VT-c05baf1f365887eabbaa5432bbb0f73a
medium
📛 Threat Title
File hash (MD5): c05baf1f365887eabbaa5432bbb0f73a
Description
Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: MD5 hashes: Recent additions
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
abuse.ch
VT 0 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
abuse.ch- First seen
- Last seen
- Attached to this threat
- Appears in
- 4019 threats
- Description
- Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | ch |
History
| Last analysis | 2026-05-24 09:28 UTC |
| Last modified on VirusTotal | 2026-05-24 16:38 UTC |
| WHOIS record date | 2026-03-29 11:09 UTC |
hash_md5
c05baf1f365887eabbaa5432bbb0f73a
VT 51 / 75
2 feeds
IOC database
- Type
- hash_md5
- Value
c05baf1f365887eabbaa5432bbb0f73a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: Abuse.ch
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Flagged by 51 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Benin.C5864524 |
| Alibaba | malicious | TrojanSpy:MSIL/Bobik.c02c299b |
| alibabacloud | malicious | Trojan[spy]:MSIL/Wacatac.C9nj |
| Antiy-AVL | malicious | Trojan/MSIL.Kryptik |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.MSIL.Benin.5 |
| Avast | malicious | Win32:MalwareX-gen [Spy] |
| AVG | malicious | Win32:MalwareX-gen [Spy] |
| Avira | malicious | TR/Crypt.XPACK.Gen8 |
| BitDefender | malicious | Gen:Heur.MSIL.Benin.5 |
| Bkav | malicious | W32.Malware.A3A84B0B |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Heur.MSIL.Benin.5 (B) |
| ESET-NOD32 | malicious | MSIL/Kryptik.APRJ trojan |
| F-Secure | malicious | Trojan.TR/Crypt.XPACK.Gen8 |
| Fortinet | malicious | MSIL/MALD2.C702!tr |
| GData | malicious | Gen:Heur.MSIL.Benin.5 |
| malicious | Detected |
|
| Ikarus | malicious | Trojan-Spy.MSIL.PureHVNC |
| K7AntiVirus | malicious | Trojan ( 700000201 ) |
| K7GW | malicious | Trojan ( 700000201 ) |
| Kaspersky | malicious | HEUR:Trojan-Spy.MSIL.Bobik.gen |
| Kingsoft | malicious | MSIL.Trojan-Spy.Bobik.gen |
| Lionic | malicious | Trojan.Win32.Bobik.l!c |
| Malwarebytes | malicious | Trojan.Crypt.MSIL.Generic |
| MaxSecure | malicious | Trojan.Malware.664932946.susgen |
| McAfeeD | malicious | Real Protect-LS!C05BAF1F3658 |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Gen:Heur.MSIL.Benin.5 |
| Paloalto | malicious | generic.ml |
| Rising | malicious | Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:W2oIcrSrLfvqBwvlgD1Lmw) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| tehtris | malicious | Generic.Malware |
| Tencent | malicious | Malware.Win32.Gencirc.14ac6fef |
| Trapmine | malicious | malicious.moderate.ml.score |
| TrellixENS | malicious | Artemis!C05BAF1F3658 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA1 |
| Varist | malicious | W32/MSIL_Kryptik.MYG.gen!Eldorado |
| VBA32 | malicious | TScope.Trojan.MSIL |
| VIPRE | malicious | Gen:Heur.MSIL.Benin.5 |
| ViRobot | malicious | Trojan.Win.Z.Kryptik.643584.AG |
| Webroot | malicious | W32.Trojan.Gen |
| Zillya | malicious | Trojan.Kryptik.Win32.6004742 |
Details From VirusTotal
Basic Properties
| MD5 | c05baf1f365887eabbaa5432bbb0f73a |
| SHA-1 | 541b592eb3032326ee15d1d863c370444d1e3eb9 |
| SHA-256 | 83b5c8aa802986507b5bc678c4839256df06f5fc71a155fb164e2a09c0b22fd5 |
| VHash | 265036751511b09528800b0 |
| SSDEEP | 12288:6waJH3htpQ9jQ4xOV3KTXvLISHHcPIC8BaGiDyU:8ftpQ9jQ4xOV3KDjIGcPIPBhOy |
| TLSH | T1D8D4AEBB76534E22D2840337C5C7484193BDD78676A7F30E748413A66A033BADE4B6A7 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 628.5 KB |
History
| Creation date | 2051-08-09 21:04 UTC |
| First seen on VirusTotal | 2026-04-03 17:27 UTC |
| Last submission | 2026-05-13 14:01 UTC |
| Last analysis | 2026-05-14 05:25 UTC |
| Last modified on VirusTotal | 2026-05-19 12:20 UTC |
Known Names
Qfkgpa.exeimagetest0071154z7.png83b5c8aa802986507b5bc678c4839256df06f5fc71a155fb164e2a09c0b22fd5.exep5eo7ku99.exey9elfp1r.exe
References (1)
-
VirusTotal report
Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).
Remediations (9)
-
web:check.town
Free file hash checker. Upload a file and compute MD5 , SHA-1, SHA-256, and SHA-512 checksums client-side.
-
web:cybercheck360.com
Calculate the MD5 , SHA-1, SHA-256, and SHA-512 hash of any file directly in your browser. No upload needed, hashes are computed locally.
-
web:flipperfile.com
Free MD5 hash checker that works entirely in your browser. Generate and compare MD5 hashes for text or files instantly, with no uploads or tracking.
-
web:inventivehq.com
Free hash lookup tool. Search MD5 , SHA-1, SHA-256 hashes in breach databases to identify compromised passwords, malware, and file integrity.
-
web:sslinsights.com
Learn how to get MD5 hash of a file in Windows using Command Prompt and PowerShell. Quick and easy methods for file verification.
-
web:tooljot.com
The File Hash Checker computes cryptographic hash values for any file directly in your browser. Drag and drop a file (or click to browse) and instantly see its MD5 , SHA-1, SHA-256, SHA-384, and SHA-512 hashes — all calculated locally using the Web Crypto API.
-
web:www.freecodeformat.com
Verify file integrity online. Calculate MD5 , SHA1, SHA256, SHA512, SHA3, RIPEMD-160, and CRC32 hashes for any file . Fast, secure, and supports multiple files .
-
web:www.getzenquery.com
Verify file integrity instantly with our free online File Hash Checker. Upload any file to compute MD5 , SHA-1, SHA-256, and SHA-512 hashes—then compare with original or expected checksums. Perfect for ensuring downloaded files are intact, validating software authenticity, or detecting corruption. All processing happens locally in your browser for privacy.
-
web:www.toolsley.com
Calculate the hash for any file online. Generate MD5 , SHA1, SHA256 or CRC32 instantly in your browser using JavaScript. Make share-able links to validate files . No need to install anything, just drag & drop.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.