bfa4248005947726368f38380aab0158.exe
Classification: Malicious
bfa4248005947726368f38380aab0158.exe is a malicious file sample. Linked to Runningrat malware. Reported by 2 threat sources, last seen 2024-10-06.
Detection summary
- 61 antivirus detections
- 0 IDS alerts
- 4 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-10-06 18:45:04 |
2024-10-06 19:30:39 |
|
|
| RunningRAT |
MalwareBazaar Abuse.ch |
2024-10-06 18:32:21 |
2024-10-06 18:32:21 |
malicious-activity
|
S0253 RunningRAT
|
Sample information
- Filenames
- bfa4248005947726368f38380aab0158.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 49152 bytes
- MD5
bfa4248005947726368f38380aab0158
- SHA-1
bf5d8ea3d634bd1b7ec164a2e3659c7ba8f96148
- SHA-256
a4cdb56a6b905ad47a796da718a187e862fee0e713755f97cc197838f3111e28
- First indexed
- 2024-10-06 18:34:46
- Last updated
- 2026-03-26 06:31:39
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | Win32:DropperX-gen [Drp] |
| AhnLab-V3 | Trojan/Win32.Agent.R128989 |
| Antiy-AVL | Trojan/Win32.Farfli |
| Arcabit | Trojan.RI.1 |
| Avast | Win32:DropperX-gen [Drp] |
| Avira | TR/AD.Farfli.qqkhu |
| BitDefender | Gen:Heur.RI.1 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Younglotus.20397 |
| CTX | exe.unknown.generic |
| ClamAV | Win.Dropper.Gh0stRAT-7073897-1 |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.DownLoader12.47777 |
| ESET-NOD32 | Win32/Farfli.BGW |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Heur.RI.1 (B) |
| F-Secure | Trojan.TR/AD.Farfli.qqkhu |
| FireEye | Generic.mg.bfa4248005947726 |
| Fortinet | W32/Farfli.BGW!tr |
| GData | Gen:Heur.RI.1 |
| Google | Detected |
| Gridinsoft | Trojan.Win32.Agent.vl!n |
| Ikarus | Trojan.Win32.Farfli |
| Jiangmin | Trojan/YoungLotus.e |
| K7AntiVirus | Trojan ( 0055e3e41 ) |
| K7GW | Trojan ( 0055e3e41 ) |
| Kaspersky | Trojan.Win32.YoungLotus.t |
| Kingsoft | malware.kb.a.971 |
| Malwarebytes | Malware.AI.4194114185 |
| MaxSecure | Trojan.Malware.8167493.susgen |
| McAfee | BackDoor-FCWQ!BFA424800594 |
| McAfeeD | ti!A4CDB56A6B90 |
| MicroWorld-eScan | Gen:Heur.RI.1 |
| Microsoft | Backdoor:Win32/Venik!pz |
| NANO-Antivirus | Trojan.Win32.YoungLotus.dpanmc |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Farfli!1.C639 (KTSE) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Zusy |
| Skyhigh | BackDoor-FCWQ!BFA424800594 |
| Sophos | Mal/Generic-S |
| Symantec | SMG.Heur!gen |
| Tencent | Malware.Win32.Gencirc.10b39405 |
| Trapmine | malicious.moderate.ml.score |
| TrendMicro | BKDR_ZEGOST.SM29 |
| TrendMicro-HouseCall | BKDR_ZEGOST.SM29 |
| VBA32 | BScope.Backdoor.Caphaw |
| VIPRE | Gen:Heur.RI.1 |
| Varist | W32/S-0f55ee81!Eldorado |
| VirIT | Backdoor.Win32.Generic.JUY |
| Webroot | Trojan.Younglotus |
| Xcitium | TrojWare.Win32.YoungLotus.TCM@5ruomd |
| Yandex | Trojan.GenAsa!BZKdUv1dR3c |
| Zillya | Trojan.YoungLotus.Win32.4 |
| ZoneAlarm | Trojan.Win32.YoungLotus.t |
| Zoner | Trojan.Win32.97590 |
| alibabacloud | Worm:Win/Farfli.ba5c7bd9 |
| huorong | Backdoor/Farfli.bn |
Process list
| Name | Command line |
| bfa4248005947726368f38380aab0158.exe | |
| cmd.exe | /c ping 127.0.0.1 -n 1 && del /f/q "C:\bfa4248005947726368f38380aab0158.exe" |
| PING.EXE | ping 127.0.0.1 -n 1 |
| SySyaus.exe | %WINDIR%\system32\SySyaus.exe "%ALLUSERSPROFILE%\application data\908871593.dll",MainThread |