8463f0c1e828afc585438c68123cc4b55628bc2ec18c58671e13f9439af31fe4
Classification: Malicious
8463f0c1e828afc585438c68123cc4b55628bc2ec18c58671e13f9439af31fe4 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 6 antivirus detections
- 8 IDS alerts
- 4 processes observed
- 10 contacted hosts
- 14 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-03-23 14:00:04 | 2026-09-02 21:45:08 | malicious-activity |
Sample information
- Filenames
- 8463f0c1e828afc585438c68123cc4b55628bc2ec18c58671e13f9439af31fe4, 25cb7192c8f7a3bfec2a4817f8552ca7.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 2320643 bytes
- MD5
25cb7192c8f7a3bfec2a4817f8552ca7- SHA-1
cc221059563e9e8025805a42a9a46154feedd55d- SHA-256
8463f0c1e828afc585438c68123cc4b55628bc2ec18c58671e13f9439af31fe4- First indexed
- 2024-03-23 13:35:56
- Last updated
- 2026-09-02 21:45:08
Antivirus detections
| Engine | Detection |
|---|---|
| Avira | HEUR/AGEN.1372994 |
| Cynet | Malicious (score: 99) |
| ESET-NOD32 | a variant of Win32/TrojanDropper.Agent.SLC |
| F-Secure | Heuristic.HEUR/AGEN.1372994 |
| Ikarus | Trojan.Win32.Crypt |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
Network contacts
152.89.198.214 91.211.247.248 185.196.9.67 173.208.215.98 209.99.187.121 141.98.234.31 109.230.199.109 45.155.250.90 45.142.214.240 93.123.39.238
DNS requests
bhxezum.com bwrqmfj.com dtczogs.info gflpqdj.com hkxjmys.net jemfmdd.info ladhulu.ru mdguvxg.com pzxyjoi.ua rexveet.com ttueriu.info viebdgm.ru wfdeavt.com bfdokix.com
Process list
| Name | Command line |
|---|---|
| 25cb7192c8f7a3bfec2a4817f8552ca7.exe | |
| 25cb7192c8f7a3bfec2a4817f8552ca7.tmp | /SL5="$50148,1960984,54272,C:\25cb7192c8f7a3bfec2a4817f8552ca7.exe" |
| colorpicker.exe | -i |
| colorpicker.exe | -s |