841a7dd1080fc87a5d73eaa4635e43f14b770b419e5e68c5e8772f567f1afc86

Classification: Malicious

841a7dd1080fc87a5d73eaa4635e43f14b770b419e5e68c5e8772f567f1afc86 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 85 antivirus detections
  • 1 IDS alerts
  • 9 processes observed
  • 1 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-03-19 16:30:04 2026-09-02 20:45:03 malicious-activity

Tags

windows-server-utility

Sample information

Filenames
841a7dd1080fc87a5d73eaa4635e43f14b770b419e5e68c5e8772f567f1afc86, 65511.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1315840 bytes
MD5
5ac2d5bcfd775d99a3aaadce4eef5d75
SHA-1
675d744f798e812d605f1a91d9b274b1212567f6
SHA-256
841a7dd1080fc87a5d73eaa4635e43f14b770b419e5e68c5e8772f567f1afc86
First indexed
2024-03-19 16:12:02
Last updated
2026-09-02 20:45:03

Antivirus detections

EngineDetection
ALYacTrojan.Agent.CGMR
APEXMalicious
AVGWin32:Prockill-A [Rtk]
AhnLab-V3Trojan/Win32.Webtoos.C1040590
Antiy-AVLTrojan[Rootkit]/Win32.Agent
ArcabitTrojan.Agent.CGMR
AvastWin32:Prockill-A [Rtk]
AviraTR/Agent.14016.2
BaiduWin32.Rootkit.Agent.at
BitDefenderTrojan.Agent.CGMR
BitDefenderThetaGen:NN.ZexaF.36802.puW@aKX7Duki
BkavW32.AIDetectMalware
CAT-QuickHealTrojan.WebToos.S18562
ClamAVWin.Trojan.Gadoopt-2
CrowdStrikewin/malicious_confidence_90% (D)
Cybereasonmalicious.cfd775
Cylanceunsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebBackDoor.Gates.8
ESET-NOD32multiple detections
EmsisoftTrojan.Agent.CGMR (B)
F-SecureTrojan.TR/Agent.14016.2
FireEyeGeneric.mg.5ac2d5bcfd775d99
FortinetW32/Agent.DGUG!tr
GDataTrojan.Agent.CGMR
GoogleDetected
GridinsoftRootkit.Win32.Agent.bot!s1
IkarusTrojan.Win32.Rootkit
JiangminTrojan/Reconyc.eyd
K7AntiVirusRootKit ( 0055e3fe1 )
K7GWRootKit ( 0055e3fe1 )
KasperskyTrojan.Win32.Reconyc.esql
Kingsoftmalware.kb.a.999
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.8750652.susgen
McAfeeGenericRXDY-OY!5AC2D5BCFD77
MicroWorld-eScanTrojan.Agent.CGMR
MicrosoftTrojan:Win32/WebToos.A
NANO-AntivirusTrojan.Win32.Reconyc.exhhog
PandaTrj/Genetic.gen
RisingTrojan.Gadoopt/x64!1.A7DF (CLASSIC)
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighGenericRXDY-OY!5AC2D5BCFD77
SophosPort stealthing rootkit
SymantecSMG.Heur!gen
TACHYONTrojan/W32.Rootkit.1315840
Trapminemalicious.high.ml.score
TrendMicroTROJ_WEBTOOS.SM
TrendMicro-HouseCallTROJ_WEBTOOS.SM
VBA32BScope.Trojan.Nagyo
VaristW32/WebToos.B.gen!Eldorado
ViRobotBackdoor.Win32.Agent.1315840.A
VirITTrojan.Win32.Generic.CNZL
WebrootW32.Trojan.Gen
YandexTrojan.GenAsa!84t1QyHA9Mc
ZillyaRootkit.Agent.Win32.15968
ZoneAlarmTrojan.Win32.Reconyc.esql
alibabacloudDDoS:Multi/BillGates.4625dac3
tehtrisGeneric.Malware
AlibabaTrojan:Win32/WebToos.fbb4335d
Antiy-AVLTrojan/Win32.Reconyc
CAT-QuickHealTrojan.Ghanarava.1752158374ef5d75
CTXexe.trojan.reconyc
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
Elasticmalicious (high confidence)
KingsoftWin32.Trojan.Reconyc.esql
LionicTrojan.Win32.Reconyc.tsr5
McAfeeDReal Protect-LS!5AC2D5BCFD77
Paloaltogeneric.ml
SentinelOneStatic AI - Suspicious PE
SkyhighBehavesLike.Win32.Generic.th
SophosTroj/RKPort-Fam
SymantecML.Attribute.HighConfidence
TencentTrojan.Win32.Reconyc.ca
TrellixENSGenericRXDY-OY!5AC2D5BCFD77
VIPRETrojan.Agent.CGMR
XcitiumMalware@#3l5home4zx29r
ZoneAlarmTroj/RKPort-Fam
alibabacloudDDoS:Multi/BillGates
huorongTrojan/Nagyo

Network contacts

23.62.230.36

DNS requests

syn.ndos.cc

Process list

NameCommand line
65511.exe
Taskkill.exeTaskkill /F /IM DbSecuritySpt.exe
Taskkill.exeTaskkill /F /IM Bill.exe
Taskkill.exeTaskkill /F /IM svch0st.exe
65511.exe
Taskkill.exeTaskkill /F /IM DbSecuritySpt.exe
Taskkill.exeTaskkill /F /IM Bill.exe
Taskkill.exeTaskkill /F /IM svch0st.exe
DbSecuritySpt.exe