Classification: Malicious
win1.exe is a malicious file sample. Linked to Sombrat malware. Reported by 3 threat sources, last seen 2024-06-19. Detected by 53 antivirus engines.
Detection summary
- 53 antivirus detections
- 0 IDS alerts
- 1 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-06-19 06:00:04 |
2024-06-19 07:15:11 |
|
|
| SombRAT |
ThreatFox Abuse.ch |
2024-05-21 15:18:45 |
2024-05-23 15:20:23 |
|
S0615 SombRAT
|
| VenomRAT |
MalwareBazaar Abuse.ch |
2024-05-21 11:23:54 |
2024-05-21 11:23:54 |
malicious-activity
|
|
Sample information
- Filenames
- win1.exe, 26125c571d6225959832f37f9ac4629a
- File type
- application/x-dosexec
- Size
- 75264 bytes
- MD5
26125c571d6225959832f37f9ac4629a
- SHA-1
ed7af3c41eaab7b10a2639f06212bd6ee0db6899
- SHA-256
94fada921a79c422e6dbf75eeca7429690d75901b5ef982a44874971b38708a0
- First indexed
- 2024-05-21 12:21:13
- Last updated
- 2025-10-14 08:53:11
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Jalapeno.627 |
| APEX | Malicious |
| AVG | Win32:DropperX-gen [Drp] |
| AhnLab-V3 | Trojan/Win.AsyncRAT.R609293 |
| Arcabit | Trojan.Jalapeno.627 |
| Avast | Win32:DropperX-gen [Drp] |
| Avira | HEUR/AGEN.1365347 |
| BitDefender | Gen:Variant.Jalapeno.627 |
| BitDefenderTheta | Gen:NN.ZemsilF.36804.em0@aO!Vvbm |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.GenericFC.S30117478 |
| ClamAV | Win.Packed.Razy-9807129-0 |
| Cylance | unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.AsyncRATNET.1 |
| ESET-NOD32 | a variant of MSIL/AsyncRAT.A |
| Elastic | Windows.Generic.Threat |
| Emsisoft | Gen:Variant.Jalapeno.627 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1365347 |
| FireEye | Generic.mg.26125c571d622595 |
| Fortinet | MSIL/Agent.CTE!tr |
| GData | MSIL.Trojan-Stealer.Keylogger.BA |
| Google | Detected |
| Gridinsoft | Trojan.Win32.AsyncRAT.dd!n |
| Ikarus | Backdoor.Agent |
| Jiangmin | Trojan.MSIL.apaek |
| K7AntiVirus | Trojan ( 700000121 ) |
| K7GW | Trojan ( 700000121 ) |
| Kaspersky | HEUR:Trojan.MSIL.Agent.gen |
| Kingsoft | malware.kb.c.1000 |
| Lionic | Trojan.Win32.VenomRAT.4!c |
| MAX | malware (ai score=84) |
| Malwarebytes | Generic.Trojan.MSIL.DDS |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | GenericRXVS-NQ!26125C571D62 |
| McAfeeD | Real Protect-LS!26125C571D62 |
| MicroWorld-eScan | Gen:Variant.Jalapeno.627 |
| Microsoft | Trojan:MSIL/AsyncRAT.S!MTB |
| Panda | Trj/GdSda.A |
| Rising | Backdoor.AsyncRAT!1.C678 (CLASSIC) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.lm |
| Sophos | Troj/VenomRat-A |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.MSIL.Agent.16000593 |
| Trapmine | malicious.moderate.ml.score |
| TrendMicro | Backdoor.MSIL.ASYNCRAT.SMYXDHV |
| VIPRE | Gen:Variant.Jalapeno.627 |
| Varist | W32/Trojan.IML.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.B |
| ZoneAlarm | HEUR:Trojan.MSIL.Agent.gen |
| alibabacloud | Backdoor[rat]:MSIL/Agenttesla.Stub.LQL!MTB |
Process list
| Name | Command line |
| win1.exe | |