Classification: Malicious
oni.exe is a malicious file sample. Reported by 1 threat source, last seen 2024-05-10. Detected by 52 antivirus engines.
Detection summary
- 52 antivirus detections
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-05-10 11:30:03 |
2024-05-10 12:30:08 |
|
|
Sample information
- Filenames
- oni.exe
- File type
- PE32+ executable (console) x86-64, for MS Windows
- Size
- 29995520 bytes
- MD5
7242f09b054e95ee3b09bc4860bf037c
- SHA-1
9693915e571b5a341a75de4f978c0a12df3ebeeb
- SHA-256
dfea3ce4fc15eb68b710249985ec97585e70ffbdf6bddcd0ff9ebced9e3c0941
- First indexed
- 2024-05-10 11:07:55
- Last updated
- 2026-09-03 00:42:52
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | Win64:MalwareX-gen [Trj] |
| Acronis | suspicious |
| Avast | Win64:MalwareX-gen [Trj] |
| Avira | HEUR/AGEN.1366424 |
| Bkav | W64.AIDetectMalware |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of Win64/Packed.VMProtect.AA suspicious |
| Elastic | malicious (high confidence) |
| F-Secure | Heuristic.HEUR/AGEN.1366424 |
| Fortinet | Riskware/Application |
| GData | Win64.Trojan.Agent.JAP4MD |
| Google | Detected |
| Gridinsoft | Trojan.Heur!.02212023 |
| Ikarus | Trojan.Win64.Vmprotect |
| Lionic | Trojan.Win32.Generic.4!c |
| McAfee | Artemis!7242F09B054E |
| Paloalto | generic.ml |
| Sangfor | Trojan.Win64.Agent.Va7w |
| Skyhigh | Artemis |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | malicious.moderate.ml.score |
| ALYac | QD:Trojan.GenericKDQ.83E9D0D3A2 |
| AVG | Win64:MalwareX-gen [Misc] |
| Alibaba | Packed:Win64/VMProtect.81c45ac5 |
| Arcabit | QD:Trojan.GenericQ.83E9D0D3A2 |
| Avast | Win64:MalwareX-gen [Misc] |
| BitDefender | QD:Trojan.GenericKDQ.83E9D0D3A2 |
| CAT-QuickHeal | Trojan.Ghanarava.1727135587bf037c |
| CTX | exe.trojan.vmprotect |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| ESET-NOD32 | Win32/Packed.VMProtect.ACX trojan |
| Emsisoft | QD:Trojan.GenericKDQ.83E9D0D3A2 (B) |
| GData | QD:Trojan.GenericKDQ.83E9D0D3A2 |
| K7AntiVirus | Riskware ( 005cdd801 ) |
| K7GW | Riskware ( 005cdd801 ) |
| Lionic | Trojan.Win32.GenericKDQ.4!c |
| Malwarebytes | Malware.Heuristic.2108 |
| MaxSecure | Trojan.Malware.8426628.susgen |
| McAfeeD | Real Protect-LS!7242F09B054E |
| MicroWorld-eScan | QD:Trojan.GenericKDQ.83E9D0D3A2 |
| Rising | [email protected] (RDML:jxyjz2p0uLWySOSFKu6/lQ) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Mal/Generic-S |
| TrellixENS | Artemis!7242F09B054E |
| TrendMicro-HouseCall | TROJ_GEN.R002H09HR25 |
| VIPRE | QD:Trojan.GenericKDQ.83E9D0D3A2 |
| Varist | W64/ABRisk.UOAR-0385 |
| alibabacloud | Trojan:Win/Packed.VMProtect.AWF |