825196f7ae2364e7712c9893e97c50fa639a3ecb747e7b431d6fa47110724eca

Classification: Malicious

825196f7ae2364e7712c9893e97c50fa639a3ecb747e7b431d6fa47110724eca is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.

Detection summary

  • 33 antivirus detections
  • 0 IDS alerts
  • 2 processes observed
  • 1 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-06-29 11:30:03 2026-09-02 18:45:06 malicious-activity
zgRAT ThreatFox Abuse.ch 2024-06-29 20:15:54 2024-06-30 15:47:50
Generic.Malware MalwareBazaar Abuse.ch 2024-06-29 11:17:56 2024-06-29 11:17:56 malicious-activity

Tags

evasive windows-server-utility win.zgrat

Sample information

Filenames
825196f7ae2364e7712c9893e97c50fa639a3ecb747e7b431d6fa47110724eca, fc993cf9a2b69cc48dbb9d8e3da898e6e49b531c441eb1ce7ca0b3c1f4151a14_payload.exe
File type
PE32 executable (console) Intel 80386 Mono/.Net as ...
Size
635392 bytes
MD5
6eab90173adf5c07e17b59fd377f4158
SHA-1
7c06d2891922870d820f51a706771877f8c801ae
SHA-256
825196f7ae2364e7712c9893e97c50fa639a3ecb747e7b431d6fa47110724eca
First indexed
2024-06-29 11:19:16
Last updated
2026-09-02 18:45:07

Antivirus detections

EngineDetection
ALYacGen:Variant.Jalapeno.13232
APEXMalicious
AVGWin32:PWSX-gen [Trj]
AhnLab-V3Trojan/Win.Generic.C5606332
ArcabitTrojan.Jalapeno.D33B0
AvastWin32:PWSX-gen [Trj]
BitDefenderGen:Variant.Jalapeno.13232
BitDefenderThetaGen:NN.ZemsilCO.36808.Mm0@aCb5NPj
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.73adf5
CylanceUnsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/Spy.RedLine.A
ElasticWindows.Trojan.RedLineStealer
EmsisoftGen:Variant.Jalapeno.13232 (B)
FireEyeGeneric.mg.6eab90173adf5c07
GDataGen:Variant.Jalapeno.13232
GoogleDetected
IkarusTrojan-Spy.FormBook
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
MAXmalware (ai score=84)
MalwarebytesSpyware.PasswordStealer.MSIL.Generic
MicroWorld-eScanGen:Variant.Jalapeno.13232
MicrosoftProgram:Win32/Wacapew.C!ml
SangforTrojan.Win32.Save.a
SymantecML.Attribute.HighConfidence
VBA32Malware-Cryptor.MSIL.AgentTesla.Heur
VIPREGen:Variant.Jalapeno.13232
VaristW32/MSIL_Troj.DEJ.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.gen
tehtrisGeneric.Malware

Network contacts

92.246.138.36

Process list

NameCommand line
fc993cf9a2b69cc48dbb9d8e3da898e6e49b531c441eb1ce7ca0b3c1f4151a14_payload.exe
fc993cf9a2b69cc48dbb9d8e3da898e6e49b531c441eb1ce7ca0b3c1f4151a14_payload.exe