84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b

Classification: Malicious

84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 56 antivirus detections
  • 2 IDS alerts
  • 5 processes observed
  • 3 contacted hosts
  • 2 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-06-11 09:30:05 2026-09-02 22:45:08 malicious-activity

Tags

evasive infostealer windows-server-utility

Sample information

Filenames
84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
730624 bytes
MD5
593bb72286c1c2ce5c2456c7d9585a80
SHA-1
cb9bf63f9005d5b4f1bcbcf3efead399a1c960a7
SHA-256
84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b
First indexed
2025-06-11 09:17:16
Last updated
2026-09-02 22:45:08

Antivirus detections

EngineDetection
ALYacTrojan.GenericKDZ.105314
APEXMalicious
AVGWin32:MalwareX-gen [Pws]
AhnLab-V3Trojan/Win.FormBook.C5582647
AlibabaTrojan:MSIL/Formbook.54133de1
ArcabitTrojan.Generic.D19B62
AvastWin32:MalwareX-gen [Pws]
AviraHEUR/AGEN.1370955
BitDefenderTrojan.GenericKDZ.105314
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.Ghanarava.1727725524585a80
CTXexe.trojan.msil
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebTrojan.PWS.Agensla.48
ESET-NOD32MSIL/Spy.AgentTesla.I
Elasticmalicious (high confidence)
EmsisoftTrojan.GenericKDZ.105314 (B)
F-SecureHeuristic.HEUR/AGEN.1370955
FortinetMSIL/Remcos.GWMJE!tr
GDataTrojan.GenericKDZ.105314
GoogleDetected
IkarusTrojan.MSIL.Crypt
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
KasperskyHEUR:Trojan.MSIL.Taskun.gen
KingsoftMSIL.Trojan.Taskun.gen
LionicTrojan.Win32.AgentTesla.4!c
MalwarebytesMalware.AI.1652489147
McAfeeDti!84F0A1001A60
MicroWorld-eScanTrojan.GenericKDZ.105314
MicrosoftTrojan:MSIL/Formbook.AMBF!MTB
NANO-AntivirusTrojan.Win32.Agensla.kilsnf
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingMalware.Obfus/[email protected] (RDM.MSIL2:rSu6smT6FuWhN5G4a4jvQw)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.bc
SophosTroj/Krypt-AFQ
SymantecScr.Malcode!gdn33
TencentMalware.Win32.Gencirc.13ffc0df
Trapminemalicious.moderate.ml.score
TrellixENSArtemis!593BB72286C1
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9Z
VBA32TrojanLoader.MSIL.DaVinci.Heur
VIPRETrojan.GenericKDZ.105314
VaristW32/MSIL_Kryptik.KMV.gen!Eldorado
ViRobotTrojan.Win.Z.Taskun.730624
VirITTrojan.Win32.MSIL_Heur.A
XcitiumMalware@#1oc15f8bn0pix
ZillyaTrojan.AgentTesla.Win32.8054
ZoneAlarmTroj/Krypt-AFQ
alibabacloudTrojan[spy]:MSIL/AgentTesla.I
huorongTrojanSpy/MSIL.AgentTesla.mq

Network contacts

104.26.13.205 89.39.7.13 104.26.12.205

DNS requests

api.ipify.org mail.triorentacar.ro

Process list

NameCommand line
84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b.exe
powershell.exeAdd-MpPreference -ExclusionPath "C:\84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b.exe"
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\nNdsLvHyWi.exe"
schtasks.exe/Create /TN "Updates\nNdsLvHyWi" /XML "%TEMP%\tmp687C.tmp"
84f0a1001a606072b86d8eca2c4d9ccefc71c38ff71d0aaa2f4ae003f802917b.exe