Classification: Malicious
lkwgbwlr.dll is a malicious file sample. Linked to Pwdump malware. Reported by 1 threat source, last seen 2020-08-12. Detected by 73 antivirus engines.
Detection summary
- 73 antivirus detections (54% detection ratio)
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| PWDump |
Hybrid-Analysis |
2020-08-12 14:15:05 |
2020-08-12 14:15:05 |
|
S0006 pwdump
|
Sample information
- Filenames
- lkwgbwlr.dll
- File type
- PE32+ executable (DLL) (GUI) x86-64, for MS Windows
- Size
- 68608 bytes
- MD5
b7afefd9d486183beed91b8b99c70da4
- SHA-1
76569b37d92ea16526c2bc1202ab326d5109d7fe
- SHA-256
24a7c13b200db5e0880dcbfe3b5c8789027c86b0a976df31853c908d1e5671ef
- First indexed
- 2020-08-12 14:15:05
- Last updated
- 2025-10-28 22:30:38
Antivirus detections
| Engine | Detection |
| McAfee | PWCrack-Pwdump |
| Zillya | Tool.PWDump.Win64.8 |
| AegisLab | PSWTool.W32.PWDump.bky!c |
| TheHacker | Trojan/Genome.afkbe |
| K7GW | Riskware ( 0015e4f01 ) |
| K7AntiVirus | Riskware ( 0015e4f01 ) |
| TrendMicro | HKTL_PWDUMP |
| Cyren | W64/Risk.CQLG-1160 |
| Symantec | Pwdump |
| ESET-NOD32 | Win64/PSWTool.PWDump.C potentially unsafe |
| TrendMicro-HouseCall | HKTL_PWDUMP |
| Avast | Win64:Malware-gen |
| Kaspersky | not-a-virus:PSWTool.Win64.PWDump.t |
| NANO-Antivirus | Trojan.Win64.Pwdump.dvqsf |
| DrWeb | Trojan.Click2.40849 |
| VIPRE | Trojan.Win32.Generic!BT |
| McAfee-GW-Edition | PWCrack-Pwdump |
| F-Prot | W64/MalwareF.SYSV |
| Jiangmin | Trojan/Genome.byhk |
| Webroot | HackTool:Win64.PWDump |
| Avira | SPR/PWDum.A |
| Antiy-AVL | Trojan[PSWTool]/Win32.PWDump |
| Microsoft | HackTool:Win64/PWDump |
| Endgame | malicious (high confidence) |
| ZoneAlarm | not-a-virus:PSWTool.Win64.PWDump.t |
| GData | Win64.Application.Agent.2LVZCN |
| AVware | Trojan.Win32.Generic!BT |
| VBA32 | Trojan.Genome.af |
| Yandex | Trojan.PWDum!1VGf3lPlzqc |
| AVG | HackTool.PMV |
| Panda | Trj/CI.A |
| Qihoo-360 | Win32/Virus.PSW.5cd |
| ALYac | Generic.LsassDump.E.77549358 |
| AVG | Win64:PUP-gen [PUP] |
| Arcabit | Generic.LsassDump.E.D49F4F2E |
| Avast | Win64:PUP-gen [PUP] |
| BitDefender | Generic.LsassDump.E.77549358 |
| Bkav | W64.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.1723753432c70da4 |
| CTX | dll.trojan.pwdump |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Generic.LsassDump.E.77549358 (B) |
| F-Secure | PrivacyRisk.SPR/PWDum.A |
| Fortinet | Riskware/PWDump |
| GData | Generic.LsassDump.E.77549358 |
| Google | Detected |
| Ikarus | not-a-virus:PSWTool.Win32.PWDump |
| K7AntiVirus | Unwanted-Program ( 004d38111 ) |
| K7GW | Unwanted-Program ( 004d38111 ) |
| Kaspersky | HackTool.Win32.PWDump.da |
| Kingsoft | Win32.PSWTroj.Undef.a |
| Lionic | Hacktool.Win32.PWDump.3!c |
| Malwarebytes | Malware.AI.349375911 |
| MaxSecure | Trojan.Malware.318647035.susgen |
| McAfeeD | ti!24A7C13B200D |
| MicroWorld-eScan | Generic.LsassDump.E.77549358 |
| Paloalto | generic.ml |
| Rising | HackTool.PWDump!8.13AA (TFE:5:twaJ6xsloLM) |
| Sangfor | Hacktool.Win64.Pwdump.Vk6f |
| Skyhigh | PWCrack-Pwdump.j |
| Symantec | ML.Attribute.HighConfidence |
| TACHYON | Trojan/W32.Agent.68608.LG |
| Tencent | Malware.Win32.Gencirc.115e2319 |
| TrellixENS | PWCrack-Pwdump.j |
| VBA32 | Trojan.Click |
| VIPRE | Generic.LsassDump.E.77549358 |
| Varist | W64/Risk.CQLG-1160 |
| VirIT | Trojan.Win32.Click2.CILD |
| Yandex | Trojan.GenAsa!bX+owrG1kHo |
| alibabacloud | HackTool:Win/PSWTool.PI#xfV |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | %WINDIR%\System32\rundll32.exe "C:\lkwgbwlr.dll",#1 |
| rundll32.exe | "C:\lkwgbwlr.dll",#1 |
| rundll32.exe | %WINDIR%\System32\rundll32.exe "C:\lkwgbwlr.dll",#2 |
| rundll32.exe | "C:\lkwgbwlr.dll",#2 |