850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a
Classification: Malicious
850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 47 antivirus detections (65% detection ratio)
- 1 IDS alerts
- 12 processes observed
- 4 contacted hosts
- 3 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-11-19 08:15:03 |
2026-09-02 22:45:07 |
malicious-activity
|
|
| Downloader |
VM-Ray |
2023-11-19 10:20:47 |
2023-11-19 15:22:29 |
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2023-11-19 07:52:15 |
2023-11-19 07:52:15 |
malicious-activity
|
|
Sample information
- Filenames
- 850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a, 850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a.exe, file
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 1322170 bytes
- MD5
ed3216dea6e09a4d42badc5f5dea07f5
- SHA-1
b6babd8bdb053ef0a703da6174ec80c4e2917990
- SHA-256
850f8e6aa01636764734348d593573e28286601af1fe3a3c6cad39c83b25b28a
- First indexed
- 2023-11-19 07:54:53
- Last updated
- 2026-09-02 22:45:07
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectMalware |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Heur.Mint.Zard.45 |
| Skyhigh | BehavesLike.Win32.MultiPlug.th |
| ALYac | Gen:Heur.Mint.Zard.45 |
| Malwarebytes | Trojan.Agent |
| VIPRE | Gen:Heur.Mint.Zard.45 |
| K7AntiVirus | Trojan ( 005956e81 ) |
| K7GW | Trojan ( 005956e81 ) |
| Cybereason | malicious.bdb053 |
| Arcabit | Trojan.Mint.Zard.45 |
| Symantec | ML.Attribute.HighConfidence |
| tehtris | Generic.Malware |
| ESET-NOD32 | a variant of Win32/Agent.ADVG |
| Cynet | Malicious (score: 100) |
| APEX | Malicious |
| ClamAV | Win.Malware.Doina-10010822-0 |
| Kaspersky | HEUR:Trojan-PSW.Win32.RisePro.gen |
| BitDefender | Gen:Heur.Mint.Zard.45 |
| NANO-Antivirus | Trojan.Win32.RisePro.kdpgzw |
| Avast | Win32:BackdoorX-gen [Trj] |
| Tencent | Malware.Win32.Gencirc.11b8c874 |
| F-Secure | Trojan.TR/Agent.klsuq |
| DrWeb | Trojan.MulDrop24.16091 |
| Trapmine | suspicious.low.ml.score |
| FireEye | Generic.mg.ed3216dea6e09a4d |
| Emsisoft | Gen:Heur.Mint.Zard.45 (B) |
| SentinelOne | Static AI - Suspicious PE |
| Avira | TR/Agent.klsuq |
| MAX | malware (ai score=82) |
| Antiy-AVL | GrayWare/Win32.Wacapew |
| Kingsoft | malware.kb.a.850 |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Microsoft | Program:Win32/Wacapew.C!ml |
| ZoneAlarm | HEUR:Trojan-PSW.Win32.RisePro.gen |
| GData | Gen:Heur.Mint.Zard.45 |
| Google | Detected |
| AhnLab-V3 | Trojan/Win.Generic.R621897 |
| VBA32 | BScope.TrojanPSW.RisePro |
| Panda | Trj/Genetic.gen |
| Rising | Downloader.Agent!1.D93C (CLASSIC) |
| Yandex | Trojan.Agent!EEdX1zPIc9s |
| Fortinet | W32/Agent.ADVG!tr |
| BitDefenderTheta | Gen:NN.ZexaF.36792.qv1@auXDyqpk |
| AVG | Win32:BackdoorX-gen [Trj] |
| DeepInstinct | MALICIOUS |
| CrowdStrike | win/malicious_confidence_60% (D) |
Process list
| Name | Command line |
| file.exe | |
| schtasks.exe | schtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 HR" /sc HOURLY /rl HIGHEST |
| schtasks.exe | schtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 LG" /sc ONLOGON /rl HIGHEST |
| WerFault.exe | -u -p 3312 -s 1280 |
| OfficeTrackerNMP131.exe | |
| OfficeTrackerNMP131.exe | |
| WerFault.exe | -u -p 3888 -s 976 |
| WerFault.exe | -u -p 920 -s 988 |
| MaxLoonaFest131.exe | |
| WerFault.exe | -u -p 1660 -s 984 |
| FANBooster131.exe | |
| WerFault.exe | -u -p 1356 -s 992 |