ag4bNl32yfCAHBiRAApiB4v3HZk952.exe
Classification: Malicious
ag4bNl32yfCAHBiRAApiB4v3HZk952.exe is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02. Detected by 99 antivirus engines.
Detection summary
- 99 antivirus detections (90% detection ratio)
- 1 IDS alerts
- 7 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-09-02 12:24:19 |
2026-09-02 12:24:19 |
anomalous-activity
|
|
| Generic Malware |
Cyber Threat Alliance |
2026-08-07 10:21:00 |
2026-08-31 10:14:42 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2025-06-15 23:15:03 |
2025-06-16 02:00:13 |
|
|
| Trojan.Generic |
Hybrid-Analysis |
2020-06-17 19:30:10 |
2020-06-17 19:30:10 |
|
|
Tags
evasive
defense_evasion
discovery
persistence
Sample information
- Filenames
- ag4bNl32yfCAHBiRAApiB4v3HZk952.exe, 9f4ad2e1a21330ed5442d666e37a3b47.exe, THUNDERDB.EXE
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 680455 bytes
- MD5
9f4ad2e1a21330ed5442d666e37a3b47
- SHA-1
af241db65197924eab63e20fd481bbdd8aafb053
- SHA-256
d895f7d839dedecac0558587ec722eb06ecf352399380aa6137052e1bc168783
- First indexed
- 2020-06-17 19:30:10
- Last updated
- 2026-09-01 06:07:47
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Generic.6257285 |
| APEX | Malicious |
| AVG | AutoIt:Agent-DG [Trj] |
| AhnLab-V3 | Worm/Win32.AutoIt.R20078 |
| Alibaba | Trojan:Win32/Babonock.37d |
| Antiy-AVL | Trojan[Spy]/Win32.AHK |
| Arcabit | Trojan.Generic.D5F7A85 |
| Avast | AutoIt:Agent-DG [Trj] |
| Avira | TR/AD.Milum.qebhh |
| Baidu | Win32.Trojan.Agent.acd |
| BitDefender | Trojan.Generic.6257285 |
| Bkav | W32.Common.720BCED4 |
| CAT-QuickHeal | Trojan.Babnock.AZ5 |
| CTX | exe.trojan.autoit |
| ClamAV | Win.Malware.Zusy-6804501-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop9.5793 |
| ESET-NOD32 | Win32/Autoit.HG |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Generic.6257285 (B) |
| F-Secure | Trojan.TR/AD.Milum.qebhh |
| Fortinet | AutoIt/Agent.NII!tr |
| GData | Win32.Trojan.PSE1.WFSZHF |
| Google | Detected |
| Gridinsoft | Worm.Win32.Mira.ka!i |
| Ikarus | Worm.Win32.AutoIt |
| Jiangmin | Packed.Katusha.arca |
| K7AntiVirus | Riskware ( 00584baa1 ) |
| K7GW | Riskware ( 00584baa1 ) |
| Kaspersky | Trojan-Spy.Win32.AutoIt.p |
| Kingsoft | Win32.HeurC.KVM007.a |
| Lionic | Trojan.Win32.Autoit.lHSt |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.326462455.susgen |
| McAfeeD | ti!D895F7D839DE |
| MicroWorld-eScan | Trojan.Generic.6257285 |
| Microsoft | Worm:Win32/Babonock!rfn |
| NANO-Antivirus | Trojan.Win32.TrjGen.efgwwj |
| Paloalto | generic.ml |
| Panda | Generic Malware |
| Rising | Trojan.Win32.Autoit.exs (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Autoit |
| Sangfor | Trojan.Win32.Save.a |
| Skyhigh | BehavesLike.Win32.Generic.jh |
| Sophos | Mal/Babonock-A |
| Symantec | W32.Babonock |
| TACHYON | Trojan/W32.Agent.680455.D |
| Tencent | Trojan.Win32.Autoit.b |
| TrellixENS | Generic.tj |
| TrendMicro | Worm.Win32.OTORUN.NKLSFV |
| TrendMicro-HouseCall | Worm.Win32.OTORUN.NKLSFV |
| VBA32 | Trojan.Autoit |
| VIPRE | Trojan.Generic.6257285 |
| Varist | W32/Trojan.XKGZ-9378 |
| ViRobot | Dropper.S.Agent.680455 |
| VirIT | Backdoor.RBot.TM |
| Webroot | W32.Infector.Virut.Gen |
| Xcitium | TrojWare.Win32.Spy.Babonock.DQ@6lkp66 |
| Yandex | Trojan.GenAsa!uaqukc/qOXI |
| Zillya | Trojan.AutoIT.Win32.7208 |
| ZoneAlarm | Mal/Babonock-A |
| Zoner | Trojan.Win32.Autoit.23699 |
| alibabacloud | Trojan[spy]:Win/Babonock.Gen |
| huorong | HEUR:Worm/FakeFolder.a |
| Bkav | W32.TaskmanumelLTAAAB.Trojan |
| FireEye | Generic.mg.9f4ad2e1a21330ed |
| Qihoo-360 | Win32/Trojan.Spy.775 |
| McAfee | Generic.tj |
| Malwarebytes | Trojan.Agent.AI |
| Sangfor | Malware |
| K7AntiVirus | Trojan ( 00071a9a1 ) |
| Alibaba | TrojanSpy:Win32/AutoIt.31da340a |
| K7GW | Trojan ( 00071a9a1 ) |
| Cybereason | malicious.1a2133 |
| TrendMicro | Mal_OtorunP |
| Cyren | W32/Agent.ALQL-9030 |
| Rising | Worm.Win32.Autorun.uav (CLASSIC) |
| Ad-Aware | Trojan.Generic.6257285 |
| Comodo | TrojWare.Win32.Spy.Babonock.DQ@6lkp66 |
| VIPRE | Trojan.Win32.Generic!BT |
| Invincea | heuristic |
| McAfee-GW-Edition | BehavesLike.Win32.Dropper.jh |
| F-Prot | W32/Agent.JZX |
| Endgame | malicious (high confidence) |
| AegisLab | Trojan.Win32.Autoit.lHSt |
| ZoneAlarm | Trojan-Spy.Win32.AutoIt.p |
| GData | Win32.Trojan.Agent.RNPST7 |
| VBA32 | Trojan.Hesv |
| MAX | malware (ai score=100) |
| TrendMicro-HouseCall | Mal_OtorunP |
| Tencent | Malware.Win32.Gencirc.10b8af28 |
| Yandex | TrojanSpy.AutoIt!uaUkVRhMVjI |
| eGambit | Unsafe.AI_Score_98% |
| Fortinet | W32/SPNR.03CM11!tr |
| BitDefenderTheta | Gen:NN.ZexaF.34128.PqX@amSO1Hni |
| MaxSecure | Trojan.Malware.1972078.susgen |
Process list
| Name | Command line |
| 9f4ad2e1a21330ed5442d666e37a3b47.exe | |
| rundll32.exe | |
| rundll32.exe | |
| THUNDERDB.EXE | |
| rundll32.exe | |
| rundll32.exe | |
| svchost.exe | -k netsvcs |