s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-92394b9a718e4e093e78361da68a8f9f high

📛 Threat Title

VirusTotal: 92394b9a718e4e093e78361da68a8f9f

Category: ioc First seen: Last updated:

Description

VirusTotal verdict: 49 malicious / 0 suspicious of 59 engines.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 92394b9a718e4e093e78361da68a8f9f VT 49 / 59

IOC database

Type
hash_md5
Value
92394b9a718e4e093e78361da68a8f9f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Recovered from a VirusTotal threat record.

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 49 of 59 VirusTotal vendors

VendorVerdictDetection
Ad-Aware malicious Generic.MSIL.Bladabindi.A7E63929
AhnLab-V3 malicious Trojan/Win32.Generic.R108665
ALYac malicious Generic.MSIL.Bladabindi.A7E63929
Antiy-AVL malicious Trojan[:HEUR]/Win32.AGeneric
Arcabit malicious Generic.MSIL.Bladabindi.A7E63929
Avast malicious MSIL:Agent-CTT [Trj]
AVG malicious PSW.ILUSpy
Avira malicious TR/ATRAPS.Gen
AVware malicious Backdoor.MSIL.Bladabindi.a (v)
Baidu malicious MSIL.Backdoor.Bladabindi.a
BitDefender malicious Generic.MSIL.Bladabindi.A7E63929
CAT-QuickHeal malicious Backdoor.Bladabindi.AL3
ClamAV malicious Win.Trojan.B-468
Comodo malicious TrojWare.MSIL.Bladabindi.KX
CrowdStrike malicious malicious_confidence_100% (W)
Cyren malicious W32/MSIL_Bladabindi.A2.gen!Eldorado
DrWeb malicious Trojan.DownLoader10.26419
Emsisoft malicious Generic.MSIL.Bladabindi.A7E63929 (B)
ESET-NOD32 malicious a variant of MSIL/Bladabindi.AS
F-Prot malicious W32/MSIL_Bladabindi.A2.gen!Eldorado
F-Secure malicious Generic.MSIL.Bladabindi.A7E63929
Fortinet malicious MSIL/Agent.PPV!tr
GData malicious Generic.MSIL.Bladabindi.A7E63929
Ikarus malicious Trojan.MSIL.Bladabindi
Invincea malicious backdoor.msil.bladabindi.aj
Jiangmin malicious Trojan.Generic.alvne
K7AntiVirus malicious Trojan ( 700000121 )
K7GW malicious Trojan ( 700000121 )
Kaspersky malicious HEUR:Trojan.Win32.Generic
Kingsoft malicious Win32.Troj.Undef.(kcloud)
Lionic malicious Troj.W32.Gen.lKQy
Malwarebytes malicious Trojan.Agent.MSIL
McAfee malicious Trojan-FIGN
McAfee-GW-Edition malicious BehavesLike.Win32.BackdoorNJRat.mm
Microsoft malicious Backdoor:MSIL/Bladabindi.AJ
MicroWorld-eScan malicious Generic.MSIL.Bladabindi.A7E63929
NANO-Antivirus malicious Trojan.Win32.DownLoader10.ctopxm
Panda malicious Trj/GdSda.A
Sophos malicious Mal/Bbindi-C
SUPERAntiSpyware malicious Trojan.Agent/Gen-Barys
Symantec malicious Backdoor.Trojan
Tencent malicious Win32.Trojan.Generic.Hqld
TotalDefense malicious Win32/DotNetDl.A!generic
TrendMicro malicious BKDR_BLADABI.SMC
TrendMicro-HouseCall malicious BKDR_BLADABI.SMC
VIPRE malicious Backdoor.MSIL.Bladabindi.a (v)
ViRobot malicious Trojan.Win32.Z.Bladabindi.29184.EED[h]
Yandex malicious Trojan.RatJn.Gen.MG
Zillya malicious Trojan.Bladabindi.Win32.15140

Details From VirusTotal

Basic Properties
MD592394b9a718e4e093e78361da68a8f9f
SHA-1a16d4cac8f8bb698aa0984b52c06fc232566f879
SHA-256a1209831fa07bffc9cdac411af875e2c9a0fda722ce7785f584b22bfac723df2
VHash22403655551f0092c94020
SSDEEP768:Y1CF8nNZx76EvoiNOK1VoeykSkXy0L4GubJ65nnnnnnn:YgEvoiNZVjXsHbJ65nnnnnnn
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly
File size28.5 KB
History
Creation date2016-11-07 04:37 UTC
First seen on VirusTotal2016-11-07 09:37 UTC
Last submission2016-11-21 13:34 UTC
Last analysis2016-11-21 13:34 UTC
Last modified on VirusTotal2016-12-16 13:55 UTC
Known Names
  • sample2.exe
  • kDUk9NcH

References (1)

Remediations (10)

  • web:blackswan-cybersecurity.com

    Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.

  • web:docs.virustotal.com

    Here are the key elements of VirusTotal reports. We'll look at a typical URL report first, then a typical report for files. The last two sections will focus on domain and IP address reports. URL Report Summary URL Report Details File Report Summary File Report Details Domain and IP address reports U…

  • web:docs.virustotal.com

    Searching for IP address information VirusTotal runs its own passive DNS replication service, built by storing the DNS resolutions performed as we visit URLs and execute malware samples submitted by users. To retrieve the information we have on a given IP address, just type it into the search box.

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

  • web:www.virustotal.com

    VirusTotal is a free online tool for scanning files, URLs, and hashes for viruses and malware using multiple antivirus solutions.

  • web:www.virustotal.com

    VirusTotal provides a free online service to scan files and URLs for viruses, malware, and other threats using multiple antivirus engines.

  • web:www.virustotal.com

    VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.

  • web:www.virustotal.com

    VirusTotal is a free online service for scanning files and URLs for viruses, malware, and other malicious content using multiple antivirus solutions.

  • web:www.virustotal.com

    VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.

  • web:www.virustotal.com

    VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.