841eb644979b3c640761762645c9cd26f9bb46e558eaeb7bf0c2a79e761878f4
Classification: Malicious
841eb644979b3c640761762645c9cd26f9bb46e558eaeb7bf0c2a79e761878f4 is a malicious file sample. Linked to Xloader malware. Detected by 64 antivirus engines.
Detection summary
- 64 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: XLOADER (S1207)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 20:45:03 | 2026-09-02 20:45:03 | malicious-activity | |
| Formbook | MalwareBazaar Abuse.ch | 2024-10-30 07:40:18 | 2024-10-30 07:40:18 | malicious-activity | S1207 XLoader |
Tags
evasiveSample information
- Filenames
- 841eb644979b3c640761762645c9cd26f9bb46e558eaeb7bf0c2a79e761878f4, BBD6FFDB33259778F08704696A04891F.exe
- File type
- application/x-dosexec
- MD5
bbd6ffdb33259778f08704696a04891f- SHA-1
0fd836bb4bfc035ff35ebe0fb47e4693cec9e8ba- SHA-256
841eb644979b3c640761762645c9cd26f9bb46e558eaeb7bf0c2a79e761878f4- First indexed
- 2024-10-30 08:19:13
- Last updated
- 2026-09-02 20:45:03
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Dropped:Trojan.Generic.32176315 |
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Trj] |
| AhnLab-V3 | Trojan/Win32.Ruftar.R30190 |
| Alibaba | Ransom:Win32/Weenloc.e8c |
| Antiy-AVL | Trojan[Dropper]/Win32.Delf.efnz |
| Arcabit | Trojan.Generic.D1EAF8BB |
| Avast | Win32:MalwareX-gen [Trj] |
| Avira | TR/Crypt.XPACK.Gen |
| Baidu | Win32.Trojan-Dropper.Delf.as |
| BitDefender | Dropped:Trojan.Generic.32176315 |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.delf |
| ClamAV | Win.Trojan.Injector-6297685-1 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Packed.20771 |
| ESET-NOD32 | Win32/TrojanDropper.Delf.OEF |
| Elastic | malicious (high confidence) |
| Emsisoft | Dropped:Trojan.Generic.32176315 (B) |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen |
| FireEye | Generic.mg.bbd6ffdb33259778 |
| Fortinet | W32/CoinMiner.PAG!tr |
| GData | Dropped:Trojan.Generic.32176315 |
| Detected | |
| Gridinsoft | Backdoor.Win32.Gen.zv!s1 |
| Ikarus | Worm.Win32.Agent |
| Jiangmin | Trojan/Genome.bawa |
| K7AntiVirus | Trojan ( 004bdc281 ) |
| K7GW | Trojan ( 004bdc281 ) |
| Kaspersky | Trojan-Dropper.Win32.Delf.eimp |
| Kingsoft | malware.kb.a.1000 |
| Lionic | Trojan.Win32.Rbot.leZz |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Dropper.Delf.EFNZ |
| McAfee | GenericRXDR-OQ!BBD6FFDB3325 |
| McAfeeD | Real Protect-LS!BBD6FFDB3325 |
| MicroWorld-eScan | Dropped:Trojan.Generic.32176315 |
| Microsoft | Trojan:Win32/Dorv.A |
| NANO-Antivirus | Trojan.Win32.Dropper.flagce |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Dropper.Delf!1.C7FF (CLASSIC) |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.rc |
| Sophos | Mal/VMProtBad-A |
| Symantec | SMG.Heur!gen |
| Tencent | Trojan-Dropper.Win32.Delf.waa |
| Trapmine | malicious.high.ml.score |
| TrendMicro | TROJ_BINDER.SMBD |
| TrendMicro-HouseCall | TROJ_BINDER.SMBD |
| VBA32 | TrojanDropper.Delf |
| VIPRE | Dropped:Trojan.Generic.32176315 |
| Varist | W32/Trojan.VVWT-8174 |
| ViRobot | Trojan.Win32.A.Scar.451584.A |
| VirIT | Trojan.Win32.Generic.CKWZ |
| Webroot | W32.Trojan.Gen |
| Xcitium | TrojWare.Win32.TrojanDropper.Delf.SOC@572vwy |
| Yandex | Trojan.GenAsa!mL69tvFKrYE |
| ZoneAlarm | Trojan-Dropper.Win32.Delf.eimp |
| alibabacloud | Trojan[dropper]:Win/Delf.OA! |
| huorong | Backdoor/DarkKomet.a |