Analysis Overview Request Report Deletion Show Sample Content
Be alerted when interesting malware samples emerge. Every day, MalQuery ingests over 750,000 malware samples, you can use YARA to monitor MalQuery as new samples are added and be alerted via email or API when there is a match.
Learn more
Falcon Sandbox Reports (6) Characteristics Legend Show All As List Submit
Windows 11 64 bit
HWiNFO_Monitor_Setup.exe
April 10th 2026 22:34:39 (UTC)
Malicious
- Threat Score:
- 100/100
- Indicators:
- 124134
- Labeled As:
- Trojan_Win32_Wacatac_C_ml
- Characteristics:
Windows 7 64 bit
HWiNFO_Monitor_Setup.exe
April 10th 2026 04:43:51 (UTC)
Malicious
- Threat Score:
- 77/100
- Indicators:
- 120173
- Labeled As:
- ABTrojan.XSEH
- Characteristics:
Windows 11 64 bit
HWiNFO_Monitor_Setup.exe
April 10th 2026 04:43:37 (UTC)
Malicious
- Threat Score:
- 77/100
- Indicators:
- 125143
- Labeled As:
- ABTrojan.XSEH
- Characteristics:
Windows 10 64 bit
HWiNFO_Monitor_Setup.exe
April 10th 2026 04:43:29 (UTC)
Malicious
- Threat Score:
- 77/100
- Indicators:
- 126132
- Labeled As:
- ABTrojan.XSEH
- Characteristics:
Windows 11 64 bit
HWiNFO_Monitor_Setup.exe
April 10th 2026 01:37:32 (UTC)
Malicious
- Threat Score:
- 71/100
- Indicators:
- 113135
- Labeled As:
- ABTrojan.XSEH
- Characteristics:
Windows 10 64 bit
HWiNFO_Monitor_Setup.exe
April 10th 2026 01:37:22 (UTC)
Malicious
- Threat Score:
- 76/100
- Indicators:
- 126161
- Labeled As:
- ABTrojan.XSEH
- Characteristics:
Falcon Sandbox Technology
- Hybrid Analysis: Powered by Falcon Sandbox
- Upgrade to a Falcon Sandbox license and gain full access to all features, IOCs and behavior analysis reportsData.
- Easily Deploy and Scale
- Process up to 25,000 files per month with Falcon Sandbox; because it is delivered on the cloud-native Falcon Platform, Falcon Sandbox is operational on Day One.
- Extensive Coverage
- Expanded support for file types and host operating systems.
Learn More!
Relations
Incident Response
Risk Assessment
- Remote Access
- Reads terminal service related keys (often RDP related)
- Spyware
- Found a string that may be used as part of an injection method
- Persistence
- Writes data to a remote process
- Evasive
- Marks file for deletion
Anonymous commented 1 day ago