Classification: Malicious
119716.exe is a malicious file sample. Linked to Sombrat malware. Reported by 3 threat sources, last seen 2024-05-08. Detected by 10 antivirus engines.
Detection summary
- 10 antivirus detections
- 1 IDS alerts
- 4 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| SombRAT |
ThreatFox Abuse.ch |
2024-05-06 17:55:29 |
2024-05-08 17:20:47 |
|
S0615 SombRAT
|
| Generic Malware |
Hybrid-Analysis |
2024-05-06 17:15:04 |
2024-05-06 18:00:09 |
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2024-05-06 17:00:11 |
2024-05-06 17:00:11 |
malicious-activity
|
|
Sample information
- Filenames
- 119716.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 27468648 bytes
- MD5
b7cb6e4c311d5bb95c34586b6c6bd8ab
- SHA-1
d3136c36d7d769bdcb14cd33a5ed36e3594b96a2
- SHA-256
aa6961014813a363db5c231c2affe761bee2da1d25f5ad39f5a8c51f3a57d1ed
- First indexed
- 2024-05-06 17:02:10
- Last updated
- 2026-03-07 10:06:15
Antivirus detections
| Engine | Detection |
| AVG | MalwareX-gen [Trj] |
| Avast | MalwareX-gen [Trj] |
| Bkav | W32.AIDetectMalware |
| DeepInstinct | MALICIOUS |
| Jiangmin | Trojan.PSW.Reline.f |
| Kaspersky | UDS:Trojan.Win32.DInvoke.gen |
| Sangfor | Trojan.Win32.Agent.V8v0 |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.Malware.Szfl |
| TrendMicro | Backdoor.Win32.ASYNCRAT.YXEEFZ |
Process list
| Name | Command line |
| 119716.exe | |
| WerFault.exe | -u -p 2824 -s 972 |
| WerFault.exe | -u -p 2824 -s 972 |
| WerFault.exe | -pss -s 464 -p 2824 -ip 2824 |