80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd
Classification: Malicious
80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-10-19 03:15:03 |
2026-09-02 16:45:06 |
malicious-activity
|
|
| Generic Malware |
Cyber Threat Alliance |
2024-12-28 10:17:15 |
2024-12-29 10:13:17 |
|
|
Tags
windows-server-utility
evasive
Sample information
- Filenames
- 80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd, routcrying.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows, ...
- Size
- 756228 bytes
- MD5
2b0402915579ce1debc2f6cc55695b78
- SHA-1
95ef25a88cb77e153984d8cc84f5fcbd9dbf764d
- SHA-256
80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd
- First indexed
- 2024-10-19 03:03:04
- Last updated
- 2026-09-02 16:45:06
Antivirus detections
| Engine | Detection |
| AVG | FileRepMalware [Trj] |
| Antiy-AVL | Trojan[Downloader]/Win32.Powedon.gen |
| Avast | FileRepMalware [Trj] |
| BitDefender | Trojan.GenericKD.74336069 |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.generic |
| CrowdStrike | win/malicious_confidence_70% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | multiple detections |
| Elastic | malicious (high confidence) |
| FireEye | Trojan.GenericKD.74336069 |
| Google | Detected |
| Kaspersky | UDS:Trojan-Downloader.Win32.Powedon.gen |
| Kingsoft | Win32.Trojan-Downloader.Powedon.gen |
| Lionic | Trojan.Win32.Powedon.a!c |
| McAfee | Artemis!2B0402915579 |
| McAfeeD | ti!80FEC3ABCCD1 |
| MicroWorld-eScan | Trojan.GenericKD.74336069 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Sangfor | Trojan.Win32.Agent.Vjmc |
| Skyhigh | BehavesLike.Win32.GuLoader.bc |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Gen.MBT |
| TrendMicro | TrojanSpy.Win32.SNAKEKEYLOGGER.YXEJQZ |
| TrendMicro-HouseCall | TrojanSpy.Win32.SNAKEKEYLOGGER.YXEJQZ |
| Varist | W32/Chgt.JZAI-4761 |
| ZoneAlarm | UDS:Trojan-Downloader.Win32.Powedon.gen |
| ALYac | Trojan.GenericKD.74336069 |
| AVG | NSIS:MalwareX-gen [Trj] |
| AhnLab-V3 | Downloader/Win.GuLoader.C5684533 |
| Antiy-AVL | Trojan[Downloader]/Win32.Powedon |
| Arcabit | Trojan.Generic.D46E4745 |
| Avast | NSIS:MalwareX-gen [Trj] |
| Avira | TR/Injector.aaadcp |
| CTX | exe.trojan.powedon |
| DrWeb | PowerShell.Packed.143 |
| Emsisoft | Trojan.GenericKD.74336069 (B) |
| F-Secure | Trojan.TR/Injector.aaadcp |
| Fortinet | W32/NDAoF |
| GData | Trojan.GenericKD.74336069 |
| Ikarus | Trojan.NSIS.Agent |
| K7AntiVirus | Trojan ( 0059035d1 ) |
| K7GW | Trojan ( 0059035d1 ) |
| Kaspersky | HEUR:Trojan-Downloader.Win32.Powedon.gen |
| Malwarebytes | Neshta.Virus.FileInfector.DDS |
| Sangfor | Downloader.Win32.Powedon.V3z1 |
| Sophos | Troj/Inject-JRW |
| Tencent | Win32.Trojan-Downloader.Powedon.Eajl |
| VIPRE | Trojan.GenericKD.74336069 |
| Webroot | W32.Trojan.Gen |
| Yandex | Trojan.Igent.b3bZwb.5 |
| alibabacloud | Trojan[downloader]:Win/Powedon.gyf |
| huorong | Trojan/Generic!5B656940D9CB36EF |
Process list
| Name | Command line |
| routcrying.exe | |
| powershell.exe | -windowstyle hidden "$Outbabbled=Get-Content -raw '%TEMP%\superincomprehensible\Chymes.Ari';$Peract=$Outbabbled.SubString(52410,3);.$Peract($Outbabbled)" |