2026-01-31_bb140985200d8281fc1757c697dcd821_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
Classification: Malicious
2026-01-31_bb140985200d8281fc1757c697dcd821_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee is a malicious file sample. Linked to Dcrat malware.
Detection summary
- 55 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: DCRAT (S9017)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Dcrat | Triage | 2026-01-31 21:20:47 | 2026-01-31 21:20:47 | malicious-activity | S9017 DCRAT |
Tags
dcrat defense_evasion discovery execution infostealer persistence rat trojanSample information
- Filenames
- 2026-01-31_bb140985200d8281fc1757c697dcd821_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
- MD5
bb140985200d8281fc1757c697dcd821- SHA-1
e2a16da9df98dbfc22c8267eacc9ccf9a93205bd- SHA-256
0a14c06eeab0906da4e8aef27d60a9e4ed8ab176fae429d86d0a61f01c005f7b- SHA-512
a140c5bd2e1be3f9c2b7c258896ba8c3dd257d4a7f75eca874f7bd4d992ce23e57b2ed97e17ee5f8d1c1d08badf7e3742088b6e5b02d6a91f14a263f49501858- First indexed
- 2026-01-31 21:20:47
- Last updated
- 2026-09-02 16:08:02
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.GQAF |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.DCRat.R729600 |
| Antiy-AVL | Trojan/Win32.DCRat |
| Arcabit | Trojan.Agent.GQAF |
| Avast | Win32:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1323984 |
| BitDefender | Trojan.Agent.GQAF |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.dcrat |
| ClamAV | Win.Malware.Gqaf-10058390-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen31.36139 |
| ESET-NOD32 | MSIL/Agent.VRB trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Agent.GQAF (B) |
| F-Secure | Heuristic.HEUR/AGEN.1323984 |
| Fortinet | W32/Agent.VRB!tr |
| GData | Trojan.Agent.GQAF |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0001140e1 ) |
| K7GW | Trojan ( 0001140e1 ) |
| Kaspersky | UDS:Backdoor.MSIL.DcRat |
| Kingsoft | MSIL.Backdoor.DcRat.gen |
| Lionic | Trojan.Win32.DCRat.4!c |
| Malwarebytes | Spyware.Passwordstealer |
| MaxSecure | Trojan.Malware.578650111.susgen |
| McAfeeD | Real Protect-LS!BB140985200D |
| MicroWorld-eScan | Trojan.Agent.GQAF |
| Microsoft | Trojan:Win32/DCRat.MX!MTB |
| Paloalto | generic.ml |
| Rising | Trojan.Agent!8.B1E (CLOUD) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Stealer |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Injector.tc |
| Sophos | Troj/DCRat-AC |
| Tencent | Trojan.Msil.Agent.16002036 |
| TrellixENS | GenericRXWS-RE!BB140985200D |
| VBA32 | Trojan.Agent |
| VIPRE | Trojan.Agent.GQAF |
| Varist | W32/Trojan.LOUW-4466 |
| ViRobot | Trojan.Win.Z.Agent.1773568.QDK |
| VirIT | Trojan.Win32.GenusC.IME |
| Webroot | Win.Malware.Gen |
| ZoneAlarm | Troj/DCRat-AC |
| alibabacloud | Trojan:MSIL/DCRat.MD8PHU |
| huorong | Backdoor/DcRAT.e |
| tehtris | Generic.Malware |