e66a9d6480722e985711144244ae1697.exe
Classification: Malicious
e66a9d6480722e985711144244ae1697.exe is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-03-25.
Detection summary
- 41 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | Abuse.ch | 2021-03-25 13:01:39 | 2021-03-25 13:01:39 | malicious-activity | S0382 ServHelper |
Sample information
- Filenames
- e66a9d6480722e985711144244ae1697.exe
- File type
- application/x-dosexec
- MD5
e66a9d6480722e985711144244ae1697- SHA-1
61f58215d6ce25aaa1addd664e8346a7fa540275- SHA-256
eed912423954b56dc4ea01f9d3fb1c46ea175be378889fd886e37c09954cfaba- First indexed
- 2021-03-25 13:15:05
- Last updated
- 2026-04-29 20:18:35
Antivirus detections
| Engine | Detection |
|---|---|
| MicroWorld-eScan | Gen:Variant.Bulz.386265 |
| FireEye | Gen:Variant.Bulz.386265 |
| CAT-QuickHeal | TrojanDropper.MSIL |
| McAfee | Artemis!E66A9D648072 |
| Cylance | Unsafe |
| Sangfor | Trojan.Win32.Ymacco.AAEE |
| K7AntiVirus | Trojan ( 00578ee41 ) |
| Alibaba | TrojanDropper:MSIL/GoCLR.607f8b20 |
| K7GW | Trojan ( 00578ee41 ) |
| Cyren | W64/GoClr.A.gen!Eldorado |
| Symantec | Trojan.Gen.2 |
| APEX | Malicious |
| Avast | Win64:Trojan-gen |
| Kaspersky | Trojan-Dropper.MSIL.Agent.seskgo |
| BitDefender | Gen:Variant.Bulz.386265 |
| NANO-Antivirus | Trojan.Win64.Bulz.iqjatp |
| Paloalto | generic.ml |
| ViRobot | Trojan.Win32.Z.Bulz.6347264 |
| Rising | Dropper.Agent!8.2F (CLOUD) |
| Ad-Aware | Gen:Variant.Bulz.386265 |
| Sophos | Mal/Generic-S |
| DrWeb | Trojan.MulDrop16.30892 |
| VIPRE | Trojan.Win32.Generic!BT |
| McAfee-GW-Edition | BehavesLike.Win64.Generic.vh |
| Emsisoft | Gen:Variant.Bulz.386265 (B) |
| GData | Gen:Variant.Bulz.386265 |
| Jiangmin | Trojan.Cobalt.ic |
| Gridinsoft | Trojan.Win64.Agent.ns |
| Microsoft | Trojan:Win32/Ymacco.AAEE |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win64.Generic.R372645 |
| ALYac | Gen:Variant.Bulz.386265 |
| MAX | malware (ai score=84) |
| VBA32 | TrojanDropper.MSIL.Agent |
| Malwarebytes | Malware.AI.3923343694 |
| ESET-NOD32 | a variant of WinGo/GoCLR.A |
| TrendMicro-HouseCall | TROJ_GEN.R002H0CCF21 |
| Ikarus | Trojan.WinGo.Goclr |
| Fortinet | W32/Agent.A!tr |
| AVG | Win64:Trojan-gen |
| Qihoo-360 | Win64/TrojanDropper.Generic.HgEASQ0A |