81e2bb8d5505d4aba6e44d4404a909a6217f9b513645b77224007dccc64669d2

Classification: Malicious

81e2bb8d5505d4aba6e44d4404a909a6217f9b513645b77224007dccc64669d2 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 16 antivirus detections (22% detection ratio)
  • 1 IDS alerts
  • 3 processes observed
  • 1 contacted hosts
  • 3 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-10 12:15:03 2026-09-02 17:45:04 malicious-activity
Generic.Malware MalwareBazaar Abuse.ch 2023-11-10 11:51:32 2023-11-10 11:51:32 malicious-activity

Sample information

Filenames
81e2bb8d5505d4aba6e44d4404a909a6217f9b513645b77224007dccc64669d2, 3af3a579b3f70dccf3263306acfd439c
File type
PE32 executable (DLL) (console) Intel 80386 Mono/. ...
Size
923136 bytes
MD5
3af3a579b3f70dccf3263306acfd439c
SHA-1
b46b230e13a52521af4b9b493db6fbe545dc9efc
SHA-256
81e2bb8d5505d4aba6e44d4404a909a6217f9b513645b77224007dccc64669d2
First indexed
2023-11-10 11:51:45
Last updated
2026-09-02 17:45:04

Antivirus detections

EngineDetection
MicroWorld-eScanGen:Variant.MSILHeracles.112435
ALYacGen:Variant.MSILHeracles.112435
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.MSILHeracles.112435
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.DRD
VIPREGen:Variant.MSILHeracles.112435
FireEyeGeneric.mg.3af3a579b3f70dcc
EmsisoftGen:Variant.MSILHeracles.112435 (B)
IkarusTrojan.MSIL.Agent
GoogleDetected
ArcabitTrojan.MSILHeracles.D1B733
GDataGen:Variant.MSILHeracles.112435
CynetMalicious (score: 100)
MAXmalware (ai score=80)
SentinelOneStatic AI - Malicious PE

Network contacts

82.223.5.210

DNS requests

pegapombo.serveftp.com zulu567.onthewifi.com india987.serveblog.net

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\3af3a579b3f70dccf3263306acfd439c.dll",SignalInitializeCrashReporting
rundll32.exe"C:\3af3a579b3f70dccf3263306acfd439c.dll",#1