850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a

Classification: Malicious

850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.

Detection summary

  • 47 antivirus detections (65% detection ratio)
  • 1 IDS alerts
  • 12 processes observed
  • 4 contacted hosts
  • 3 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-19 08:15:03 2026-09-02 22:45:07 malicious-activity
Downloader VM-Ray 2023-11-19 10:20:47 2023-11-19 15:22:29
Generic.Malware MalwareBazaar Abuse.ch 2023-11-19 07:52:15 2023-11-19 07:52:15 malicious-activity

Sample information

Filenames
850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a, 850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a.exe, file
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1322170 bytes
MD5
ed3216dea6e09a4d42badc5f5dea07f5
SHA-1
b6babd8bdb053ef0a703da6174ec80c4e2917990
SHA-256
850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a
First indexed
2023-11-19 07:54:53
Last updated
2026-09-02 22:45:07

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.45
SkyhighBehavesLike.Win32.MultiPlug.th
ALYacGen:Heur.Mint.Zard.45
MalwarebytesTrojan.Agent
VIPREGen:Heur.Mint.Zard.45
K7AntiVirusTrojan ( 005956e81 )
K7GWTrojan ( 005956e81 )
Cybereasonmalicious.bdb053
ArcabitTrojan.Mint.Zard.45
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.ADVG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Doina-10010822-0
KasperskyHEUR:Trojan-PSW.Win32.RisePro.gen
BitDefenderGen:Heur.Mint.Zard.45
NANO-AntivirusTrojan.Win32.RisePro.kdpgzw
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.11b8c874
F-SecureTrojan.TR/Agent.klsuq
DrWebTrojan.MulDrop24.16091
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.ed3216dea6e09a4d
EmsisoftGen:Heur.Mint.Zard.45 (B)
SentinelOneStatic AI - Suspicious PE
AviraTR/Agent.klsuq
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Wacapew
Kingsoftmalware.kb.a.850
GridinsoftTrojan.Win32.Agent.oa!s1
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmHEUR:Trojan-PSW.Win32.RisePro.gen
GDataGen:Heur.Mint.Zard.45
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R621897
VBA32BScope.TrojanPSW.RisePro
PandaTrj/Genetic.gen
RisingDownloader.Agent!1.D93C (CLASSIC)
YandexTrojan.Agent!EEdX1zPIc9s
FortinetW32/Agent.ADVG!tr
BitDefenderThetaGen:NN.ZexaF.36792.qv1@auXDyqpk
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

Network contacts

194.49.94.152 34.117.59.81 104.26.5.15 104.18.146.235

DNS requests

db-ip.com ipinfo.io www.maxmind.com

Process list

NameCommand line
file.exe
schtasks.exeschtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 HR" /sc HOURLY /rl HIGHEST
schtasks.exeschtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 LG" /sc ONLOGON /rl HIGHEST
WerFault.exe-u -p 3312 -s 1280
OfficeTrackerNMP131.exe
OfficeTrackerNMP131.exe
WerFault.exe-u -p 3888 -s 976
WerFault.exe-u -p 920 -s 988
MaxLoonaFest131.exe
WerFault.exe-u -p 1660 -s 984
FANBooster131.exe
WerFault.exe-u -p 1356 -s 992