e3f245020bcf6beaca39b8cc9eb06b3db7f209356e765f41d8306ad56735e944
Classification: Malicious
e3f245020bcf6beaca39b8cc9eb06b3db7f209356e765f41d8306ad56735e944 is a malicious file sample. Linked to Sombrat malware. Detected by 57 antivirus engines.
Detection summary
- 57 antivirus detections
- 1 IDS alerts
- 13 processes observed
- 3 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-08-23 07:00:06 |
2025-08-23 11:45:23 |
|
|
| SombRAT |
ThreatFox Abuse.ch |
2024-05-23 15:21:11 |
2024-05-25 15:22:44 |
|
S0615 SombRAT
|
| VenomRAT |
MalwareBazaar Abuse.ch |
2024-05-23 13:32:54 |
2024-05-23 13:32:54 |
malicious-activity
|
|
Sample information
- Filenames
- e3f245020bcf6beaca39b8cc9eb06b3db7f209356e765f41d8306ad56735e944, SecuriteInfo.com.Trojan.PackedNET.2595.1466.2669
- File type
- application/x-dosexec
- Size
- 236544 bytes
- MD5
144f1b1c4b9cdad97d8dd1a3a89e7ea1
- SHA-1
1a11d76a6ab646a0d699efa0e5fc71de6e5af92c
- SHA-256
e3f245020bcf6beaca39b8cc9eb06b3db7f209356e765f41d8306ad56735e944
- First indexed
- 2024-05-23 14:21:09
- Last updated
- 2025-08-31 03:00:51
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Ransom.Loki.5934 |
| APEX | Malicious |
| AhnLab-V3 | Trojan/Win.Generic.C5144844 |
| Alibaba | TrojanDropper:MSIL/AsyncRAT.d2e8825b |
| Arcabit | Trojan.Ransom.Loki.D172E |
| Avira | TR/Dropper.Gen |
| BitDefender | Gen:Variant.Ransom.Loki.5934 |
| BitDefenderTheta | Gen:NN.ZemsilF.36804.om0@aqF9s!j |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Generic.TRFH465 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cybereason | malicious.c4b9cd |
| Cylance | unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.PackedNET.2595 |
| ESET-NOD32 | a variant of MSIL/GenKryptik.FZQG |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Ransom.Loki.5934 (B) |
| F-Secure | Trojan.TR/Dropper.Gen |
| FireEye | Generic.mg.144f1b1c4b9cdad9 |
| Fortinet | MSIL/GenKryptik.FVDD!tr |
| GData | Gen:Variant.Ransom.Loki.5934 |
| Google | Detected |
| Gridinsoft | Ransom.Win32.AzorUlt.sa |
| Ikarus | Trojan.MSIL.CoinMiner |
| K7AntiVirus | Trojan ( 00597c021 ) |
| K7GW | Trojan ( 00597c021 ) |
| Kaspersky | HEUR:Trojan-Dropper.MSIL.Dapato.gen |
| Kingsoft | MSIL.Trojan-Dropper.Dapato.gen |
| Lionic | Trojan.Win32.AsyncRAT.b!c |
| MAX | malware (ai score=82) |
| Malwarebytes | Trojan.MalPack |
| McAfee | FE_Dropper_MSIL_Generic_21 |
| McAfeeD | Real Protect-LS!144F1B1C4B9C |
| MicroWorld-eScan | Gen:Variant.Ransom.Loki.5934 |
| NANO-Antivirus | Trojan.Win32.Dapato.kmuykk |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:1MQPh41ehUklSjL/Vj0zIw) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.dc |
| Sophos | Troj/MDrop-JWW |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.140b6332 |
| Trapmine | malicious.high.ml.score |
| TrendMicro | Backdoor.Win32.ASYNCRAT.YXEEKZ |
| TrendMicro-HouseCall | Backdoor.Win32.ASYNCRAT.YXEEKZ |
| VIPRE | Gen:Variant.Ransom.Loki.5934 |
| Varist | W32/Azorult.D.gen!Eldorado |
| ViRobot | Trojan.Win.Z.Ransom.236544 |
| Webroot | W32.Trojan.TR.Dropper |
| Xcitium | Malware@#3qggoszxcf1s2 |
| Yandex | Trojan.GenKryptik!6JoAGkUAcAs |
| Zillya | Trojan.GenKryptik.Win32.615881 |
| ZoneAlarm | HEUR:Trojan-Dropper.MSIL.Dapato.gen |
| alibabacloud | Trojan[dropper]:MSIL/AsyncRAT.Z9OKG |
Process list
| Name | Command line |
| e3f245020bcf6beaca39b8cc9eb06b3db7f209356e765f41d8306ad56735e944.exe | |
| Client.exe | |
| cmd.exe | /c schtasks /create /f /sc onlogon /rl highest /tn "Loader" /tr '"%APPDATA%\Loader.exe"' & exit |
| schtasks.exe | schtasks /create /f /sc onlogon /rl highest /tn "Loader" /tr '"%APPDATA%\Loader.exe"' |
| cmd.exe | /c ""%TEMP%\tmp5480.tmp.bat"" |
| timeout.exe | timeout 3 |
| Infected.exe | |
| cmd.exe | /c schtasks /create /f /sc onlogon /rl highest /tn "Loaader" /tr '"%APPDATA%\Loaader.exe"' & exit |
| schtasks.exe | schtasks /create /f /sc onlogon /rl highest /tn "Loaader" /tr '"%APPDATA%\Loaader.exe"' |
| cmd.exe | /c ""%TEMP%\tmp4FEC.tmp.bat"" |
| timeout.exe | timeout 3 |
| Loaader.exe | |
| WinDefend.exe | |