83fa28f2043de0cab2c7e602a35df1e630628c51aa622de5a7395cb26bb70f84
Classification: Malicious
83fa28f2043de0cab2c7e602a35df1e630628c51aa622de5a7395cb26bb70f84 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 64 antivirus detections
- 0 IDS alerts
- 6 processes observed
- 2 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-07-25 02:44:21 |
2026-09-02 20:45:05 |
malicious-activity
|
|
| Worm.Ramnit |
MalwareBazaar Abuse.ch |
2024-07-25 02:10:06 |
2024-07-25 02:10:06 |
malicious-activity
|
|
Tags
evasive
suspicious
malicious
wapomi
Sample information
- Filenames
- 83fa28f2043de0cab2c7e602a35df1e630628c51aa622de5a7395cb26bb70f84, Lisect_AVT_24003_G1A_79.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 1908736 bytes
- MD5
0b2deb5af6494180fe5768220b629c24
- SHA-1
d81fddab8ba1a6eff20e6a6775209bcb7c0c8d07
- SHA-256
83fa28f2043de0cab2c7e602a35df1e630628c51aa622de5a7395cb26bb70f84
- First indexed
- 2024-07-25 02:25:21
- Last updated
- 2026-09-02 20:45:05
Antivirus detections
| Engine | Detection |
| ALYac | Win32.VJadtre.3 |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Win32/VJadtre.Gen |
| Antiy-AVL | Virus/Win32.Nimnul.f |
| Arcabit | Win32.VJadtre.3 |
| Avast | Win32:Evo-gen [Trj] |
| Avira | W32/Jadtre.B |
| Baidu | Win32.Virus.Otwycal.d |
| BitDefender | Win32.VJadtre.3 |
| BitDefenderTheta | AI:FileInfector.991137D00F |
| Bkav | W32.FamVT.DumpModuleInfectiousNME.PE |
| ClamAV | Win.Malware.Wapomi-10020301-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cybereason | malicious.af6494 |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.Darkshell.246 |
| ESET-NOD32 | Win32/Wapomi.BA |
| Elastic | malicious (high confidence) |
| Emsisoft | Win32.VJadtre.3 (B) |
| F-Secure | Malware.W32/Jadtre.B |
| FireEye | Generic.mg.0b2deb5af6494180 |
| Fortinet | W32/CoinMiner.EC2B!tr |
| GData | Win32.Virus.Wapomi.A |
| Google | Detected |
| Gridinsoft | Trojan.Heur!.038122A1 |
| Ikarus | Virus.Win32.Wapomi |
| Jiangmin | Win32/Nimnul.f |
| K7AntiVirus | Virus ( 0040f7441 ) |
| K7GW | Virus ( 0040f7441 ) |
| Kaspersky | Virus.Win32.Nimnul.f |
| MAX | malware (ai score=80) |
| Malwarebytes | Trojan.MalPack.Themida.Generic |
| MaxSecure | Virus.Nimnul.F |
| McAfee | W32/Kudj |
| McAfeeD | Real Protect-LS!0B2DEB5AF649 |
| MicroWorld-eScan | Win32.VJadtre.3 |
| Microsoft | Virus:Win32/Mikcer.B |
| NANO-Antivirus | Trojan.Win32.Banload.cstqaj |
| Panda | W32/Pcarrier.A |
| Rising | Virus.Roue!1.9E10 (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Kryptik |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.tc |
| Sophos | W32/Nimnul-A |
| Symantec | W32.Wapomi.C!inf |
| TACHYON | Virus/W32.Ramnit.C |
| Tencent | Virus.Win32.Loader.aab |
| Trapmine | malicious.high.ml.score |
| TrendMicro | PE_WAPOMI.BM |
| TrendMicro-HouseCall | PE_WAPOMI.BM |
| VBA32 | Virus.Nimnul.19209 |
| VIPRE | Win32.VJadtre.3 |
| Varist | W32/PatchLoad.E |
| ViRobot | Win32.Ramnit.F |
| VirIT | Win32.Nimnul.F |
| Xcitium | Virus.Win32.Wali.KA@558nxg |
| Zillya | Virus.Nimnul.Win32.5 |
| ZoneAlarm | Virus.Win32.Nimnul.f |
| Zoner | Probably Heur.ExeHeaderL |
| tehtris | Generic.Malware |
Process list
| Name | Command line |
| Lisect_AVT_24003_G1A_79.exe | |
| zjOtfY.exe | |
| cmd.exe | %WINDIR%\system32\cmd.exe /c ""%TEMP%\1d5637f7.bat" " |
| WerFault.exe | -u -p 7760 -s 756 |
| WerFault.exe | -u -p 7760 -s 756 |
| WerFault.exe | -pss -s 440 -p 7760 -ip 7760 |