0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e.dll
Classification: Malicious
0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e.dll is a malicious file sample. Linked to Squirrelwaffle malware.
Detection summary
- 95 antivirus detections (63% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 4 contacted hosts
- 4 DNS requests
MITRE ATT&CK associations
Malware families: SQUIRRELWAFFLE (S1030)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Squirrelwaffle | Abuse.ch | 2021-10-27 10:31:13 | 2021-10-27 10:31:13 | malicious-activity | S1030 Squirrelwaffle |
Sample information
- Filenames
- 0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e.dll, test1.test.dll
- File type
- application/x-dosexec
- Size
- 458218 bytes
- MD5
7df7e578e914d992be61f8057adc25cd- SHA-1
1fe5e1eaf8ab95478635664ee2141dbe52e5a5e8- SHA-256
0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e- First indexed
- 2021-10-27 07:17:46
- Last updated
- 2026-03-03 06:07:48
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Malicious.4!c |
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.DownLoader43.22421 |
| MicroWorld-eScan | Trojan.Generic.30185270 |
| FireEye | Generic.mg.7df7e578e914d992 |
| McAfee | GenericRXAA-AA!7DF7E578E914 |
| Cylance | Unsafe |
| Zillya | Downloader.Agent.Win32.449545 |
| Sangfor | Virus.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_90% (W) |
| Alibaba | TrojanDownloader:Win32/Qakbot.9a3c205e |
| K7GW | Trojan-Downloader ( 005825f01 ) |
| K7AntiVirus | Trojan-Downloader ( 005825f01 ) |
| Arcabit | Trojan.Generic.D1CC9736 |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | Win32/TrojanDownloader.Agent.FWT |
| APEX | Malicious |
| BitDefender | Trojan.Generic.30185270 |
| NANO-Antivirus | Trojan.Win32.Delphi.fewgku |
| Avast | Win32:Trojan-gen |
| Ad-Aware | Trojan.Generic.30185270 |
| Emsisoft | Trojan.Generic.30185270 (B) |
| McAfee-GW-Edition | Artemis!Trojan |
| Sophos | Mal/EncPk-APY |
| SentinelOne | Static AI - Malicious PE |
| MaxSecure | Trojan.Malware.122357445.susgen |
| Avira | TR/YAV.Minerva.pzitl |
| Gridinsoft | Trojan.Win32.Downloader.oa!s1 |
| Microsoft | Trojan:Win32/Qakbot.SM!MTB |
| ViRobot | Trojan.Win32.Z.Agent.458218 |
| GData | Win32.Trojan.PSE.11UBQ5E |
| Cynet | Malicious (score: 99) |
| AhnLab-V3 | Trojan/Win.Qakbot.R442762 |
| ALYac | Trojan.Generic.30185270 |
| MAX | malware (ai score=88) |
| VBA32 | BScope.TrojanDownloader.Deyma |
| Malwarebytes | Malware.AI.536830020 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DIT21 |
| Yandex | Trojan.DL.Agent!B9q93vzme+0 |
| Ikarus | Trojan.Win32.Generic |
| Fortinet | W32/Injector.EQDN!tr |
| AVG | Win32:Trojan-gen |
| Panda | Trj/GdSda.A |
| Alibaba | TrojanDownloader:Win32/Qakbot.7b4ff486 |
| Cyren | W32/Kryptik.FQB.gen!Eldorado |
| Kaspersky | HEUR:Trojan.Win32.Qshell.pef |
| Tencent | Malware.Win32.Gencirc.11d0eb3c |
| Sophos | Mal/Generic-R + Mal/EncPk-APY |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| ZoneAlarm | HEUR:Trojan.Win32.Qshell.pef |
| Cynet | Malicious (score: 100) |
| Ikarus | Trojan.Win32.Injector |
| ALYac | Gen:Variant.Zusy.405600 |
| AVG | Win32:Evo-gen [Trj] |
| Alibaba | TrojanDownloader:Win32/Qakbot.7ddb4ab3 |
| Antiy-AVL | Trojan/Win32.Kryptik |
| Arcabit | Trojan.Zusy.D63060 |
| Avast | Win32:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1368173 |
| BitDefender | Gen:Variant.Zusy.405600 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.QakbotIH.S24673104 |
| CTX | dll.trojan.generic |
| ClamAV | Win.Malware.Barys-9917903-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| ESET-NOD32 | Win32/TrojanDownloader.Agent.FWT trojan |
| Emsisoft | Gen:Variant.Zusy.405600 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1368173 |
| Fortinet | W32/Injector.A!tr |
| GData | Gen:Variant.Zusy.405600 |
| Detected | |
| Ikarus | Trojan.Win32.Krypt |
| K7AntiVirus | Trojan-Downloader ( 005fec881 ) |
| K7GW | Trojan-Downloader ( 005fec881 ) |
| Kingsoft | malware.kb.a.980 |
| Lionic | Trojan.Win32.Qakbot.4!c |
| Malwarebytes | Inject.Exploit.Shellcode.DDS |
| McAfeeD | ti!0278A0FF3A6F |
| MicroWorld-eScan | Gen:Variant.Zusy.405600 |
| Paloalto | generic.ml |
| Rising | Downloader.Agent!8.B23 (TFE:5:W6FBAXqIPYF) |
| Sangfor | Downloader.Win32.Qakbot.Vt4p |
| SentinelOne | Static AI - Suspicious PE |
| Symantec | Trojan Horse |
| Tencent | Malware.Win32.Gencirc.10bbb4ce |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | GenericRXRH-CO!7DF7E578E914 |
| VIPRE | Gen:Variant.Zusy.405600 |
| Varist | W32/Kryptik.FQB.gen!Eldorado |
| Webroot | W32.Trojan.Squirrelwaffle |
| Xcitium | Malware@#27ugtn8b35o7z |
| ZoneAlarm | Mal/EncPk-APY |
| alibabacloud | Trojan[downloader]:Win/Qakbot.SZ8PHU |
| huorong | Trojan/Injector.akr |
| tehtris | Generic.Malware |
Network contacts
DNS requests
deanandwilconstruction.com eresourcesmoneymarket.com flyershipmanager.com gitamschool.com
Process list
| Name | Command line |
|---|---|
| <Ignored Process> | |
| regsvr32.exe | /s "C:\0278a0ff3a6fc56294995c86444bba7f264b945ed29e91d62e9256157ce6d15e.dll" |