84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432

Classification: Malicious

84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 8 antivirus detections
  • 0 IDS alerts
  • 14 processes observed
  • 0 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-07-27 14:45:04 2026-09-02 21:45:03 malicious-activity

Tags

windows-server-utility

Sample information

Filenames
84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432, muxrsxGRAKBwiv.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
5711824 bytes
MD5
543bb60eb637573be1afd717f8d38707
SHA-1
b39ffc53f6bfd136a9f5326a522b6709f1a37700
SHA-256
84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432
First indexed
2024-07-27 14:25:21
Last updated
2026-09-02 21:45:03

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
CrowdStrikewin/grayware_confidence_90% (D)
ESET-NOD32NSIS/Runner.W
KasperskyHEUR:Backdoor.Win32.Agent.gen
McAfeeArtemis!543BB60EB637
SkyhighArtemis!Trojan
ZoneAlarmHEUR:Backdoor.Win32.Agent.gen
huorongTrojan/Runner.az

DNS requests

zWjfqxpNSYvLaHiQsqX.zWjfqxpNSYvLaHiQsqX

Process list

NameCommand line
muxrsxGRAKBwiv.exe
cmd.exe/k move Rm Rm.cmd & Rm.cmd & exit
tasklist.exe
findstr.exefindstr /I "wrsa.exe opssvc.exe"
tasklist.exe
findstr.exefindstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe"
cmd.execmd /c md 649005
findstr.exefindstr /V "pizzaplaneslemongirl" Bestiality
cmd.execmd /c copy /b Saint + Helpful + Intel + Recommend + Drawn + Recently + Desert 649005\H
Extras.pif649005\Extras.pif 649005\H
timeout.exetimeout 5
cmd.execmd /c schtasks.exe /create /tn "Bath" /tr "wscript //B '%LOCALAPPDATA%\EduInno Dynamics\SophieCraft.js'" /sc minute /mo 5 /F
schtasks.exe/create /tn "Bath" /tr "wscript //B '%LOCALAPPDATA%\EduInno Dynamics\SophieCraft.js'" /sc minute /mo 5 /F
cmd.execmd /k echo [InternetShortcut] > "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\SophieCraft.url" & echo URL="%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\SophieCraft.url" & exit