869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e
Classification: Malicious
869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e is a malicious file sample. Reported by 1 threat source, last seen 2026-09-03.
Detection summary
- 42 antivirus detections
- 1 IDS alerts
- 18 processes observed
- 17 contacted hosts
- 19 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-02-15 20:15:04 | 2026-09-03 00:45:06 | malicious-activity |
Tags
downloader evasiveSample information
- Filenames
- 869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e, file
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 2357760 bytes
- MD5
cc05fe7f90334c2dcc74f652a37612e8- SHA-1
a57f4307fe317c1a11d468de8f48eaa6217be63b- SHA-256
869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e- First indexed
- 2024-02-15 19:55:43
- Last updated
- 2026-09-03 00:45:06
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.Zusy.536670 |
| AVG | Win32:TrojanX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.TrojanX-gen.R635050 |
| Arcabit | Trojan.Zusy.D8305E |
| Avast | Win32:TrojanX-gen [Trj] |
| BitDefender | Gen:Variant.Zusy.536670 |
| BitDefenderTheta | Gen:NN.ZexaF.36744.pE0aauzGk7hk |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cybereason | malicious.7fe317 |
| Cylance | unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of Win32/Packed.Themida.HZB |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Zusy.536670 (B) |
| FireEye | Generic.mg.cc05fe7f90334c2d |
| Fortinet | W32/Agent.BFB5!tr |
| GData | Gen:Variant.Zusy.536670 |
| Detected | |
| Gridinsoft | Trojan.Heur!.038120A1 |
| K7AntiVirus | Trojan ( 00585f781 ) |
| K7GW | Trojan ( 00585f781 ) |
| Kaspersky | VHO:Trojan-PSW.Win32.RisePro.gen |
| MAX | malware (ai score=86) |
| Malwarebytes | Trojan.MalPack |
| MaxSecure | Trojan.Malware.300983.susgen |
| MicroWorld-eScan | Gen:Variant.Zusy.536670 |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| Rising | [email protected] (RDML:qsOjlcQCWm8tAU10PjHzhg) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.vc |
| Sophos | Mal/RisePro-A |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | malicious.high.ml.score |
| VBA32 | TScope.Malware-Cryptor.SB |
| VIPRE | Gen:Variant.Zusy.536670 |
| Varist | W32/Convagent.FC.gen!Eldorado |
| ZoneAlarm | VHO:Trojan-PSW.Win32.RisePro.gen |
| Zoner | Probably Heur.ExeHeaderL |
| tehtris | Generic.Malware |
Network contacts
193.233.132.62 34.117.186.192 104.26.5.15 172.67.75.166 185.215.113.46 142.250.189.206 142.251.46.163 142.250.189.163 157.240.11.35 104.18.146.235 157.240.22.35 157.240.22.25 142.251.2.84 142.250.189.227 142.250.191.35 142.251.46.228 142.251.46.174
DNS requests
accounts.google.com accounts.youtube.com crls.pki.goog db-ip.com facebook.com fbcdn.net fbsbx.com fonts.gstatic.com ipinfo.io m.facebook.com ocsp.digicert.com ocsp.pki.goog scontent.xx.fbcdn.net static.xx.fbcdn.net www.facebook.com www.google.com www.gstatic.com www.maxmind.com www.youtube.com
Process list
| Name | Command line |
|---|---|
| file.exe | |
| schtasks.exe | schtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST |
| schtasks.exe | schtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST |
| WerFault.exe | -u -p 5564 -s 1256 |
| MPGPH131.exe | |
| nbtIZ9DFJzKV_GdFxw6Q.exe | |
| iexplore.exe | https://www.youtube.com/ |
| iexplore.exe | SCODEF:5260 CREDAT:275457 /prefetch:2 |
| iexplore.exe | SCODEF:5260 CREDAT:4142086 /prefetch:2 |
| iexplore.exe | SCODEF:5260 CREDAT:3421188 /prefetch:2 |
| FwlA79gunq9nP85qrzhW.exe | |
| nzOyY6bEcoj8F4ahJltg.exe | |
| marczYCXrAMmd7ZzmPD_.exe | |
| NzPTsUzXDEe_0tJi5TWA.exe | |
| MPGPH131.exe | |
| WerFault.exe | -u -p 4024 -s 452 |
| RageMP131.exe | |
| MPGPH131.exe | |