vwExeNX.exe
Classification: Malicious
vwExeNX.exe is a malicious file sample. Linked to Crossrat, Remcos malware. Reported by 4 threat sources, last seen 2026-06-24.
Detection summary
- 0 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 1 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: CROSSRAT (S0235) REMCOS (S0332)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Remcos | Triage | 2026-06-18 12:49:11 | 2026-06-24 17:15:03 | malicious-activity | S0332 Remcos |
| CrossRAT | ThreatFox Abuse.ch | 2026-06-18 16:49:19 | 2026-06-18 17:25:03 | S0235 CrossRAT | |
| Generic Malware | Hybrid-Analysis | 2026-06-18 13:45:05 | 2026-06-18 13:45:05 | malicious-activity | |
| RemcosRAT | MalwareBazaar Abuse.ch | 2026-06-18 12:47:02 | 2026-06-18 12:47:02 | malicious-activity |
Tags
remcos slikfix discovery execution persistence rat suspicious jar.crossrat trupto ransomwareSample information
- Filenames
- vwExeNX.exe, 9f844a78cc2cd8d8a426f050a3efe319930f723eb10be231de1c1f1600e82127.bin, JUNE18TH-PO-3520398763520.bat, _9f844a78cc2cd8d8a426f050a3efe319930f723eb10be231de1c1f1600e82127.exe
- File type
- PE32 executable for MS Windows 6.00 (GUI), Intel i ...
- MD5
52c1005cff76c7c6f4b21a231ad6e130- SHA-1
fceb71b23ead80d609b2523936fe925e6c1fcb24- SHA-256
9f844a78cc2cd8d8a426f050a3efe319930f723eb10be231de1c1f1600e82127- First indexed
- 2026-06-18 12:47:02
- Last updated
- 2026-07-18 22:21:11