63151e4f7c3972f18a23c0e9996e14ef.exe
Classification: Malicious
63151e4f7c3972f18a23c0e9996e14ef.exe is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-10-26.
Detection summary
- 49 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | Abuse.ch | 2021-10-26 14:48:15 | 2021-10-26 14:48:15 | malicious-activity | S0382 ServHelper |
Sample information
- Filenames
- 63151e4f7c3972f18a23c0e9996e14ef.exe
- File type
- application/x-dosexec
- MD5
63151e4f7c3972f18a23c0e9996e14ef- SHA-1
5d041fde6433a8ff8fc78a69fca1fd4630e3f270- SHA-256
cc28e327610e9deb6551c99a32a44fec86220f2840276474ded747580af850d3- First indexed
- 2021-10-26 16:15:13
- Last updated
- 2026-04-18 09:04:53
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Cobalt.trRF |
| Elastic | malicious (high confidence) |
| DrWeb | PowerShell.Inject.56 |
| MicroWorld-eScan | Trojan.GenericKD.37874674 |
| CAT-QuickHeal | TrojanDropper.MSIL |
| McAfee | Artemis!63151E4F7C39 |
| Cylance | Unsafe |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 00580cbe1 ) |
| Alibaba | Trojan:Win64/GoCLR.7f2d9138 |
| K7GW | Trojan ( 00580cbe1 ) |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Symantec | Trojan.Gen.MBT |
| ESET-NOD32 | a variant of WinGo/GoCLR.B |
| APEX | Malicious |
| ClamAV | Win.Malware.Bulz-9847817-0 |
| Kaspersky | UDS:Trojan-Dropper.MSIL.Agent |
| BitDefender | Trojan.GenericKD.37874674 |
| Avast | Win64:TrojanX-gen [Trj] |
| Ad-Aware | Trojan.GenericKD.37874674 |
| Sophos | Mal/Generic-S |
| Comodo | TrojWare.Win32.Agent.lqquz@0 |
| TrendMicro | TROJ_GEN.R002C0WJ921 |
| McAfee-GW-Edition | BehavesLike.Win64.Generic.th |
| FireEye | Trojan.GenericKD.37874674 |
| Emsisoft | Trojan.Agent (A) |
| SentinelOne | Static AI - Suspicious PE |
| Jiangmin | Trojan.Generic.gzxxe |
| Webroot | W32.Trojan.Gen |
| Avira | TR/Redcap.jiphy |
| MAX | malware (ai score=82) |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Gridinsoft | Malware.Win64.GenericMC.cc |
| Microsoft | Trojan:Win32/CryptInject!MSR |
| ViRobot | Trojan.Win32.Z.Goclr.6024704 |
| GData | Trojan.GenericKD.37874674 |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Agent.R442164 |
| ALYac | Backdoor.Agent.ServHelper |
| VBA32 | TrojanDropper.MSIL.Agent |
| Malwarebytes | Malware.AI.2563784621 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0WJ921 |
| Rising | HackTool.GoCLR!1.D71D (CLASSIC) |
| Ikarus | Trojan.WinGo.Goclr |
| eGambit | Unsafe.AI_Score_100% |
| Fortinet | W64/GoCLR.B!tr |
| AVG | Win64:TrojanX-gen [Trj] |
| Panda | Trj/CI.A |
| MaxSecure | Trojan.Malware.73890867.susgen |