82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38

Classification: Malicious

82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 17 antivirus detections
  • 2 IDS alerts
  • 22 processes observed
  • 1 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-02-15 04:15:04 2026-09-02 19:45:06 malicious-activity
NanoCore MalwareBazaar Abuse.ch 2024-02-15 03:55:13 2024-02-15 03:55:13 malicious-activity

Tags

rat infostealer

Sample information

Filenames
82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38, IqgoWz56w4vBHL8.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
778240 bytes
MD5
1293d289dc6df54cd2fe461b01f8f28e
SHA-1
8fea033fc6cdb88f82b2ca0f2c3cb8a02e1703e4
SHA-256
82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38
First indexed
2024-02-15 03:57:11
Last updated
2026-09-02 19:45:06

Antivirus detections

EngineDetection
APEXMalicious
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (D)
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
Elasticmalicious (high confidence)
FortinetMSIL/GenKryptik.FQQD!tr
MaxSecureTrojan.Malware.300983.susgen
MicrosoftTrojan:MSIL/Formbook.KAH!MTB
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.bc
SymantecScr.Malcode!gdn33
Trapminemalicious.high.ml.score
VBA32TrojanLoader.MSIL.DaVinci.Heur
VirITTrojan.Win32.MSIL_Heur.A
ZoneAlarmVHO:Trojan-Spy.MSIL.Noon.gen

Network contacts

103.114.104.158

DNS requests

tzitziklishop3.ddns.net

Process list

NameCommand line
IqgoWz56w4vBHL8.exe
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe"
schtasks.exe/Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp2731.tmp"
RegSvcs.exe
schtasks.exe/create /f /tn "PCI Monitor" /xml "%TEMP%\tmp6B00.tmp"
schtasks.exe/create /f /tn "PCI Monitor Task" /xml "%TEMP%\tmp78EC.tmp"
DVWubBK.exe
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe"
schtasks.exe/Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp8F67.tmp"
RegSvcs.exe
IqgoWz56w4vBHL8.exe
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe"
schtasks.exe/Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp2424.tmp"
RegSvcs.exe
schtasks.exe/create /f /tn "SCSI Service" /xml "%TEMP%\tmp2AFA.tmp"
schtasks.exe/create /f /tn "SCSI Service Task" /xml "%TEMP%\tmp2CC0.tmp"
DVWubBK.exe
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe"
schtasks.exe/Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp76AF.tmp"
RegSvcs.exe
schtasks.exe/create /f /tn "SCSI Service" /xml "%TEMP%\tmp7893.tmp"
schtasks.exe/create /f /tn "SCSI Service Task" /xml "%TEMP%\tmp7A98.tmp"