windefragsvc.exe

Classification: Malicious

windefragsvc.exe is a malicious file sample. Linked to Sombrat malware. Reported by 3 threat sources, last seen 2024-08-15. Detected by 27 antivirus engines.

Detection summary

  • 27 antivirus detections
  • 0 IDS alerts
  • 4 processes observed
  • 6 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: SOMBRAT (S0615)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-08-15 16:00:03 2024-08-15 16:45:04
SombRAT ThreatFox Abuse.ch 2024-05-16 15:59:02 2024-05-18 15:20:48 S0615 SombRAT
VenomRAT MalwareBazaar Abuse.ch 2024-05-16 13:26:17 2024-05-16 13:26:17 malicious-activity

Tags

win.sombrat

Sample information

Filenames
windefragsvc.exe
File type
application/x-dosexec
Size
12311040 bytes
MD5
4cbf5db190e95e44d2a637e3513cb39f
SHA-1
0f83db9b94d8d3975116732282364ee7aa8d142f
SHA-256
84c2b21f5b3c48dfb7481094b8e7f8c2f56e041fe3244b1a608bc264d83536bb
First indexed
2024-05-16 14:23:48
Last updated
2025-12-25 00:49:55

Antivirus detections

EngineDetection
ALYacGen:Variant.MSILHeracles.143938
AVGCrypterX-gen [Trj]
ArcabitTrojan.MSILHeracles.D23242
AvastCrypterX-gen [Trj]
AviraTR/Dropper.MSIL.Gen
BitDefenderGen:Variant.MSILHeracles.143938
Cylanceunsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/GenKryptik.GXLZ
Elasticmalicious (high confidence)
EmsisoftGen:Variant.MSILHeracles.143938 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
FireEyeGen:Variant.MSILHeracles.143938
GDataGen:Variant.MSILHeracles.143938
MAXmalware (ai score=80)
MalwarebytesTrojan.Crypt.MSIL.Generic
MaxSecureTrojan.Malware.300983.susgen
McAfeeArtemis!4CBF5DB190E9
MicroWorld-eScanGen:Variant.MSILHeracles.143938
MicrosoftProgram:Win32/Wacapew.C!ml
RisingMalware.Obfus/[email protected] (RDM.MSIL2:rfkDtIQZE1w2/E71Eh5Qnw)
SangforTrojan.Msil.Agent.Vurm
SentinelOneStatic AI - Malicious PE
SkyhighArtemis!Trojan
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
VIPREGen:Variant.MSILHeracles.143938

Network contacts

91.92.251.159 94.156.64.5 91.92.254.21 94.156.64.90 91.92.251.153 91.92.255.79

Process list

NameCommand line
windefragsvc.exe
RegAsm.exe
RegAsm.exe
RegAsm.exe