1d1decac693bfc7c19e26f01929716924d7607e300f8385a7a8a02d176800db5
Classification: Malicious
1d1decac693bfc7c19e26f01929716924d7607e300f8385a7a8a02d176800db5 is a malicious file sample. Linked to Mimikatz, Maze malware.
Detection summary
- 43 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: MIMIKATZ (S0002) MAZE (S0449)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Bitrat | Triage | 2026-04-22 12:03:44 | 2026-07-28 14:04:24 | malicious-activity | |
| Maze | Triage | 2026-03-09 19:16:30 | 2026-03-09 19:16:30 | malicious-activity | S0449 Maze |
| Kpot | Triage | 2026-03-09 18:29:59 | 2026-03-09 18:29:59 | malicious-activity | |
| Mimikatz | Triage | 2026-02-23 06:25:01 | 2026-02-23 06:25:01 | malicious-activity | S0002 Mimikatz |
Tags
bitrat blackmatter bpfdoor bruteratel cobaltstrike darkcomet dharma egregor gafgyt gh0strat gozi kpot latrodectus meduza metasploit mimikatz netwalker netwire ploutus pony predatorstealer pubload purplefox qakbot runningrat sodinokibi stealc systembc toneshell xmrig zebrocy $2a$10$qxscf5cdia/z/fajtwcmlei3gljcolzkvzc78fqd3ac2xdlebudjw $2a$10$yamp3nict2cddmxcwgfmso8kdqueiafw/m3lwazfqerf9xglgmaui 0 4e591a315c54e8800dae714320555fa5 aa b5 guest16 kapitan 1649660679 4525 5012 earth_preta mustang_panda apt aspackv2 backdoor botnet credential_access defense_evasion discovery execution impact installer isfb linux loader miner persistence pyinstaller ransomware rat rootkit spyware stealer themida upx vmprotect virtualgate maze phobos evasion privilege_escalation trojan atm banker revoked_codesign adware costura packerSample information
- Filenames
- 1d1decac693bfc7c19e26f01929716924d7607e300f8385a7a8a02d176800db5
- MD5
abe6a27d681b0e8f91e2a3a3039ee341- SHA-1
f1548376f89a8332cb3ec142397e3c1b9c93046c- SHA-256
1d1decac693bfc7c19e26f01929716924d7607e300f8385a7a8a02d176800db5- SHA-512
02862b054c2f87d29e1729aa71fe793f7f0d226314dc3dc5317db3dac7ec77586cabcc13dd3c866f9c7786fc3b51f9832f095516dd467d8b5a08e9a4836747bf- First indexed
- 2026-02-23 06:25:01
- Last updated
- 2026-07-28 14:56:24
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.Doina.28250 |
| AVG | Win32:MalwareX-gen [Ransom] |
| Acronis | suspicious |
| AhnLab-V3 | Ransomware/Win.Crysis.R213980 |
| Arcabit | Trojan.Ransom.Crysis.E [many] |
| Avast | Win32:MalwareX-gen [Ransom] |
| Avast-Mobile | ELF:DDoS-S [Trj] |
| Avira | TR/Dropper.Gen |
| BitDefender | Trojan.Ransom.Crysis.E |
| CTX | zip.trojan.crysis |
| DrWeb | Trojan.Encoder.3953 |
| ESET-NOD32 | Win32/Filecoder.Crysis.P trojan |
| Elastic | Windows.Ransomware.Dharma |
| Emsisoft | Trojan.FileCoder (A) |
| F-Secure | Trojan.TR/Dropper.Gen |
| Fortinet | W32/Crysis.L!tr.ransom |
| GData | Win32.Virus.Floxif.B |
| Ikarus | Trojan-Ransom.Crysis |
| Jiangmin | Trojan.Generic.dkxeo |
| K7AntiVirus | Ransomware ( 005cfd1d1 ) |
| K7GW | Ransomware ( 005cfd1d1 ) |
| Kaspersky | Trojan-Ransom.Win32.Crusis.to |
| Kingsoft | malware.kb.a.1000 |
| Lionic | Trojan.ZIP.Crysis.j!c |
| NANO-Antivirus | Trojan.Win32.Filecoder.emdnxn |
| Rising | Trojan.Webshell/ASP!8.1333D (TOPIS:E0:hKczyWhVKjF) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious Archive |
| Skyhigh | ASP/Webshell.m |
| Symantec | Ransom.Zombie |
| Tencent | Asp.Backdoor.Agent.Ymhl |
| TrellixENS | Ransom-Dharma!009C2377B679 |
| TrendMicro | Ransom.Win32.CRYSIS.SM |
| TrendMicro-HouseCall | Ransom.Win32.CRYSIS.SM |
| VIPRE | Trojan.Ransom.Crysis.E |
| Varist | W32/Trojan.ILHO-9216 |
| VirIT | Trojan.Win32.Generic.IXL |
| Webroot | W32.Ransom.Gen |
| Yandex | Trojan.GenAsa!PU4zXkABPRE |
| Zillya | Dropper.Crusis.Win32.175 |
| ZoneAlarm | Troj/Criakl-G |
| Zoner | Probably Heur.ExeHeaderP |
| alibabacloud | Ransomware:Win/Zusy.7c5222b1 |