84d011e18cec6190e2c79b270e9d2d575bfaa63998f50d13d3f9da147f49b799
Classification: Malicious
84d011e18cec6190e2c79b270e9d2d575bfaa63998f50d13d3f9da147f49b799 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 77 antivirus detections
- 1 IDS alerts
- 79 processes observed
- 5 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-01-29 16:30:03 |
2026-09-02 21:45:04 |
malicious-activity
|
|
Tags
evasive
windows-server-utility
Sample information
- Filenames
- 84d011e18cec6190e2c79b270e9d2d575bfaa63998f50d13d3f9da147f49b799, file
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 7656448 bytes
- MD5
6af4b8b8c8399fca6798e3f2d7df9af5
- SHA-1
7cc85c826668d6f09b43ea9358ecdc57fecf398b
- SHA-256
84d011e18cec6190e2c79b270e9d2d575bfaa63998f50d13d3f9da147f49b799
- First indexed
- 2024-01-29 16:14:06
- Last updated
- 2026-09-02 21:45:04
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | Win32:DropperX-gen [Drp] |
| AhnLab-V3 | Malware/Win.Generic.C4478643 |
| Arcabit | IL:Trojan.MSILZilla.D26A3 |
| Avast | Win32:DropperX-gen [Drp] |
| Avira | HEUR/AGEN.1365025 |
| BitDefender | IL:Trojan.MSILZilla.9891 |
| BitDefenderTheta | Gen:NN.ZemsilF.36680.@p0@aSAZrBc |
| Bkav | W32.AIDetectMalware.CS |
| ClamAV | Win.Packed.Msilzilla-10018301-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cybereason | malicious.26668d |
| Cylance | unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDropNET.43 |
| ESET-NOD32 | a variant of MSIL/Agent.UZA |
| Elastic | malicious (high confidence) |
| Emsisoft | IL:Trojan.MSILZilla.9891 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1365025 |
| FireEye | Generic.mg.6af4b8b8c8399fca |
| Fortinet | MSIL/GenKryptik.FFMZ!tr |
| GData | IL:Trojan.MSILZilla.9891 |
| Google | Detected |
| Ikarus | Trojan.MSIL.Krypt |
| K7AntiVirus | Ransomware ( 005a8b921 ) |
| K7GW | Ransomware ( 005a8b921 ) |
| Kaspersky | HEUR:Trojan-Downloader.MSIL.ShortLoader.gen |
| Kingsoft | malware.kb.c.1000 |
| MAX | malware (ai score=84) |
| Malwarebytes | Trojan.Crypt.MSIL.Generic |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | GenericRXOO-YN!6AF4B8B8C839 |
| MicroWorld-eScan | IL:Trojan.MSILZilla.9891 |
| Microsoft | Trojan:MSIL/Mokes.B!MTB |
| Panda | Trj/GdSda.A |
| Rising | Trojan.AntiVM!1.CF63 (CLASSIC) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.wc |
| Sophos | Troj/ILAgent-I |
| Symantec | ML.Attribute.HighConfidence |
| VBA32 | Trojan.MSIL.Injector.gen |
| VIPRE | IL:Trojan.MSILZilla.9891 |
| Varist | W32/MSIL_Kryptik.FFY.gen!Eldorado |
| ZoneAlarm | HEUR:Trojan-Downloader.MSIL.ShortLoader.gen |
| ALYac | Gen:Variant.Jalapeno.293 |
| AVG | Win32:MalwareX-gen [Drp] |
| Alibaba | TrojanDownloader:MSIL/Mokes.79a2e42f |
| Antiy-AVL | Trojan/Win32.Agent |
| Arcabit | Trojan.Jalapeno.293 |
| Avast | Win32:MalwareX-gen [Drp] |
| BitDefender | Gen:Variant.Jalapeno.293 |
| Bkav | W32.Common.D693AFB0 |
| CAT-QuickHeal | Trojan.Ghanarava.1727030270df9af5 |
| CTX | exe.trojan.msil |
| Cylance | Unsafe |
| Emsisoft | Gen:Variant.Jalapeno.293 (B) |
| GData | Gen:Variant.Jalapeno.293 |
| Gridinsoft | Ransom.Win32.STOP.dg!n |
| Jiangmin | TrojanDownloader.MSIL.aqbx |
| Kingsoft | MSIL.Trojan-Downloader.ShortLoader.gen |
| Lionic | Trojan.Win32.ShortLoader.a!c |
| McAfeeD | Real Protect-LS!6AF4B8B8C839 |
| MicroWorld-eScan | Gen:Variant.Jalapeno.293 |
| NANO-Antivirus | Trojan.Win32.ShortLoader.khyxhv |
| Paloalto | generic.ml |
| Tencent | Malware.Win32.Gencirc.13ff46c4 |
| Trapmine | malicious.high.ml.score |
| TrellixENS | GenericRXOO-YN!6AF4B8B8C839 |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9j |
| VIPRE | Gen:Variant.Jalapeno.293 |
| Xcitium | Malware@#edov5qw52or6 |
| Zillya | Trojan.Agent.Win32.3854582 |
| ZoneAlarm | Troj/ILAgent-I |
| alibabacloud | Trojan:MSIL/Mokes.B!MTB |
| huorong | VirTool/MSIL.Obfuscator.su |
Process list
| Name | Command line |
| file.exe | |
| InstallSetup9.exe | |
| BroomSetup.exe | |
| cmd.exe | %WINDIR%\system32\cmd.exe /c ""%APPDATA%\Temp\Task.bat" " |
| chcp.com | chcp 1251 |
| schtasks.exe | schtasks /create /tn "MalayamaraUpdate" /tr "'%TEMP%\Updater.exe'" /sc minute /mo 30 /F |
| nsd67A7.tmp | |
| toolspub1.exe | |
| WerFault.exe | -u -p 1344 -s 556 |
| 31839b57a4f11171d6abc8bbc4451ee4.exe | |
| WerFault.exe | -u -p 4788 -s 448 |
| WerFault.exe | -u -p 4788 -s 468 |
| WerFault.exe | -u -p 4788 -s 456 |
| WerFault.exe | -u -p 4788 -s 568 |
| WerFault.exe | -u -p 4788 -s 676 |
| WerFault.exe | -u -p 4788 -s 684 |
| WerFault.exe | -u -p 4788 -s 668 |
| WerFault.exe | -u -p 4788 -s 692 |
| WerFault.exe | -u -p 4788 -s 728 |
| WerFault.exe | -u -p 4788 -s 736 |
| WerFault.exe | -u -p 4788 -s 820 |
| WerFault.exe | -u -p 4788 -s 708 |
| WerFault.exe | -u -p 4788 -s 860 |
| WerFault.exe | -u -p 4788 -s 880 |
| WerFault.exe | -u -p 4788 -s 876 |
| WerFault.exe | -u -p 4788 -s 808 |
| WerFault.exe | -u -p 4788 -s 896 |
| WerFault.exe | -u -p 4788 -s 876 |
| WerFault.exe | -u -p 4788 -s 836 |
| WerFault.exe | -u -p 4788 -s 884 |