2026-05-24_1f28e4081a12ad59a4399d1244e08b00_coinminer_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
Classification: Malicious
2026-05-24_1f28e4081a12ad59a4399d1244e08b00_coinminer_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee is a malicious file sample.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Snojan |
Triage |
2026-05-24 09:44:17 |
2026-05-24 09:44:17 |
malicious-activity
|
|
Tags
snojan
discovery
downloader
upx
Sample information
- Filenames
- 2026-05-24_1f28e4081a12ad59a4399d1244e08b00_coinminer_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
- SHA-256
15478a3e0d51ff942654a5bdab336ce2468c80066215fc956db130526ed28e52
- First indexed
- 2026-05-24 09:44:17
- Last updated
- 2026-09-03 00:54:48
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Agent.CYZT |
| APEX | Malicious |
| AVG | Win32:Banker-LAA [Trj] |
| Acronis | suspicious |
| AhnLab-V3 | Downloader/Win.Generic.R665906 |
| Antiy-AVL | HackTool[Flooder]/Win32.CoreWarrior |
| Arcabit | Trojan.Agent.CYZT |
| Avast | Win32:Banker-LAA [Trj] |
| Avira | TR/Crypt.ULPM.Gen2 |
| BitDefender | Trojan.Agent.CYZT |
| Bkav | W32.Malware.E493A7D8 |
| CAT-QuickHeal | Trojan.AgentbPMF.S33725804 |
| CTX | exe.trojan.cyzt |
| ClamAV | Win.Malware.Cymt-10023133-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Tool.Snojan.1 |
| ESET-NOD32 | Win32/Agent.AAEF trojan |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Trojan.Agent.CYZT (B) |
| F-Secure | Trojan.TR/Crypt.ULPM.Gen2 |
| Fortinet | Riskware/Snojan |
| GData | Win32.Application.Snojan.A |
| Google | Detected |
| Ikarus | Trojan.Agent |
| Jiangmin | Downloader.Snojan.adp |
| K7AntiVirus | Trojan ( 005c835f1 ) |
| K7GW | Trojan ( 005464da1 ) |
| Kaspersky | Flooder.Win32.CoreWarrior.aa |
| Malwarebytes | Trojan.Downloader |
| MaxSecure | Trojan.Malware.325666027.susgen |
| McAfeeD | Real Protect-LS!1F28E4081A12 |
| MicroWorld-eScan | Trojan.Agent.CYZT |
| Microsoft | Trojan:Win32/CoreWarrior.DA!MTB |
| NANO-Antivirus | Trojan.Win32.Snojan.jqzopm |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Agent!1.B576 (C64:YzY0Ol25WmiKQCOL) |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Troj/Bdoor-BHD |
| Symantec | Hacktool.Flooder |
| Tencent | Trojan.Win32.Corewarrior.ca |
| Trapmine | suspicious.low.ml.score |
| TrellixENS | GenericRXWT-SU!3405D10BF52F |
| VBA32 | Flooder.CoreWarrior |
| VIPRE | Trojan.Agent.CYZT |
| Varist | W32/Agent.FBOO-5422 |
| VirIT | Trojan.Win32.AgentT.DYK |
| Webroot | W32.Malware.gen |
| Xcitium | TrojWare.Win32.Snojan.B@7h1cjp |
| Yandex | Riskware.Flooder!j7BYbbJGLUM |
| Zillya | Tool.CoreWarrior.Win32.18 |
| ZoneAlarm | Troj/Bdoor-BHD |
| alibabacloud | DDoS:Win/Nemucod |
| huorong | HVM:TrojanDownloader/Small.gen!A |