a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe

Classification: Malicious

a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe is a malicious file sample. Reported by 1 threat source, last seen 2019-06-06.

Detection summary

  • 92 antivirus detections (87% detection ratio)
  • 1 IDS alerts
  • 4 processes observed
  • 4 contacted hosts
  • 32 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Backdoor.Shiz Hybrid-Analysis 2019-06-06 11:45:15 2019-06-06 11:45:15

Tags

banker shifu shiz

Sample information

Filenames
a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
260096 bytes
MD5
f872e8cfca55310524e13c4401ea6478
SHA-1
614b228e5bac06aa25a0e4a31fb42538a1923d89
SHA-256
a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac
First indexed
2019-06-06 11:45:15
Last updated
2026-01-15 01:14:02

Antivirus detections

EngineDetection
BkavW32.Clod423.Trojan.3444
MicroWorld-eScanGen:Heur.Zybut.1
nProtectTrojan/W32.Agent.260096.EB
CAT-QuickHeal(Suspicious) - DNAScan
McAfeeArtemis!F872E8CFCA55
VIPRETrojan.Win32.EncPk.acr.gen (v)
K7AntiVirusSpyware ( 0040f2501 )
K7GWSpyware ( 0040f2501 )
TheHackerBackdoor/Shiz.aqva
AgnitumBackdoor.Shiz!sF1pxQKpkUc
F-ProtW32/Shiz.QY
SymantecInfostealer.Shiz!gen
NormanSuspicious_Gen4.EMEG
TotalDefenseWin32/Shiz.P!generic
TrendMicro-HouseCallTROJ_RUNLOAD.USB13VC
AvastWin32:MalOb-JH [Cryp]
ClamAVTrojan.Shiz-138
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Zybut.1
NANO-AntivirusTrojan.Win32.Agent2.pmsux
ViRobotBackdoor.Win32.A.Shiz.260096.A
TencentWin32.Backdoor.Shiz.Edxa
Ad-AwareGen:Heur.Zybut.1
EmsisoftGen:Heur.Zybut.1 (B)
ComodoBackdoor.Win32.Shiz.ASFK
F-SecureGen:Heur.Zybut.1
DrWebTrojan.Packed.20771
ZillyaTrojan.Shiz.Win32.402
AntiVirTR/Crypt.ZPACK.Gen
TrendMicroTROJ_RUNLOAD.USB13VC
McAfee-GW-EditionHeuristic.LooksLike.Win32.SuspiciousPE.C!87
SophosMal/EncPk-ACR
JiangminBackdoor/Shiz.btw
Antiy-AVLTrojan[Backdoor]/Win32.Shiz
KingsoftWin32.Hack.Shiz.(kcloud)
MicrosoftBackdoor:Win32/Simda
SUPERAntiSpywareTrojan.Agent/Gen-Falprod
AhnLab-V3Backdoor/Win32.Shiz
GDataGen:Heur.Zybut.1
CommtouchW32/Shiz.GVIA-4223
VBA32Backdoor.Shiz
PandaTrj/Genetic.gen
ESET-NOD32Win32/Spy.Shiz.NCF
IkarusBackdoor.Win32.Shiz
FortinetW32/Shiz.YWP!tr.bdr
AVGBackDoor.Generic15.AGK
Qihoo-360HEUR/Malware.QVM19.Gen
APEXMalicious
AVGWin32:MalOb-JH [Cryp]
AhnLab-V3Backdoor/Win32.Shiz.R20029
AlibabaTrojanSpy:Win32/Simda.de16dae5
ArcabitTrojan.Zybut.1
AviraTR/Crypt.ZPACK.Gen
BkavW32.AIDetectMalware
CAT-QuickHealBackdoor.SimdaCS.S15594
CTXexe.unknown.zybut
ClamAVWin.Trojan.Shiz-151
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
Elasticmalicious (high confidence)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
FireEyeGeneric.mg.f872e8cfca553105
GoogleDetected
JiangminBackdoor/Shiz.bnr
K7AntiVirusSpyware ( 005068aa1 )
K7GWSpyware ( 005068aa1 )
KingsoftWin32.Trojan.Generic.a
LionicTrojan.Win32.Generic.mBMA
MalwarebytesMalware.AI.4065397674
MaxSecureTrojan.Malware.7164915.susgen
McAfeeGenericRXCM-PI!F872E8CFCA55
NANO-AntivirusTrojan.Win32.Agent.pmsux
Paloaltogeneric.ml
RisingBackdoor.Simda!8.2D9 (TFE:1:ZDPV1YCHhwV)
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.dc
SymantecML.Attribute.HighConfidence
TencentMalware.Win32.Gencirc.10b15f32
Trapminemalicious.high.ml.score
VIPREGen:Heur.Zybut.1
VaristW32/Shiz.GVIA-4223
VirITBackdoor.Win32.Generic.AGK
WebrootW32.Trojan.Gen
XcitiumBackdoor.Win32.Shiz.ASFK@4n04z5
YandexBackdoor.Shiz!sF1pxQKpkUc
ZoneAlarmMal/EncPk-ACR
alibabacloudTrojan[spy]:Win/Shiz.NCF
huorongHEUR:VirTool/Obfuscator.gen!C
tehtrisGeneric.Malware

Network contacts

23.253.126.58 208.100.26.251 35.231.151.7 198.187.30.249

DNS requests

cicafykemaj.eu cicaratupig.eu cicavemejih.eu cicezomaxyz.eu cicidutuwap.eu ciciqacidir.eu cicokokyvyf.eu cicucifokym.eu cicynefogic.eu cicypucitan.eu cidacomutur.eu cidaqyfynos.eu cidediceleg.eu cidinymuqom.eu cidizakisuv.eu cidohukigeq.eu cidufitojex.eu cidykatafuj.eu cidyrecavok.eu cihakotihuz.eu cihaqokiwel.eu cihevykupoc.eu cihihacakuf.eu cihipifebep.eu cihocytodoh.eu cihunemyror.eu cihuzucagot.eu cihyfafexuw.eu cihyrimymen.eu cilakyfaloq.eu cilavocofer.eu cileretirus.eu

Process list

NameCommand line
a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe
explorer.exe
dwm.exe
dllhost.exe/Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}