80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd

Classification: Malicious

80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 57 antivirus detections
  • 0 IDS alerts
  • 2 processes observed
  • 0 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-10-19 03:15:03 2026-09-02 16:45:06 malicious-activity
Generic Malware Cyber Threat Alliance 2024-12-28 10:17:15 2024-12-29 10:13:17

Tags

windows-server-utility evasive

Sample information

Filenames
80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd, routcrying.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows, ...
Size
756228 bytes
MD5
2b0402915579ce1debc2f6cc55695b78
SHA-1
95ef25a88cb77e153984d8cc84f5fcbd9dbf764d
SHA-256
80fec3abccd1b92402ee722616dff2605fd5132d9b208d5069c47389247de6dd
First indexed
2024-10-19 03:03:04
Last updated
2026-09-02 16:45:06

Antivirus detections

EngineDetection
AVGFileRepMalware [Trj]
Antiy-AVLTrojan[Downloader]/Win32.Powedon.gen
AvastFileRepMalware [Trj]
BitDefenderTrojan.GenericKD.74336069
BkavW32.AIDetectMalware
CTXexe.trojan.generic
CrowdStrikewin/malicious_confidence_70% (D)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32multiple detections
Elasticmalicious (high confidence)
FireEyeTrojan.GenericKD.74336069
GoogleDetected
KasperskyUDS:Trojan-Downloader.Win32.Powedon.gen
KingsoftWin32.Trojan-Downloader.Powedon.gen
LionicTrojan.Win32.Powedon.a!c
McAfeeArtemis!2B0402915579
McAfeeDti!80FEC3ABCCD1
MicroWorld-eScanTrojan.GenericKD.74336069
MicrosoftTrojan:Win32/Wacatac.B!ml
Paloaltogeneric.ml
PandaTrj/Chgt.AD
SangforTrojan.Win32.Agent.Vjmc
SkyhighBehavesLike.Win32.GuLoader.bc
SophosMal/Generic-S
SymantecTrojan.Gen.MBT
TrendMicroTrojanSpy.Win32.SNAKEKEYLOGGER.YXEJQZ
TrendMicro-HouseCallTrojanSpy.Win32.SNAKEKEYLOGGER.YXEJQZ
VaristW32/Chgt.JZAI-4761
ZoneAlarmUDS:Trojan-Downloader.Win32.Powedon.gen
ALYacTrojan.GenericKD.74336069
AVGNSIS:MalwareX-gen [Trj]
AhnLab-V3Downloader/Win.GuLoader.C5684533
Antiy-AVLTrojan[Downloader]/Win32.Powedon
ArcabitTrojan.Generic.D46E4745
AvastNSIS:MalwareX-gen [Trj]
AviraTR/Injector.aaadcp
CTXexe.trojan.powedon
DrWebPowerShell.Packed.143
EmsisoftTrojan.GenericKD.74336069 (B)
F-SecureTrojan.TR/Injector.aaadcp
FortinetW32/NDAoF
GDataTrojan.GenericKD.74336069
IkarusTrojan.NSIS.Agent
K7AntiVirusTrojan ( 0059035d1 )
K7GWTrojan ( 0059035d1 )
KasperskyHEUR:Trojan-Downloader.Win32.Powedon.gen
MalwarebytesNeshta.Virus.FileInfector.DDS
SangforDownloader.Win32.Powedon.V3z1
SophosTroj/Inject-JRW
TencentWin32.Trojan-Downloader.Powedon.Eajl
VIPRETrojan.GenericKD.74336069
WebrootW32.Trojan.Gen
YandexTrojan.Igent.b3bZwb.5
alibabacloudTrojan[downloader]:Win/Powedon.gyf
huorongTrojan/Generic!5B656940D9CB36EF

Process list

NameCommand line
routcrying.exe
powershell.exe-windowstyle hidden "$Outbabbled=Get-Content -raw '%TEMP%\superincomprehensible\Chymes.Ari';$Peract=$Outbabbled.SubString(52410,3);.$Peract($Outbabbled)"