874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1
Classification: Malicious
874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1 is a malicious file sample. Linked to Xloader malware. Detected by 25 antivirus engines.
Detection summary
- 25 antivirus detections
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-09-26 12:00:04 |
2026-09-03 01:45:06 |
malicious-activity
|
|
| Formbook |
ThreatFox Abuse.ch |
2024-09-26 19:38:53 |
2024-09-28 19:20:22 |
|
S1207 XLoader
|
| Formbook |
MalwareBazaar Abuse.ch |
2024-09-26 11:43:56 |
2024-09-26 11:43:56 |
malicious-activity
|
S1207 XLoader
|
Tags
win.formbook
win.xloader
Sample information
- Filenames
- 874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1, DOC_PDF.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 611328 bytes
- MD5
debff2e29172e4c6b07a62a5d7b8a6b4
- SHA-1
6e2073a1f0dbd338f0a8673f35b8628581fac402
- SHA-256
874c6faee7e17445012c0f573c29dde997a71cc86e15fc3152a22365cf83bdf1
- First indexed
- 2024-09-26 11:43:46
- Last updated
- 2026-09-03 01:45:06
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | FileRepMalware [Pws] |
| Avast | FileRepMalware [Pws] |
| Bkav | W32.AIDetectMalware.CS |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| Fortinet | MSIL/Kryptik.XSWP!tr |
| Google | Detected |
| Ikarus | Win32.Outbreak |
| Kingsoft | malware.kb.c.723 |
| Malwarebytes | Malware.AI.1612201208 |
| MaxSecure | Trojan.Malware.300983.susgen |
| Microsoft | Trojan:Win32/Leonem |
| Paloalto | generic.ml |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:Vl54ef9lVk6wVd6Tj+Nn3g) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.hc |
| Symantec | Scr.Malcode!gdn34 |
| Trapmine | suspicious.low.ml.score |
| Varist | W32/MSIL_Kryptik.KPV.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| huorong | HEUR:TrojanSpy/MSIL.AgentTesla.sl |
Process list
| Name | Command line |
| DOC_PDF.exe | |
| DOC_PDF.exe | |