848260ba966228c4db251cfbcc0e02d6ca70523a86b56e5c21f55098cec92479

Classification: Malicious

848260ba966228c4db251cfbcc0e02d6ca70523a86b56e5c21f55098cec92479 is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.

Detection summary

  • 0 antivirus detections
  • 0 IDS alerts
  • 12 processes observed
  • 1 contacted hosts
  • 2 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-08-02 16:30:05 2026-09-02 21:45:07 malicious-activity
Cobalt Strike ThreatFox Abuse.ch 2024-08-02 20:58:14 2024-08-04 20:18:57
CobaltStrike MalwareBazaar Abuse.ch 2024-08-02 18:16:47 2024-08-02 18:16:47 malicious-activity

Tags

suspicious win.cobalt_strike agentemis beacon cobaltstrike cobeacon

Sample information

Filenames
848260ba966228c4db251cfbcc0e02d6ca70523a86b56e5c21f55098cec92479, SecuriteInfo.com.Trojan.NSIS.Runner.18384.10066, ConsiderableWinners.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1184734 bytes
MD5
a23837debdc8f0e9fce308bff036f18f
SHA-1
cf4df97e65bc8a17eefca9d384f55f19fb50602f
SHA-256
848260ba966228c4db251cfbcc0e02d6ca70523a86b56e5c21f55098cec92479
First indexed
2024-08-02 16:12:30
Last updated
2026-09-02 21:45:07

Network contacts

5.181.202.246

DNS requests

UmLcmUHSTT.UmLcmUHSTT fender-shop.online

Process list

NameCommand line
ConsiderableWinners.exe
cmd.exe/k move Dk Dk.cmd & Dk.cmd & exit
tasklist.exe
findstr.exefindstr /I "wrsa.exe opssvc.exe"
tasklist.exe
findstr.exefindstr /I "avastui.exe avgui.exe ekrn.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe"
cmd.execmd /c md 217412
findstr.exefindstr /V "PlasmaProfessionalConstitutesGuide" Cheaper
cmd.execmd /c copy /b Mailing + Violin + Ethernet + Operated + Lunch + Useful 217412\N
Possibly.pifN
choice.exechoice /d y /t 5
Possibly.pif