windefragsvc.exe
Classification: Malicious
windefragsvc.exe is a malicious file sample. Linked to Sombrat malware. Reported by 3 threat sources, last seen 2024-08-15. Detected by 27 antivirus engines.
Detection summary
- 27 antivirus detections
- 0 IDS alerts
- 4 processes observed
- 6 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SOMBRAT (S0615)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-08-15 16:00:03 | 2024-08-15 16:45:04 | ||
| SombRAT | ThreatFox Abuse.ch | 2024-05-16 15:59:02 | 2024-05-18 15:20:48 | S0615 SombRAT | |
| VenomRAT | MalwareBazaar Abuse.ch | 2024-05-16 13:26:17 | 2024-05-16 13:26:17 | malicious-activity |
Tags
win.sombratSample information
- Filenames
- windefragsvc.exe
- File type
- application/x-dosexec
- Size
- 12311040 bytes
- MD5
4cbf5db190e95e44d2a637e3513cb39f- SHA-1
0f83db9b94d8d3975116732282364ee7aa8d142f- SHA-256
84c2b21f5b3c48dfb7481094b8e7f8c2f56e041fe3244b1a608bc264d83536bb- First indexed
- 2024-05-16 14:23:48
- Last updated
- 2025-12-25 00:49:55
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.MSILHeracles.143938 |
| AVG | CrypterX-gen [Trj] |
| Arcabit | Trojan.MSILHeracles.D23242 |
| Avast | CrypterX-gen [Trj] |
| Avira | TR/Dropper.MSIL.Gen |
| BitDefender | Gen:Variant.MSILHeracles.143938 |
| Cylance | unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of MSIL/GenKryptik.GXLZ |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.MSILHeracles.143938 (B) |
| F-Secure | Trojan.TR/Dropper.MSIL.Gen |
| FireEye | Gen:Variant.MSILHeracles.143938 |
| GData | Gen:Variant.MSILHeracles.143938 |
| MAX | malware (ai score=80) |
| Malwarebytes | Trojan.Crypt.MSIL.Generic |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | Artemis!4CBF5DB190E9 |
| MicroWorld-eScan | Gen:Variant.MSILHeracles.143938 |
| Microsoft | Program:Win32/Wacapew.C!ml |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:rfkDtIQZE1w2/E71Eh5Qnw) |
| Sangfor | Trojan.Msil.Agent.Vurm |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| VIPRE | Gen:Variant.MSILHeracles.143938 |
Network contacts
91.92.251.159 94.156.64.5 91.92.254.21 94.156.64.90 91.92.251.153 91.92.255.79
Process list
| Name | Command line |
|---|---|
| windefragsvc.exe | |
| RegAsm.exe | |
| RegAsm.exe | |
| RegAsm.exe | |