8239559d5c986284031b5918e229e63e61ea790e35cd1e972241bd3ff36b5087
Classification: Malicious
8239559d5c986284031b5918e229e63e61ea790e35cd1e972241bd3ff36b5087 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 13 antivirus detections
- 0 IDS alerts
- 12 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-09-09 12:00:03 |
2026-09-02 18:45:07 |
malicious-activity
|
|
Sample information
- Filenames
- 8239559d5c986284031b5918e229e63e61ea790e35cd1e972241bd3ff36b5087, z72Nowezam_wienie.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 17408 bytes
- MD5
e1a906c8e061756213b4745e769a86db
- SHA-1
a5a3af63dc82bbfc302f9b3471e6115e2d456056
- SHA-256
8239559d5c986284031b5918e229e63e61ea790e35cd1e972241bd3ff36b5087
- First indexed
- 2024-09-09 11:48:15
- Last updated
- 2026-09-02 18:45:08
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectMalware.CS |
| CrowdStrike | win/malicious_confidence_60% (D) |
| DeepInstinct | MALICIOUS |
| Fortinet | MSIL/GenKryptik.GMRM!tr |
| Google | Detected |
| Ikarus | Trojan-Downloader.MSIL.Agent |
| Malwarebytes | Trojan.Crypt.MSIL |
| Microsoft | Trojan:Win32/Sonbokli.A!cl |
| Paloalto | generic.ml |
| Sangfor | Trojan.Win32.Save.MSIL_Inject |
| SentinelOne | Static AI - Malicious PE |
| Symantec | ML.Attribute.HighConfidence |
| VirIT | Trojan.Win32.MSIL_Heur.A |
Process list
| Name | Command line |
| z72Nowezam_wienie.exe | |
| cmd.exe | cmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "z72Nowezam_wienie" /t REG_SZ /F /D "%USERPROFILE%\Documents\z72Nowezam_wienie.pif" |
| reg.exe | REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "z72Nowezam_wienie" /t REG_SZ /F /D "%USERPROFILE%\Documents\z72Nowezam_wienie.pif" |
| cmd.exe | cmd /c Copy "C:\z72Nowezam_wienie.exe" "%USERPROFILE%\Documents\z72Nowezam_wienie.pif" |
| RegAsm.exe | |
| RegAsm.exe | |
| RegAsm.exe | |
| z72Nowezam_wienie.pif | |
| cmd.exe | cmd /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "z72Nowezam_wienie.pif" /t REG_SZ /F /D "%USERPROFILE%\Documents\z72Nowezam_wienie.pif.pif" |
| reg.exe | REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "z72Nowezam_wienie.pif" /t REG_SZ /F /D "%USERPROFILE%\Documents\z72Nowezam_wienie.pif.pif" |
| cmd.exe | cmd /c Copy "%USERPROFILE%\Documents\z72Nowezam_wienie.pif" "%USERPROFILE%\Documents\z72Nowezam_wienie.pif.pif" |
| RegAsm.exe | |