82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28
Classification: Malicious
82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28 is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 31 antivirus detections
- 1 IDS alerts
- 6 processes observed
- 2 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-07-04 06:30:03 |
2026-09-02 19:45:06 |
malicious-activity
|
|
| Remcos |
ThreatFox Abuse.ch |
2024-07-04 15:32:10 |
2024-07-04 15:38:48 |
|
|
| RemcosRAT |
MalwareBazaar Abuse.ch |
2024-07-04 06:21:10 |
2024-07-04 06:21:10 |
malicious-activity
|
|
Tags
evasive
win.remcos
remcosrat
remvio
socmer
Sample information
- Filenames
- 82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28, DHL AWB 6533732999.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 1325056 bytes
- MD5
e5114c7a45a7b3c658c4ae212ac089e5
- SHA-1
072dd71ea12a57bdef11b663bce746878f4585ec
- SHA-256
82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28
- First indexed
- 2024-07-04 06:21:19
- Last updated
- 2026-09-02 19:45:07
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | Win32:Malware-gen |
| Alibaba | Trojan:Win32/Strab.456d006f |
| Avast | Win32:Malware-gen |
| Avira | TR/AD.ShellcodeCrypter.gyfun |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_60% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DrWeb | Trojan.AutoIt.1410 |
| Elastic | malicious (high confidence) |
| F-Secure | Trojan.TR/AD.ShellcodeCrypter.gyfun |
| FireEye | Generic.mg.e5114c7a45a7b3c6 |
| Fortinet | AutoIt/Injector.AAD!tr |
| Google | Detected |
| Ikarus | Trojan.Autoit |
| Kaspersky | Backdoor.Win32.Remcos.yen |
| Kingsoft | malware.kb.a.863 |
| Malwarebytes | Trojan.Injector.AutoIt |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | ti!82EDDB35F29F |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| Paloalto | generic.ml |
| Rising | Trojan.Injector/Autoit!1.FD30 (CLASSIC) |
| Sangfor | Trojan.Win32.Save.a |
| Skyhigh | BehavesLike.Win32.TrojanAitInject.tc |
| Sophos | Troj/AutoIt-DGJ |
| VBA32 | Trojan-Downloader.Autoit.gen |
| Varist | W32/AutoIt.IJ.gen!Eldorado |
| VirIT | Trojan.Win32.Dnldr27.DIMR |
| ZoneAlarm | Backdoor.Win32.Remcos.yen |
Process list
| Name | Command line |
| DHLAWB6533732999.exe | |
| nonsubmerged.exe | "C:\DHLAWB6533732999.exe" |
| svchost.exe | "C:\DHLAWB6533732999.exe" |
| WScript.exe | "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\nonsubmerged.vbs" |
| nonsubmerged.exe | |
| svchost.exe | "%LOCALAPPDATA%\Myriopoda\nonsubmerged.exe" |