stGui2.dll
Classification: Malicious
stGui2.dll is a malicious file sample. Linked to Ta505 activity. Reported by 1 threat source, last seen 2020-12-11. Detected by 58 antivirus engines.
Detection summary
- 58 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: TA505 (G0092)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic.Malware | Abuse.ch | 2020-12-11 17:57:30 | 2020-12-11 17:57:30 | malicious-activity | |
| TA505 | Abuse.ch | 2020-12-11 17:57:30 | 2020-12-11 17:57:30 | malicious-activity | G0092 TA505 |
Sample information
- Filenames
- stGui2.dll
- File type
- application/x-dosexec
- MD5
cbdbdf754e9f89b10a7a64aeca6b07d6- SHA-1
bf65f5a98e07f6125c6a98cf1f764a17c30e46d8- SHA-256
120816daada4aeb05da2ee888fe52f25c37b7aba3915da8534904b8247c8526b- First indexed
- 2020-12-11 19:15:10
- Last updated
- 2025-11-02 00:01:23
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.Zenpak |
| AVG | Win64:CrypterX-gen [Trj] |
| AhnLab-V3 | Trojan/Win64.Reflect.R357706 |
| Alibaba | Trojan:Win64/CryptInject.16c00200 |
| Antiy-AVL | Trojan/Win64.Agent |
| Arcabit | Trojan.Razy.DC497D |
| Avast | Win64:CrypterX-gen [Trj] |
| Avira | TR/Agent.zswly |
| BitDefender | Gen:Variant.Razy.805245 |
| Bkav | W64.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.17119223036b07d6 |
| CTX | dll.trojan.generic |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Packed2.42540 |
| ESET-NOD32 | Win64/Agent.ACO |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Razy.805245 (B) |
| F-Secure | Trojan.TR/Agent.zswly |
| FireEye | Generic.mg.cbdbdf754e9f89b1 |
| Fortinet | PossibleThreat.PALLAS.H |
| GData | Gen:Variant.Razy.805245 |
| Detected | |
| Gridinsoft | Trojan.Win64.Agent.oa!s1 |
| Ikarus | Trojan.Win64.Agent |
| K7AntiVirus | Trojan ( 0056c1f81 ) |
| K7GW | Trojan ( 0056c1f81 ) |
| Kaspersky | Trojan.Win32.Agentb.kgpy |
| Kingsoft | malware.kb.a.808 |
| Lionic | Trojan.Win32.Agentb.X!c |
| Malwarebytes | Malware.AI.3939811584 |
| MaxSecure | Trojan.Malware.1728101.susgen |
| McAfee | Artemis!CBDBDF754E9F |
| McAfeeD | ti!120816DAADA4 |
| MicroWorld-eScan | Gen:Variant.Razy.805245 |
| Microsoft | Trojan:Win64/CryptInject!MSR |
| NANO-Antivirus | Trojan.Win64.Razy.jninbj |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Trojan.Detplock!8.4A0D (TFE:4:C2a7idCOBrG) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.115c8fda |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9V |
| VBA32 | Trojan.Wacatac |
| VIPRE | Gen:Variant.Razy.805245 |
| Varist | W64/Agent.NCDI |
| ViRobot | Trojan.Win.Z.Agent.263680.BG |
| Webroot | W32.Malware.gen |
| Xcitium | Malware@#1xks10ynvu4yt |
| Yandex | Trojan.Agentb!niAp4N4FWfE |
| Zillya | Trojan.Agent.Win64.7003 |
| alibabacloud | Trojan:Win/Agentb.kgpy |
| huorong | TrojanDownloader/Agent.ud |