82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38
Classification: Malicious
82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 17 antivirus detections
- 2 IDS alerts
- 22 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-02-15 04:15:04 |
2026-09-02 19:45:06 |
malicious-activity
|
|
| NanoCore |
MalwareBazaar Abuse.ch |
2024-02-15 03:55:13 |
2024-02-15 03:55:13 |
malicious-activity
|
|
Sample information
- Filenames
- 82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38, IqgoWz56w4vBHL8.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 778240 bytes
- MD5
1293d289dc6df54cd2fe461b01f8f28e
- SHA-1
8fea033fc6cdb88f82b2ca0f2c3cb8a02e1703e4
- SHA-256
82f800b2cd609858f78b1014e5fe5729059cf520d598aa99d22b97045853eb38
- First indexed
- 2024-02-15 03:57:11
- Last updated
- 2026-09-02 19:45:06
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| Bkav | W32.AIDetectMalware.CS |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| Fortinet | MSIL/GenKryptik.FQQD!tr |
| MaxSecure | Trojan.Malware.300983.susgen |
| Microsoft | Trojan:MSIL/Formbook.KAH!MTB |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.bc |
| Symantec | Scr.Malcode!gdn33 |
| Trapmine | malicious.high.ml.score |
| VBA32 | TrojanLoader.MSIL.DaVinci.Heur |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| ZoneAlarm | VHO:Trojan-Spy.MSIL.Noon.gen |
Process list
| Name | Command line |
| IqgoWz56w4vBHL8.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe" |
| schtasks.exe | /Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp2731.tmp" |
| RegSvcs.exe | |
| schtasks.exe | /create /f /tn "PCI Monitor" /xml "%TEMP%\tmp6B00.tmp" |
| schtasks.exe | /create /f /tn "PCI Monitor Task" /xml "%TEMP%\tmp78EC.tmp" |
| DVWubBK.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe" |
| schtasks.exe | /Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp8F67.tmp" |
| RegSvcs.exe | |
| IqgoWz56w4vBHL8.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe" |
| schtasks.exe | /Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp2424.tmp" |
| RegSvcs.exe | |
| schtasks.exe | /create /f /tn "SCSI Service" /xml "%TEMP%\tmp2AFA.tmp" |
| schtasks.exe | /create /f /tn "SCSI Service Task" /xml "%TEMP%\tmp2CC0.tmp" |
| DVWubBK.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\DVWubBK.exe" |
| schtasks.exe | /Create /TN "Updates\DVWubBK" /XML "%TEMP%\tmp76AF.tmp" |
| RegSvcs.exe | |
| schtasks.exe | /create /f /tn "SCSI Service" /xml "%TEMP%\tmp7893.tmp" |
| schtasks.exe | /create /f /tn "SCSI Service Task" /xml "%TEMP%\tmp7A98.tmp" |