82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28

Classification: Malicious

82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28 is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.

Detection summary

  • 31 antivirus detections
  • 1 IDS alerts
  • 6 processes observed
  • 2 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-07-04 06:30:03 2026-09-02 19:45:06 malicious-activity
Remcos ThreatFox Abuse.ch 2024-07-04 15:32:10 2024-07-04 15:38:48
RemcosRAT MalwareBazaar Abuse.ch 2024-07-04 06:21:10 2024-07-04 06:21:10 malicious-activity

Tags

evasive win.remcos remcosrat remvio socmer

Sample information

Filenames
82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28, DHL AWB 6533732999.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1325056 bytes
MD5
e5114c7a45a7b3c658c4ae212ac089e5
SHA-1
072dd71ea12a57bdef11b663bce746878f4585ec
SHA-256
82eddb35f29fcef506f76342077d1bcbe38689680a9efd6d7a58b08479d13f28
First indexed
2024-07-04 06:21:19
Last updated
2026-09-02 19:45:07

Antivirus detections

EngineDetection
APEXMalicious
AVGWin32:Malware-gen
AlibabaTrojan:Win32/Strab.456d006f
AvastWin32:Malware-gen
AviraTR/AD.ShellcodeCrypter.gyfun
BkavW32.AIDetectMalware
CrowdStrikewin/malicious_confidence_60% (D)
CylanceUnsafe
CynetMalicious (score: 99)
DrWebTrojan.AutoIt.1410
Elasticmalicious (high confidence)
F-SecureTrojan.TR/AD.ShellcodeCrypter.gyfun
FireEyeGeneric.mg.e5114c7a45a7b3c6
FortinetAutoIt/Injector.AAD!tr
GoogleDetected
IkarusTrojan.Autoit
KasperskyBackdoor.Win32.Remcos.yen
Kingsoftmalware.kb.a.863
MalwarebytesTrojan.Injector.AutoIt
MaxSecureTrojan.Malware.300983.susgen
McAfeeDti!82EDDB35F29F
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Paloaltogeneric.ml
RisingTrojan.Injector/Autoit!1.FD30 (CLASSIC)
SangforTrojan.Win32.Save.a
SkyhighBehavesLike.Win32.TrojanAitInject.tc
SophosTroj/AutoIt-DGJ
VBA32Trojan-Downloader.Autoit.gen
VaristW32/AutoIt.IJ.gen!Eldorado
VirITTrojan.Win32.Dnldr27.DIMR
ZoneAlarmBackdoor.Win32.Remcos.yen

Network contacts

172.93.218.178 178.237.33.50

DNS requests

geoplugin.net

Process list

NameCommand line
DHLAWB6533732999.exe
nonsubmerged.exe"C:\DHLAWB6533732999.exe"
svchost.exe"C:\DHLAWB6533732999.exe"
WScript.exe"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\nonsubmerged.vbs"
nonsubmerged.exe
svchost.exe"%LOCALAPPDATA%\Myriopoda\nonsubmerged.exe"