8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d.exe
Classification: Malicious
8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d.exe is a malicious file sample. Linked to Cobian Rat malware.
Detection summary
- 92 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 6 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: COBIAN RAT (S0338)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-03-03 08:45:04 | 2026-03-03 08:45:04 | ||
| Cobianrat | Triage | 2026-03-03 08:05:39 | 2026-03-03 08:05:39 | malicious-activity | S0338 Cobian RAT |
| Generic.Malware | Abuse.ch | 2020-07-24 10:57:52 | 2020-07-24 10:57:52 |
Tags
cobianrat persistence ratSample information
- Filenames
- 8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d.exe, 8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d.bin, njRAT
- File type
- application/x-dosexec
- MD5
f755142ef8a850daa4822d45bcdc1417- SHA-1
15174372056805d447a2a99b34e04ceef3f4c973- SHA-256
8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d- SHA-512
fea0b7d1d987b1ea2748a610d8baae74f72aa4bc55c70acb350598e917b320ce043fc3ad62335ae626033e7eadd40ba447129277dfa8a0a45429257fe70a90a9- First indexed
- 2020-07-24 12:15:18
- Last updated
- 2026-04-12 08:59:06
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.FamVT.AveMaiLK.Trojan |
| Cynet | Malicious (score: 100) |
| FireEye | Generic.mg.f755142ef8a850da |
| CAT-QuickHeal | PUA.GenericFC.S7081120 |
| McAfee | Trojan-FMEX!F755142EF8A8 |
| Cylance | Unsafe |
| VIPRE | Trojan.Win32.Generic!BT |
| Sangfor | Malware |
| K7AntiVirus | Trojan ( 00507d2e1 ) |
| K7GW | Trojan ( 00507d2e1 ) |
| Cybereason | malicious.ef8a85 |
| Arcabit | Trojan.MSIL.Agent.CPM |
| Invincea | heuristic |
| F-Prot | W32/MSIL_Troj.AP.gen!Eldorado |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of MSIL/Bladabindi.HP |
| APEX | Malicious |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| BitDefender | Trojan.MSIL.Agent.CPM |
| MicroWorld-eScan | Trojan.MSIL.Agent.CPM |
| Avast | MSIL:Agent-CIB [Trj] |
| Endgame | malicious (high confidence) |
| F-Secure | Trojan.TR/Dropper.MSIL.Gen |
| DrWeb | Trojan.DownLoader26.5584 |
| Zillya | Trojan.Bladabindi.Win32.111302 |
| TrendMicro | BKDR_BLADABI.SMC |
| MaxSecure | Trojan.Malware.300983.susgen |
| Emsisoft | Trojan.MSIL.Agent.CPM (B) |
| Ikarus | Trojan.ILCrypt |
| Cyren | W32/MSIL_Troj.AP.gen!Eldorado |
| Jiangmin | Trojan.Generic.dgira |
| Avira | TR/Dropper.MSIL.Gen |
| MAX | malware (ai score=87) |
| Antiy-AVL | Trojan/Win32.Wacatac |
| Microsoft | Trojan:Win32/Wacatac.D8!ml |
| ZoneAlarm | HEUR:Trojan.Win32.Generic |
| GData | MSIL.Backdoor.Bladabindi.AV |
| AhnLab-V3 | Trojan/Win32.Bladabindi.R278728 |
| VBA32 | TScope.Trojan.MSIL |
| ALYac | Trojan.MSIL.Agent.CPM |
| Ad-Aware | Trojan.MSIL.Agent.CPM |
| Malwarebytes | Backdoor.Bladabindi.MSIL |
| TrendMicro-HouseCall | BKDR_BLADABI.SMC |
| Rising | Backdoor.MSIL.Bladabindi!1.9E49 (CLASSIC) |
| Yandex | Trojan.Agent!cWpVxJjE3Ms |
| SentinelOne | DFI - Malicious PE |
| eGambit | Unsafe.AI_Score_99% |
| Fortinet | MSIL/Generic.AP.61102A!tr |
| BitDefenderTheta | Gen:NN.ZemsilF.34138.bm0@aKDuAOo |
| AVG | MSIL:Agent-CIB [Trj] |
| Panda | Trj/GdSda.A |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Qihoo-360 | HEUR/QVM03.0.C74D.Malware.Gen |
| ALYac | Gen:Variant.Application.MSILPerseus.82594 |
| Alibaba | Trojan:MSIL/Bladabindi.8533f267 |
| Arcabit | Trojan.Application.MSILPerseus.D142A2 |
| BitDefender | Gen:Variant.Application.MSILPerseus.82594 |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.GenericFC.S20328187 |
| CTX | exe.trojan.bladabindi |
| ClamAV | Win.Packed.Bladabindi-9857493-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Application.MSILPerseus.82594 (B) |
| Detected | |
| Gridinsoft | Backdoor.Win32.Bladabindi.vl!ni |
| Ikarus | Trojan-Downloader.Agent |
| Kingsoft | malware.kb.c.1000 |
| Lionic | Trojan.Win32.Bladabindi.4!c |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.7164915.susgen |
| McAfeeD | Real Protect-LS!F755142EF8A8 |
| MicroWorld-eScan | Gen:Variant.Application.MSILPerseus.82594 |
| Microsoft | Trojan:Win32/CoinMiner!pz |
| NANO-Antivirus | Trojan.Win32.Bladabindi.hpbuvf |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Backdoor.njRAT!1.9E49 (CLASSIC) |
| SUPERAntiSpyware | Backdoor.Bladabindi/Variant |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | Trojan-FMEX!F755142EF8A8 |
| Sophos | Troj/MSIL-TGD |
| Tencent | Trojan.Win32.Bladabindi.16000442 |
| VIPRE | Gen:Variant.Application.MSILPerseus.82594 |
| Varist | W32/MSIL_Troj.AP.gen!Eldorado |
| VirIT | Trojan.Win32.Dnldr24.CJC |
| Xcitium | Malware@#2ue6ws4qhdq6q |
| ZoneAlarm | Troj/MSIL-TGD |
| alibabacloud | Trojan:MSIL/Bladabindi.HP |
| huorong | TrojanDownloader/MSIL.MalDownload.b |
Network contacts
3.128.107.74 52.14.18.129 3.138.45.170 3.131.207.170 3.22.53.161 13.59.15.185