84ab5607a472d325b4128bf0012fe9253e09a694b57bac657abf54973c9b6312
Classification: Malicious
84ab5607a472d325b4128bf0012fe9253e09a694b57bac657abf54973c9b6312 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 49 antivirus detections
- 0 IDS alerts
- 4 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-07-31 21:30:38 |
2026-09-02 21:45:05 |
malicious-activity
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2024-07-30 23:35:01 |
2024-07-30 23:35:01 |
malicious-activity
|
|
Sample information
- Filenames
- 84ab5607a472d325b4128bf0012fe9253e09a694b57bac657abf54973c9b6312, 84ab5. Backdoor.exe, f81185426901a3519e4d8d030d677ecf8a50d873fecfdd3980ef3ccfac785707_dump.exe
- File type
- application/x-dosexec
- Size
- 46592 bytes
- MD5
15b8e2ef54c276964ff060b418efe7ef
- SHA-1
44c15cfbcd468be279a6fc87f173215ff1f6e7a1
- SHA-256
84ab5607a472d325b4128bf0012fe9253e09a694b57bac657abf54973c9b6312
- First indexed
- 2024-07-31 01:19:17
- Last updated
- 2026-09-02 21:45:06
Antivirus detections
| Engine | Detection |
| ALYac | IL:Trojan.MSILZilla.105845 |
| APEX | Malicious |
| AVG | Win32:TrojanX-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.XenoRAT.R633435 |
| Arcabit | IL:Trojan.MSILZilla.D19D75 |
| Avast | Win32:TrojanX-gen [Trj] |
| Avira | HEUR/AGEN.1371394 |
| BitDefender | IL:Trojan.MSILZilla.105845 |
| BitDefenderTheta | Gen:NN.ZemsilF.36810.cm0@amONu |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.YakbeexMSIL.ZZ4 |
| ClamAV | Win.Packed.Msilzilla-10031599-0 |
| CrowdStrike | win/malicious_confidence_90% (W) |
| Cybereason | malicious.f54c27 |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.XenoRatNET.15 |
| ESET-NOD32 | a variant of MSIL/Agent.WNX |
| Elastic | Windows.Generic.Threat |
| Emsisoft | IL:Trojan.MSILZilla.105845 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1371394 |
| FireEye | Generic.mg.15b8e2ef54c27696 |
| Fortinet | MSIL/Agent.WNX!tr |
| GData | MSIL.Trojan.PSE.1XH2EV4 |
| Google | Detected |
| Gridinsoft | Trojan.Win32.Agent.dd!ni |
| Ikarus | Trojan.MSIL.XenoRat |
| Jiangmin | TrojanDropper.MSIL.bmdr |
| K7AntiVirus | Trojan ( 005b11ae1 ) |
| K7GW | Trojan ( 005b11ae1 ) |
| Kaspersky | HEUR:Trojan-Dropper.MSIL.Agent.gen |
| Kingsoft | malware.kb.c.993 |
| MAX | malware (ai score=81) |
| Malwarebytes | Backdoor.XenoRAT |
| McAfee | XenoRat!15B8E2EF54C2 |
| McAfeeD | Real Protect-LS!15B8E2EF54C2 |
| MicroWorld-eScan | IL:Trojan.MSILZilla.105845 |
| Microsoft | Trojan:MSIL/Zusy.EA!MTB |
| Panda | Trj/GdSda.A |
| Rising | Backdoor.XenoRAT!1.F6EA (CLASSIC) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Mal/RAT-C |
| Symantec | ML.Attribute.HighConfidence |
| VIPRE | IL:Trojan.MSILZilla.105845 |
| Varist | W32/MSIL_Agent.HCQ.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL.GVF |
| ZoneAlarm | HEUR:Trojan-Dropper.MSIL.Agent.gen |
| huorong | Trojan/MSIL.Agent.dj |
Process list
| Name | Command line |
| 84ab5.Backdoor.exe | |
| 84ab5.Backdoor.exe | |
| schtasks.exe | /Create /TN "vplayer" /XML "%TEMP%\tmpA29F.tmp" /F |
| 84ab5.Backdoor.exe | |