eef60e851002da7ddb2ffa04e97676e0.exe
Classification: Malicious
eef60e851002da7ddb2ffa04e97676e0.exe is a malicious file sample. Linked to Remcos malware. Reported by 2 threat sources, last seen 2025-08-26.
Detection summary
- 55 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: REMCOS (S0332)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Remcos | ThreatFox Abuse.ch | 2025-08-24 17:51:35 | 2025-08-26 17:18:46 | S0332 Remcos | |
| RemcosRAT | MalwareBazaar Abuse.ch | 2025-08-24 14:48:11 | 2025-08-24 14:48:11 | malicious-activity |
Tags
win.remcos remcosrat remvio socmerSample information
- Filenames
- eef60e851002da7ddb2ffa04e97676e0.exe
- File type
- application/x-dosexec
- MD5
eef60e851002da7ddb2ffa04e97676e0- SHA-1
2b5e18364749661733d1f77766b80117e245e0bb- SHA-256
9f5e1c5ea05a6275d90bac217e0fd8061c7e87e174b69bcdd26625e873c7579b- First indexed
- 2025-08-24 16:19:01
- Last updated
- 2026-09-03 00:15:32
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.GenericKD.77153011 |
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Cryp] |
| AhnLab-V3 | Trojan/Win.Kryptik.C5790626 |
| Alibaba | Trojan:MSIL/Kryptik.7e6dd2ca |
| Arcabit | Trojan.Generic.D49942F3 |
| Avast | Win32:MalwareX-gen [Cryp] |
| Avira | TR/Kryptik.lsgyf |
| BitDefender | Trojan.GenericKD.77153011 |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Ghanarava.17576109027676e0 |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.PackedNET.3393 |
| ESET-NOD32 | a variant of MSIL/Kryptik.AOFH |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.GenericKD.77153011 (B) |
| F-Secure | Trojan.TR/Kryptik.lsgyf |
| Fortinet | MSIL/Formbook.D5D0!tr.spy |
| GData | Trojan.GenericKD.77153011 |
| Detected | |
| Ikarus | Trojan.MSIL.Inject |
| K7AntiVirus | Trojan ( 005cc7f51 ) |
| K7GW | Trojan ( 005cc7f51 ) |
| Kaspersky | HEUR:Backdoor.MSIL.Remcos.gen |
| Kingsoft | malware.kb.c.918 |
| Lionic | Trojan.Win32.Remcos.m!c |
| Malwarebytes | Trojan.MalPack |
| MaxSecure | Trojan.Malware.423943036.susgen |
| McAfeeD | ti!9F5E1C5EA05A |
| MicroWorld-eScan | Trojan.GenericKD.77153011 |
| Microsoft | Trojan:MSIL/XWorm.SPZT!MTB |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:/jXX2QORBwVf+9zuF4lnWQ) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.cc |
| Sophos | Troj/Krypt-AQM |
| Symantec | MSIL.Packed.19 |
| Tencent | Trojan.Msil.Kryptik.16002193 |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | Artemis!EEF60E851002 |
| TrendMicro | Backdoor.Win32.REMCOS.YXFHXZ |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9n |
| VIPRE | Trojan.GenericKD.77153011 |
| Varist | W32/MSIL_Kryptik.MJN.gen!Eldorado |
| ViRobot | Trojan.Win.Z.Kryptik.920576.A |
| VirIT | Trojan.Win32.MSIL.IQB |
| Zillya | Trojan.Kryptik.Win32.5475541 |
| ZoneAlarm | Troj/Krypt-AQM |
| alibabacloud | Backdoor:MSIL/XWorm.SXPK3DGW |
| huorong | TrojanSpy/MSIL.Formbook.az |