MEE6 Controller - Setup.exe

Classification: Malicious

MEE6 Controller - Setup.exe is a malicious file sample. Reported by 1 threat source, last seen 2022-12-29. Detected by 39 antivirus engines.

Detection summary

  • 39 antivirus detections (57% detection ratio)
  • 1 IDS alerts
  • 7 processes observed
  • 3 contacted hosts
  • 2 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2022-12-29 23:00:04 2022-12-29 23:00:04
Discord.AP Hybrid-Analysis 2020-08-18 16:45:11 2020-08-18 16:45:11

Sample information

Filenames
MEE6 Controller - Setup.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
11679989 bytes
MD5
c7fbbbe6e295905750ffc1a141dce60f
SHA-1
5c016d85ab18c8106b4c61fed178cd935058273a
SHA-256
c8dc364bbad7cbaa1a2f39a1155700b9789087316997622eb86e8d1c7c1b461b
First indexed
2020-08-18 16:45:11
Last updated
2022-12-29 23:00:04

Antivirus detections

EngineDetection
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43477549
CAT-QuickHealTrojanpws.Msil
ALYacTrojan.GenericKD.43477549
CylanceUnsafe
K7AntiVirusPassword-Stealer ( 0054b4351 )
AlibabaTrojanPSW:MSIL/Discord.3327b8b4
K7GWPassword-Stealer ( 0054b4351 )
F-ProtW32/Razy.CN.gen!Eldorado
SymantecTrojan.Gen.MBT
GDataTrojan.GenericKD.43477549
KasperskyHEUR:Trojan-PSW.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.43477549
NANO-AntivirusTrojan.Win32.Stealer.hhzgle
AvastWin32:PWSX-gen [Trj]
RisingStealer.Discord!1.B7AA (CLOUD)
Ad-AwareTrojan.GenericKD.43477549
ComodoMalware@#9ko7vjdj7acv
F-SecureHeuristic.HEUR/AGEN.1127855
DrWebTrojan.PWS.Stealer.26221
VIPRETrojan.Win32.Generic!BT
FireEyeTrojan.GenericKD.43477549
CyrenW32/Razy.CN.gen!Eldorado
WebrootW32.Trojan.Agent.Gen
AviraHEUR/AGEN.1127855
ArcabitTrojan.Generic.D2976A2D
AegisLabTrojan.MSIL.Agent.i!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Discord.BM!MTB
McAfeeArtemis!C7FBBBE6E295
MAXmalware (ai score=88)
VBA32TrojanPSW.MSIL.Agent
ESET-NOD32MSIL/PSW.Discord.AP
YandexTrojan.PWS.Discord!
IkarusTrojan.MSIL.PSW
FortinetW32/Discord.AP!tr.pws
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
Qihoo-360Generic/Trojan.PSW.634

Network contacts

95.217.228.176 162.159.134.233 162.159.133.233

DNS requests

discordapp.com wtfismyip.com

Process list

NameCommand line
MEE6Controller-Setup.exe
MEE6Controller-Setup.tmp/SL5="$B01C0,10886353,724992,C:\MEE6Controller-Setup.exe"
MEE6 Controller.exe
MEE6 Controller.exe
MEE6Controller-Setup.exe
MEE6Controller-Setup.tmp/SL5="$901BA,10886353,724992,C:\MEE6Controller-Setup.exe"
MEE6 Controller.exe