83a4c4955e180a527d9057901b5e1abfea25de6078856364d795ca53d68cd530
Classification: Malicious
83a4c4955e180a527d9057901b5e1abfea25de6078856364d795ca53d68cd530 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 33 antivirus detections
- 1 IDS alerts
- 18 processes observed
- 9 contacted hosts
- 11 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-11-21 06:26:48 | 2026-09-02 20:45:07 | malicious-activity | |
| Generic.Malware | MalwareBazaar Abuse.ch | 2024-11-21 06:07:38 | 2024-11-21 06:07:38 | malicious-activity |
Tags
evasive maliciousSample information
- Filenames
- 83a4c4955e180a527d9057901b5e1abfea25de6078856364d795ca53d68cd530, file
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 1896960 bytes
- MD5
1ff9879aba9138b20606b03471ec3d11- SHA-1
3b4e3eec402e23200372840a1ba15362a5171119- SHA-256
83a4c4955e180a527d9057901b5e1abfea25de6078856364d795ca53d68cd530- First indexed
- 2024-11-21 06:09:35
- Last updated
- 2026-09-02 20:45:07
Antivirus detections
| Engine | Detection |
|---|---|
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.R682229 |
| Avast | Win32:Evo-gen [Trj] |
| Avira | TR/Crypt.TPM.Gen |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of Win32/Packed.Themida.HZB |
| Elastic | malicious (high confidence) |
| F-Secure | Trojan.TR/Crypt.TPM.Gen |
| FireEye | Generic.mg.1ff9879aba9138b2 |
| Fortinet | W32/Themida.HZB!tr |
| Detected | |
| Gridinsoft | Trojan.Heur!.038120A1 |
| Kaspersky | HEUR:Trojan.Win32.DInvoke.gen |
| Kingsoft | Win32.HeurC.KVMH008.a |
| Malwarebytes | Trojan.MalPack |
| McAfee | Themida-FWSE!1FF9879ABA91 |
| McAfeeD | Real Protect-LS!1FF9879ABA91 |
| Microsoft | Backdoor:Win32/Bladabindi!ml |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Themida.tc |
| Sophos | Mal/Amadey-D |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.Dinvoke.Hajl |
| Trapmine | malicious.high.ml.score |
| VBA32 | TScope.Malware-Cryptor.SB |
| Varist | W32/Wacatac.EG.gen!Eldorado |
| Zoner | Probably Heur.ExeHeaderL |
| tehtris | Generic.Malware |
Network contacts
185.215.113.43 185.215.113.16 31.41.244.11 104.21.66.38 185.215.113.206 172.67.206.172 172.67.208.166 34.116.198.130 104.21.81.208
DNS requests
3xp3cts1aim.sbs befall-sm0ker.sbs cook-rain.sbs fvtekk5pn.top home.fvtekk5pn.top librari-night.sbs owner-vacat10n.sbs p10tgrace.sbs p3ar11fter.sbs peepburry828.sbs processhol.sbs
Process list
| Name | Command line |
|---|---|
| file.exe | |
| skotes.exe | |
| bd1aa5b5ad.exe | |
| 9dfbf22d15.exe | |
| chrome.exe | --remote-debugging-port=9229 --profile-directory="Default" |
| chrome.exe | --type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xe4,0xe8,0xec,0xb8,0xf0,0x7fef0866b58,0x7fef0866b68,0x7fef0866b78 |
| 9bf7b576bf.exe | |
| taskkill.exe | taskkill /F /IM firefox.exe /T |
| taskkill.exe | taskkill /F /IM chrome.exe /T |
| taskkill.exe | taskkill /F /IM msedge.exe /T |
| taskkill.exe | taskkill /F /IM opera.exe /T |
| taskkill.exe | taskkill /F /IM brave.exe /T |
| firefox.exe | --kiosk "https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd" --no-default-browser-check --disable-popup-blocking |
| taskkill.exe | taskkill /F /IM firefox.exe /T |
| 0dad53c2e5.exe | |
| 4d03016523.exe | |
| chrome.exe | --remote-debugging-port=9222 --profile-directory="Default" |
| chrome.exe | --type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xe4,0xe8,0xec,0x80,0xf0,0x7fef0706b58,0x7fef0706b68,0x7fef0706b78 |