845b30ffa7cd1180517aad6d3c0c653e0e4e49b5bfe34d7e692a76752d63d57c
Classification: Malicious
845b30ffa7cd1180517aad6d3c0c653e0e4e49b5bfe34d7e692a76752d63d57c is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 29 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-09-22 04:15:03 |
2026-09-02 21:45:08 |
malicious-activity
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2024-09-22 03:58:01 |
2024-09-22 03:58:01 |
malicious-activity
|
|
Sample information
- Filenames
- 845b30ffa7cd1180517aad6d3c0c653e0e4e49b5bfe34d7e692a76752d63d57c, BallonySwords.exe
- File type
- PE32 executable (console) Intel 80386 Mono/.Net as ...
- Size
- 475512 bytes
- MD5
f1def597850e7f0490adc3a10b08db3d
- SHA-1
3dd5594049e154002f3b60c821a4d8d854d212c6
- SHA-256
845b30ffa7cd1180517aad6d3c0c653e0e4e49b5bfe34d7e692a76752d63d57c
- First indexed
- 2024-09-22 03:59:38
- Last updated
- 2026-09-02 21:45:08
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.MSILHeracles.179443 |
| APEX | Malicious |
| AVG | Win32:PWSX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Vidar.C5672959 |
| Arcabit | Trojan.MSILHeracles.D2BCF3 |
| Avast | Win32:PWSX-gen [Trj] |
| BitDefender | Gen:Variant.MSILHeracles.179443 |
| Bkav | W32.AIDetectMalware.CS |
| CTX | exe.unknown.msilheracles |
| ClamAV | Win.Packed.Pwsx-10035189-0 |
| CrowdStrike | win/malicious_confidence_60% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of MSIL/GenKryptik.HBWY |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.MSILHeracles.179443 (B) |
| FireEye | Generic.mg.f1def597850e7f04 |
| GData | Gen:Variant.MSILHeracles.179443 |
| Google | Detected |
| Gridinsoft | Trojan.Win32.Packed.dd!ni |
| Ikarus | Trojan.MSIL.Krypt |
| MicroWorld-eScan | Gen:Variant.MSILHeracles.179443 |
| Microsoft | Program:Win32/Wacapew.C!ml |
| SentinelOne | Static AI - Malicious PE |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | malicious.moderate.ml.score |
| VIPRE | Gen:Variant.MSILHeracles.179443 |
| Varist | W32/MSIL_Agent.ILW.gen!Eldorado |
| huorong | Trojan/MSIL.Agent.li |
Process list
| Name | Command line |
| BallonySwords.exe | |
| RegAsm.exe | |
| WerFault.exe | -u -p 2876 -s 956 |
| WerFault.exe | -u -p 2876 -s 956 |
| WerFault.exe | -pss -s 448 -p 2876 -ip 2876 |