869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e

Classification: Malicious

869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e is a malicious file sample. Reported by 1 threat source, last seen 2026-09-03.

Detection summary

  • 42 antivirus detections
  • 1 IDS alerts
  • 18 processes observed
  • 17 contacted hosts
  • 19 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-02-15 20:15:04 2026-09-03 00:45:06 malicious-activity

Tags

downloader evasive

Sample information

Filenames
869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e, file
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
2357760 bytes
MD5
cc05fe7f90334c2dcc74f652a37612e8
SHA-1
a57f4307fe317c1a11d468de8f48eaa6217be63b
SHA-256
869053664dd8c21379bcce2b6c8b35a301f1e5160e5ada0cb86ed349e9da487e
First indexed
2024-02-15 19:55:43
Last updated
2026-09-03 00:45:06

Antivirus detections

EngineDetection
ALYacGen:Variant.Zusy.536670
AVGWin32:TrojanX-gen [Trj]
AhnLab-V3Trojan/Win.TrojanX-gen.R635050
ArcabitTrojan.Zusy.D8305E
AvastWin32:TrojanX-gen [Trj]
BitDefenderGen:Variant.Zusy.536670
BitDefenderThetaGen:NN.ZexaF.36744.pE0aauzGk7hk
BkavW32.AIDetectMalware
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.7fe317
Cylanceunsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32a variant of Win32/Packed.Themida.HZB
Elasticmalicious (high confidence)
EmsisoftGen:Variant.Zusy.536670 (B)
FireEyeGeneric.mg.cc05fe7f90334c2d
FortinetW32/Agent.BFB5!tr
GDataGen:Variant.Zusy.536670
GoogleDetected
GridinsoftTrojan.Heur!.038120A1
K7AntiVirusTrojan ( 00585f781 )
K7GWTrojan ( 00585f781 )
KasperskyVHO:Trojan-PSW.Win32.RisePro.gen
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack
MaxSecureTrojan.Malware.300983.susgen
MicroWorld-eScanGen:Variant.Zusy.536670
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Rising[email protected] (RDML:qsOjlcQCWm8tAU10PjHzhg)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.vc
SophosMal/RisePro-A
SymantecML.Attribute.HighConfidence
Trapminemalicious.high.ml.score
VBA32TScope.Malware-Cryptor.SB
VIPREGen:Variant.Zusy.536670
VaristW32/Convagent.FC.gen!Eldorado
ZoneAlarmVHO:Trojan-PSW.Win32.RisePro.gen
ZonerProbably Heur.ExeHeaderL
tehtrisGeneric.Malware

Network contacts

193.233.132.62 34.117.186.192 104.26.5.15 172.67.75.166 185.215.113.46 142.250.189.206 142.251.46.163 142.250.189.163 157.240.11.35 104.18.146.235 157.240.22.35 157.240.22.25 142.251.2.84 142.250.189.227 142.250.191.35 142.251.46.228 142.251.46.174

DNS requests

accounts.google.com accounts.youtube.com crls.pki.goog db-ip.com facebook.com fbcdn.net fbsbx.com fonts.gstatic.com ipinfo.io m.facebook.com ocsp.digicert.com ocsp.pki.goog scontent.xx.fbcdn.net static.xx.fbcdn.net www.facebook.com www.google.com www.gstatic.com www.maxmind.com www.youtube.com

Process list

NameCommand line
file.exe
schtasks.exeschtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
schtasks.exeschtasks /create /f /RU "%OSUSER%" /tr "%ALLUSERSPROFILE%\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
WerFault.exe-u -p 5564 -s 1256
MPGPH131.exe
nbtIZ9DFJzKV_GdFxw6Q.exe
iexplore.exehttps://www.youtube.com/
iexplore.exeSCODEF:5260 CREDAT:275457 /prefetch:2
iexplore.exeSCODEF:5260 CREDAT:4142086 /prefetch:2
iexplore.exeSCODEF:5260 CREDAT:3421188 /prefetch:2
FwlA79gunq9nP85qrzhW.exe
nzOyY6bEcoj8F4ahJltg.exe
marczYCXrAMmd7ZzmPD_.exe
NzPTsUzXDEe_0tJi5TWA.exe
MPGPH131.exe
WerFault.exe-u -p 4024 -s 452
RageMP131.exe
MPGPH131.exe