a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe
Classification: Malicious
a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe is a malicious file sample. Reported by 1 threat source, last seen 2019-06-06.
Detection summary
- 92 antivirus detections (87% detection ratio)
- 1 IDS alerts
- 4 processes observed
- 4 contacted hosts
- 32 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Backdoor.Shiz |
Hybrid-Analysis |
2019-06-06 11:45:15 |
2019-06-06 11:45:15 |
|
|
Sample information
- Filenames
- a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 260096 bytes
- MD5
f872e8cfca55310524e13c4401ea6478
- SHA-1
614b228e5bac06aa25a0e4a31fb42538a1923d89
- SHA-256
a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac
- First indexed
- 2019-06-06 11:45:15
- Last updated
- 2026-01-15 01:14:02
Antivirus detections
| Engine | Detection |
| Bkav | W32.Clod423.Trojan.3444 |
| MicroWorld-eScan | Gen:Heur.Zybut.1 |
| nProtect | Trojan/W32.Agent.260096.EB |
| CAT-QuickHeal | (Suspicious) - DNAScan |
| McAfee | Artemis!F872E8CFCA55 |
| VIPRE | Trojan.Win32.EncPk.acr.gen (v) |
| K7AntiVirus | Spyware ( 0040f2501 ) |
| K7GW | Spyware ( 0040f2501 ) |
| TheHacker | Backdoor/Shiz.aqva |
| Agnitum | Backdoor.Shiz!sF1pxQKpkUc |
| F-Prot | W32/Shiz.QY |
| Symantec | Infostealer.Shiz!gen |
| Norman | Suspicious_Gen4.EMEG |
| TotalDefense | Win32/Shiz.P!generic |
| TrendMicro-HouseCall | TROJ_RUNLOAD.USB13VC |
| Avast | Win32:MalOb-JH [Cryp] |
| ClamAV | Trojan.Shiz-138 |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| BitDefender | Gen:Heur.Zybut.1 |
| NANO-Antivirus | Trojan.Win32.Agent2.pmsux |
| ViRobot | Backdoor.Win32.A.Shiz.260096.A |
| Tencent | Win32.Backdoor.Shiz.Edxa |
| Ad-Aware | Gen:Heur.Zybut.1 |
| Emsisoft | Gen:Heur.Zybut.1 (B) |
| Comodo | Backdoor.Win32.Shiz.ASFK |
| F-Secure | Gen:Heur.Zybut.1 |
| DrWeb | Trojan.Packed.20771 |
| Zillya | Trojan.Shiz.Win32.402 |
| AntiVir | TR/Crypt.ZPACK.Gen |
| TrendMicro | TROJ_RUNLOAD.USB13VC |
| McAfee-GW-Edition | Heuristic.LooksLike.Win32.SuspiciousPE.C!87 |
| Sophos | Mal/EncPk-ACR |
| Jiangmin | Backdoor/Shiz.btw |
| Antiy-AVL | Trojan[Backdoor]/Win32.Shiz |
| Kingsoft | Win32.Hack.Shiz.(kcloud) |
| Microsoft | Backdoor:Win32/Simda |
| SUPERAntiSpyware | Trojan.Agent/Gen-Falprod |
| AhnLab-V3 | Backdoor/Win32.Shiz |
| GData | Gen:Heur.Zybut.1 |
| Commtouch | W32/Shiz.GVIA-4223 |
| VBA32 | Backdoor.Shiz |
| Panda | Trj/Genetic.gen |
| ESET-NOD32 | Win32/Spy.Shiz.NCF |
| Ikarus | Backdoor.Win32.Shiz |
| Fortinet | W32/Shiz.YWP!tr.bdr |
| AVG | BackDoor.Generic15.AGK |
| Qihoo-360 | HEUR/Malware.QVM19.Gen |
| APEX | Malicious |
| AVG | Win32:MalOb-JH [Cryp] |
| AhnLab-V3 | Backdoor/Win32.Shiz.R20029 |
| Alibaba | TrojanSpy:Win32/Simda.de16dae5 |
| Arcabit | Trojan.Zybut.1 |
| Avira | TR/Crypt.ZPACK.Gen |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Backdoor.SimdaCS.S15594 |
| CTX | exe.unknown.zybut |
| ClamAV | Win.Trojan.Shiz-151 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (high confidence) |
| F-Secure | Trojan.TR/Crypt.ZPACK.Gen |
| FireEye | Generic.mg.f872e8cfca553105 |
| Google | Detected |
| Jiangmin | Backdoor/Shiz.bnr |
| K7AntiVirus | Spyware ( 005068aa1 ) |
| K7GW | Spyware ( 005068aa1 ) |
| Kingsoft | Win32.Trojan.Generic.a |
| Lionic | Trojan.Win32.Generic.mBMA |
| Malwarebytes | Malware.AI.4065397674 |
| MaxSecure | Trojan.Malware.7164915.susgen |
| McAfee | GenericRXCM-PI!F872E8CFCA55 |
| NANO-Antivirus | Trojan.Win32.Agent.pmsux |
| Paloalto | generic.ml |
| Rising | Backdoor.Simda!8.2D9 (TFE:1:ZDPV1YCHhwV) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.dc |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.10b15f32 |
| Trapmine | malicious.high.ml.score |
| VIPRE | Gen:Heur.Zybut.1 |
| Varist | W32/Shiz.GVIA-4223 |
| VirIT | Backdoor.Win32.Generic.AGK |
| Webroot | W32.Trojan.Gen |
| Xcitium | Backdoor.Win32.Shiz.ASFK@4n04z5 |
| Yandex | Backdoor.Shiz!sF1pxQKpkUc |
| ZoneAlarm | Mal/EncPk-ACR |
| alibabacloud | Trojan[spy]:Win/Shiz.NCF |
| huorong | HEUR:VirTool/Obfuscator.gen!C |
| tehtris | Generic.Malware |
Process list
| Name | Command line |
| a141343445be49f7394d1ca53ca0c0704e79b48d15f4cf5db81baef0b03d95ac.exe | |
| explorer.exe | |
| dwm.exe | |
| dllhost.exe | /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF} |