81ccbbfcfd5e8991632a16d6b4d28b36ef74409773b3e5622cf58cf43638ce07
Classification: Malicious
81ccbbfcfd5e8991632a16d6b4d28b36ef74409773b3e5622cf58cf43638ce07 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 32 antivirus detections
- 0 IDS alerts
- 4 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-10-29 21:45:04 |
2026-09-02 17:45:04 |
malicious-activity
|
|
Sample information
- Filenames
- 81ccbbfcfd5e8991632a16d6b4d28b36ef74409773b3e5622cf58cf43638ce07, file.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 2094592 bytes
- MD5
31c844530d857c4266248543c40284cc
- SHA-1
97f7aae6867695e025abdc5e1a7d446d7c5b875f
- SHA-256
81ccbbfcfd5e8991632a16d6b4d28b36ef74409773b3e5622cf58cf43638ce07
- First indexed
- 2024-10-29 21:34:14
- Last updated
- 2026-09-02 17:45:05
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | Win32:BackdoorX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.R674227 |
| Avast | Win32:BackdoorX-gen [Trj] |
| Avira | TR/Crypt.TPM.Gen |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of Win32/Packed.Themida.HVJ |
| Elastic | malicious (high confidence) |
| F-Secure | Trojan.TR/Crypt.TPM.Gen |
| FireEye | Generic.mg.31c844530d857c42 |
| Fortinet | W32/Themida.HZB!tr |
| GData | Win32.Trojan-Stealer.StealC.C |
| Gridinsoft | Trojan.Heur!.03A120A1 |
| Kaspersky | HEUR:Trojan.Win32.Miner.vho |
| Kingsoft | Win32.HeurC.KVMH008.a |
| Malwarebytes | Trojan.Amadey |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | Real Protect-LS!31C844530D85 |
| Microsoft | TrojanDownloader:Win32/Upatre!ml |
| Rising | [email protected] (RDML:yhRsal0Y3Url6YeS7c56vA) |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.tc |
| Sophos | Generic ML PUA (PUA) |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | malicious.high.ml.score |
| VBA32 | BScope.Trojan.Downloader |
| ZoneAlarm | HEUR:Trojan.Win32.Miner.vho |
| Zoner | Probably Heur.ExeHeaderL |
Process list
| Name | Command line |
| file.exe | |
| WerFault.exe | -u -p 2236 -s 580 |
| WerFault.exe | -u -p 2236 -s 580 |
| WerFault.exe | -pss -s 164 -p 2236 -ip 2236 |