1af2037acbabfe804a522a5c4dd5a4ce.exe
Classification: Malicious
1af2037acbabfe804a522a5c4dd5a4ce.exe is a malicious file sample. Linked to Sandworm Team, Earth Lusca activity. Detected by 56 antivirus engines.
Detection summary
- 56 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034) EARTH LUSCA (G1006)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:12 | malicious-activity | G0034 Sandworm Team |
| Earth Lusca | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:09 | malicious-activity | G1006 Earth Lusca |
| TitanStealer | MalwareBazaar Abuse.ch | 2022-12-25 13:52:56 | 2022-12-25 13:52:56 | malicious-activity |
Tags
aptSample information
- Filenames
- 1af2037acbabfe804a522a5c4dd5a4ce.exe
- File type
- application/x-dosexec
- MD5
1af2037acbabfe804a522a5c4dd5a4ce- SHA-1
119f5b7da9e57bad8b618c660d21a91d06d1795c- SHA-256
152ef5fcd0278e127c3df415018857f3aed0a748160032356786815ccbe870d5- First indexed
- 2022-12-27 12:19:21
- Last updated
- 2023-03-03 14:34:13
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Coins.tse2 |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Trojan.GenericKD.63377737 |
| ALYac | Trojan.Stealer.Titan |
| Cylance | Unsafe |
| Sangfor | Infostealer.Win32.Coins.V2tm |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | Trojan:Win32/runner.ali1000123 |
| K7GW | Trojan ( 0059a53d1 ) |
| K7AntiVirus | Trojan ( 0059a53d1 ) |
| Cyren | W32/ABRisk.KOLM-8081 |
| Symantec | Infostealer |
| ESET-NOD32 | a variant of Win32/Kryptik.HRKB |
| APEX | Malicious |
| Paloalto | generic.ml |
| Cynet | Malicious (score: 99) |
| Kaspersky | Trojan-PSW.Win32.Coins.advp |
| BitDefender | Trojan.GenericKD.63377737 |
| NANO-Antivirus | Trojan.Win32.Inject.jtihbz |
| Tencent | Win32.Trojan-QQPass.QQRob.Ljgl |
| Emsisoft | Trojan.GenericKD.63377737 (B) |
| F-Secure | Trojan.TR/AD.Inject.gnkcs |
| DrWeb | Trojan.DownLoader45.31326 |
| VIPRE | Trojan.GenericKD.63377737 |
| TrendMicro | TROJ_GEN.R002C0DK322 |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.vc |
| Trapmine | suspicious.low.ml.score |
| FireEye | Trojan.GenericKD.63377737 |
| Sophos | Mal/Generic-S |
| Jiangmin | Trojan.PSW.Coins.jvt |
| Webroot | W32.Trojan.GenKD |
| Avira | TR/AD.Inject.gnkcs |
| Antiy-AVL | Trojan/Win32.Kryptik |
| Kingsoft | Win32.PSWTroj.Undef.(kcloud) |
| Microsoft | Trojan:Win32/Redline.RE!MTB |
| Xcitium | Malware@#nbotf81ssa5 |
| Arcabit | Trojan.Generic.D3C71149 |
| ViRobot | Trojan.Win32.S.Agent.2947359 |
| ZoneAlarm | Trojan-PSW.Win32.Coins.advp |
| GData | Trojan.GenericKD.63377737 |
| Detected | |
| AhnLab-V3 | Trojan/Win.RedLine.C5290298 |
| McAfee | Artemis!1AF2037ACBAB |
| MAX | malware (ai score=85) |
| VBA32 | BScope.TrojanPSW.Arkei |
| Malwarebytes | Trojan.Vidar |
| Panda | Trj/CI.A |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DK322 |
| Rising | Stealer.Coins!8.133E9 (CLOUD) |
| Yandex | Trojan.Kryptik!7LkSxhntt4g |
| Ikarus | Trojan.Win32.Crypt |
| MaxSecure | Trojan.Malware.73640957.susgen |
| Fortinet | W32/DotNetPacker.I!tr |
| BitDefenderTheta | Gen:NN.ZexaE.36276.Z!ZaaC9zBqg |
| AVG | Win32:PWSX-gen [Trj] |
| Avast | Win32:PWSX-gen [Trj] |