan/MSIL.Injector
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Marsilia.D12F41
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZemsilCO.36738.nm0@amx@Vtp
ALYacGen:Variant.Marsilia.77633
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallBackdoor.Win32.ASYNCRAT.YXDJGZ
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.4c916a
AvastWin32:TrojanX-gen [Trj]

Network contacts

194.169.175.43

DNS requests

amm.mine.nu

Process list

NameCommand line
80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.exe
cmd.execmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7" /t REG_SZ /F /D "%USERPROFILE%\Documents\80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.pif"
reg.exeREG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7" /t REG_SZ /F /D "%USERPROFILE%\Documents\80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.pif"
cmd.execmd /c Copy "C:\80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.exe" "%USERPROFILE%\Documents\80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.pif"
80f3aa803d69a8a11cd9d625340f9cf1e759c2c23cfab97752c8ac76e74fdfb7.exe
1712.exe
cmd.execmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "1712" /t REG_SZ /F /D "%USERPROFILE%\Documents\1712.pif"
reg.exeREG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "1712" /t REG_SZ /F /D "%USERPROFILE%\Documents\1712.pif"
cmd.execmd /c Copy "C:\1712.exe" "%USERPROFILE%\Documents\1712.pif"
1712.exe
1712.pif
cmd.execmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "1712.pif" /t REG_SZ /F /D "%USERPROFILE%\Documents\1712.pif.pif"
reg.exeREG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "1712.pif" /t REG_SZ /F /D "%USERPROFILE%\Documents\1712.pif.pif"
cmd.execmd /c Copy "%USERPROFILE%\Documents\1712.pif" "%USERPROFILE%\Documents\1712.pif.pif"
1712.pif