VT-92394b9a718e4e093e78361da68a8f9f
high
📛 Threat Title
VirusTotal: 92394b9a718e4e093e78361da68a8f9f
Description
VirusTotal verdict: 49 malicious / 0 suspicious of 59 engines.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_md5
92394b9a718e4e093e78361da68a8f9f
VT 49 / 59
IOC database
- Type
- hash_md5
- Value
92394b9a718e4e093e78361da68a8f9f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Recovered from a VirusTotal threat record.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 49 of 59 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Ad-Aware | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| AhnLab-V3 | malicious | Trojan/Win32.Generic.R108665 |
| ALYac | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| Antiy-AVL | malicious | Trojan[:HEUR]/Win32.AGeneric |
| Arcabit | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| Avast | malicious | MSIL:Agent-CTT [Trj] |
| AVG | malicious | PSW.ILUSpy |
| Avira | malicious | TR/ATRAPS.Gen |
| AVware | malicious | Backdoor.MSIL.Bladabindi.a (v) |
| Baidu | malicious | MSIL.Backdoor.Bladabindi.a |
| BitDefender | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| CAT-QuickHeal | malicious | Backdoor.Bladabindi.AL3 |
| ClamAV | malicious | Win.Trojan.B-468 |
| Comodo | malicious | TrojWare.MSIL.Bladabindi.KX |
| CrowdStrike | malicious | malicious_confidence_100% (W) |
| Cyren | malicious | W32/MSIL_Bladabindi.A2.gen!Eldorado |
| DrWeb | malicious | Trojan.DownLoader10.26419 |
| Emsisoft | malicious | Generic.MSIL.Bladabindi.A7E63929 (B) |
| ESET-NOD32 | malicious | a variant of MSIL/Bladabindi.AS |
| F-Prot | malicious | W32/MSIL_Bladabindi.A2.gen!Eldorado |
| F-Secure | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| Fortinet | malicious | MSIL/Agent.PPV!tr |
| GData | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| Ikarus | malicious | Trojan.MSIL.Bladabindi |
| Invincea | malicious | backdoor.msil.bladabindi.aj |
| Jiangmin | malicious | Trojan.Generic.alvne |
| K7AntiVirus | malicious | Trojan ( 700000121 ) |
| K7GW | malicious | Trojan ( 700000121 ) |
| Kaspersky | malicious | HEUR:Trojan.Win32.Generic |
| Kingsoft | malicious | Win32.Troj.Undef.(kcloud) |
| Lionic | malicious | Troj.W32.Gen.lKQy |
| Malwarebytes | malicious | Trojan.Agent.MSIL |
| McAfee | malicious | Trojan-FIGN |
| McAfee-GW-Edition | malicious | BehavesLike.Win32.BackdoorNJRat.mm |
| Microsoft | malicious | Backdoor:MSIL/Bladabindi.AJ |
| MicroWorld-eScan | malicious | Generic.MSIL.Bladabindi.A7E63929 |
| NANO-Antivirus | malicious | Trojan.Win32.DownLoader10.ctopxm |
| Panda | malicious | Trj/GdSda.A |
| Sophos | malicious | Mal/Bbindi-C |
| SUPERAntiSpyware | malicious | Trojan.Agent/Gen-Barys |
| Symantec | malicious | Backdoor.Trojan |
| Tencent | malicious | Win32.Trojan.Generic.Hqld |
| TotalDefense | malicious | Win32/DotNetDl.A!generic |
| TrendMicro | malicious | BKDR_BLADABI.SMC |
| TrendMicro-HouseCall | malicious | BKDR_BLADABI.SMC |
| VIPRE | malicious | Backdoor.MSIL.Bladabindi.a (v) |
| ViRobot | malicious | Trojan.Win32.Z.Bladabindi.29184.EED[h] |
| Yandex | malicious | Trojan.RatJn.Gen.MG |
| Zillya | malicious | Trojan.Bladabindi.Win32.15140 |
Details From VirusTotal
Basic Properties
| MD5 | 92394b9a718e4e093e78361da68a8f9f |
| SHA-1 | a16d4cac8f8bb698aa0984b52c06fc232566f879 |
| SHA-256 | a1209831fa07bffc9cdac411af875e2c9a0fda722ce7785f584b22bfac723df2 |
| VHash | 22403655551f0092c94020 |
| SSDEEP | 768:Y1CF8nNZx76EvoiNOK1VoeykSkXy0L4GubJ65nnnnnnn:YgEvoiNZVjXsHbJ65nnnnnnn |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly |
| File size | 28.5 KB |
History
| Creation date | 2016-11-07 04:37 UTC |
| First seen on VirusTotal | 2016-11-07 09:37 UTC |
| Last submission | 2016-11-21 13:34 UTC |
| Last analysis | 2016-11-21 13:34 UTC |
| Last modified on VirusTotal | 2016-12-16 13:55 UTC |
Known Names
sample2.exekDUk9NcH
References (1)
-
VirusTotal report
VirusTotal verdict: 49 malicious / 0 suspicious of 59 engines.
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:docs.virustotal.com
Here are the key elements of VirusTotal reports. We'll look at a typical URL report first, then a typical report for files. The last two sections will focus on domain and IP address reports. URL Report Summary URL Report Details File Report Summary File Report Details Domain and IP address reports U…
-
web:docs.virustotal.com
Searching for IP address information VirusTotal runs its own passive DNS replication service, built by storing the DNS resolutions performed as we visit URLs and execute malware samples submitted by users. To retrieve the information we have on a given IP address, just type it into the search box.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.com
VirusTotal is a free online tool for scanning files, URLs, and hashes for viruses and malware using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal provides a free online service to scan files and URLs for viruses, malware, and other threats using multiple antivirus engines.
-
web:www.virustotal.com
VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a free online service for scanning files and URLs for viruses, malware, and other malicious content using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.