813c0c02e8f498fdd3583567ceff03842b89a3cddafd100f46c84f926e768322
Classification: Malicious
813c0c02e8f498fdd3583567ceff03842b89a3cddafd100f46c84f926e768322 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 18 antivirus detections (25% detection ratio)
- 1 IDS alerts
- 8 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-11-25 15:23:00 |
2026-09-02 16:45:03 |
malicious-activity
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2023-11-25 15:15:11 |
2023-11-25 15:15:11 |
malicious-activity
|
|
Sample information
- Filenames
- 813c0c02e8f498fdd3583567ceff03842b89a3cddafd100f46c84f926e768322, 0e33184bab78740f0a5b9cec1ca0704a.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows, ...
- Size
- 392576 bytes
- MD5
0e33184bab78740f0a5b9cec1ca0704a
- SHA-1
307e62eeb35a879ac5f76a1eb257580512e8c8ee
- SHA-256
813c0c02e8f498fdd3583567ceff03842b89a3cddafd100f46c84f926e768322
- First indexed
- 2023-11-25 15:15:45
- Last updated
- 2026-09-02 16:45:03
Antivirus detections
| Engine | Detection |
| FireEye | Generic.mg.0e33184bab78740f |
| Skyhigh | RDN/Generic BackDoor |
| Zillya | Backdoor.Lotok.Win32.3625 |
| Sangfor | Trojan.Win32.Silverfox.ulgyzg |
| Alibaba | Backdoor:Win32/Lotok.c6c03418 |
| CrowdStrike | win/grayware_confidence_70% (W) |
| Elastic | malicious (moderate confidence) |
| APEX | Malicious |
| Kaspersky | Backdoor.Win32.Lotok.slg |
| NANO-Antivirus | Virus.Win32.Gen-Crypt.ccnc |
| Tencent | Trojan.Win32.FakeInst_l.16001054 |
| Antiy-AVL | Trojan[Backdoor]/Win32.Lotok.slk |
| Microsoft | Trojan:Win32/Sabsik.TE.B!ml |
| ZoneAlarm | Backdoor.Win32.Lotok.slg |
| AhnLab-V3 | Backdoor/Win.Agent.C5547319 |
| McAfee | RDN/Generic BackDoor |
| Rising | Trojan.Kryptik!1.EF0E (CLASSIC) |
| MaxSecure | Trojan.Malware.220621148.susgen |
Process list
| Name | Command line |
| 0e33184bab78740f0a5b9cec1ca0704a.exe | |
| WerFault.exe | -u -p 7612 -s 552 |
| WerFault.exe | -u -p 7612 -s 552 |
| WerFault.exe | -pss -s 440 -p 7612 -ip 7612 |
| 0e33184bab78740f0a5b9cec1ca0704a.exe | |
| fvNyA2FJu.exe | |
| WerFault.exe | -u -p 2904 -s 736 |
| WerFault.exe | -u -p 2904 -s 736 |