84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432
Classification: Malicious
84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 8 antivirus detections
- 0 IDS alerts
- 14 processes observed
- 0 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-07-27 14:45:04 |
2026-09-02 21:45:03 |
malicious-activity
|
|
Tags
windows-server-utility
Sample information
- Filenames
- 84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432, muxrsxGRAKBwiv.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 5711824 bytes
- MD5
543bb60eb637573be1afd717f8d38707
- SHA-1
b39ffc53f6bfd136a9f5326a522b6709f1a37700
- SHA-256
84dbfed31b0adf1e953af9e94de8eff031d58a03a16851999c566b21ac7e0432
- First indexed
- 2024-07-27 14:25:21
- Last updated
- 2026-09-02 21:45:03
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/grayware_confidence_90% (D) |
| ESET-NOD32 | NSIS/Runner.W |
| Kaspersky | HEUR:Backdoor.Win32.Agent.gen |
| McAfee | Artemis!543BB60EB637 |
| Skyhigh | Artemis!Trojan |
| ZoneAlarm | HEUR:Backdoor.Win32.Agent.gen |
| huorong | Trojan/Runner.az |
Process list
| Name | Command line |
| muxrsxGRAKBwiv.exe | |
| cmd.exe | /k move Rm Rm.cmd & Rm.cmd & exit |
| tasklist.exe | |
| findstr.exe | findstr /I "wrsa.exe opssvc.exe" |
| tasklist.exe | |
| findstr.exe | findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" |
| cmd.exe | cmd /c md 649005 |
| findstr.exe | findstr /V "pizzaplaneslemongirl" Bestiality |
| cmd.exe | cmd /c copy /b Saint + Helpful + Intel + Recommend + Drawn + Recently + Desert 649005\H |
| Extras.pif | 649005\Extras.pif 649005\H |
| timeout.exe | timeout 5 |
| cmd.exe | cmd /c schtasks.exe /create /tn "Bath" /tr "wscript //B '%LOCALAPPDATA%\EduInno Dynamics\SophieCraft.js'" /sc minute /mo 5 /F |
| schtasks.exe | /create /tn "Bath" /tr "wscript //B '%LOCALAPPDATA%\EduInno Dynamics\SophieCraft.js'" /sc minute /mo 5 /F |
| cmd.exe | cmd /k echo [InternetShortcut] > "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\SophieCraft.url" & echo URL="%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\SophieCraft.url" & exit |