lkwgbwlr.dll

Classification: Malicious

lkwgbwlr.dll is a malicious file sample. Linked to Pwdump malware. Reported by 1 threat source, last seen 2020-08-12. Detected by 73 antivirus engines.

Detection summary

  • 73 antivirus detections (54% detection ratio)
  • 0 IDS alerts
  • 5 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: PWDUMP (S0006)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
PWDump Hybrid-Analysis 2020-08-12 14:15:05 2020-08-12 14:15:05 S0006 pwdump

Tags

hacktool

Sample information

Filenames
lkwgbwlr.dll
File type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Size
68608 bytes
MD5
b7afefd9d486183beed91b8b99c70da4
SHA-1
76569b37d92ea16526c2bc1202ab326d5109d7fe
SHA-256
24a7c13b200db5e0880dcbfe3b5c8789027c86b0a976df31853c908d1e5671ef
First indexed
2020-08-12 14:15:05
Last updated
2025-10-28 22:30:38

Antivirus detections

EngineDetection
McAfeePWCrack-Pwdump
ZillyaTool.PWDump.Win64.8
AegisLabPSWTool.W32.PWDump.bky!c
TheHackerTrojan/Genome.afkbe
K7GWRiskware ( 0015e4f01 )
K7AntiVirusRiskware ( 0015e4f01 )
TrendMicroHKTL_PWDUMP
CyrenW64/Risk.CQLG-1160
SymantecPwdump
ESET-NOD32Win64/PSWTool.PWDump.C potentially unsafe
TrendMicro-HouseCallHKTL_PWDUMP
AvastWin64:Malware-gen
Kasperskynot-a-virus:PSWTool.Win64.PWDump.t
NANO-AntivirusTrojan.Win64.Pwdump.dvqsf
DrWebTrojan.Click2.40849
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWCrack-Pwdump
F-ProtW64/MalwareF.SYSV
JiangminTrojan/Genome.byhk
WebrootHackTool:Win64.PWDump
AviraSPR/PWDum.A
Antiy-AVLTrojan[PSWTool]/Win32.PWDump
MicrosoftHackTool:Win64/PWDump
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:PSWTool.Win64.PWDump.t
GDataWin64.Application.Agent.2LVZCN
AVwareTrojan.Win32.Generic!BT
VBA32Trojan.Genome.af
YandexTrojan.PWDum!1VGf3lPlzqc
AVGHackTool.PMV
PandaTrj/CI.A
Qihoo-360Win32/Virus.PSW.5cd
ALYacGeneric.LsassDump.E.77549358
AVGWin64:PUP-gen [PUP]
ArcabitGeneric.LsassDump.E.D49F4F2E
AvastWin64:PUP-gen [PUP]
BitDefenderGeneric.LsassDump.E.77549358
BkavW64.AIDetectMalware
CAT-QuickHealTrojan.Ghanarava.1723753432c70da4
CTXdll.trojan.pwdump
CylanceUnsafe
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
Elasticmalicious (moderate confidence)
EmsisoftGeneric.LsassDump.E.77549358 (B)
F-SecurePrivacyRisk.SPR/PWDum.A
FortinetRiskware/PWDump
GDataGeneric.LsassDump.E.77549358
GoogleDetected
Ikarusnot-a-virus:PSWTool.Win32.PWDump
K7AntiVirusUnwanted-Program ( 004d38111 )
K7GWUnwanted-Program ( 004d38111 )
KasperskyHackTool.Win32.PWDump.da
KingsoftWin32.PSWTroj.Undef.a
LionicHacktool.Win32.PWDump.3!c
MalwarebytesMalware.AI.349375911
MaxSecureTrojan.Malware.318647035.susgen
McAfeeDti!24A7C13B200D
MicroWorld-eScanGeneric.LsassDump.E.77549358
Paloaltogeneric.ml
RisingHackTool.PWDump!8.13AA (TFE:5:twaJ6xsloLM)
SangforHacktool.Win64.Pwdump.Vk6f
SkyhighPWCrack-Pwdump.j
SymantecML.Attribute.HighConfidence
TACHYONTrojan/W32.Agent.68608.LG
TencentMalware.Win32.Gencirc.115e2319
TrellixENSPWCrack-Pwdump.j
VBA32Trojan.Click
VIPREGeneric.LsassDump.E.77549358
VaristW64/Risk.CQLG-1160
VirITTrojan.Win32.Click2.CILD
YandexTrojan.GenAsa!bX+owrG1kHo
alibabacloudHackTool:Win/PSWTool.PI#xfV

Process list

NameCommand line
<Ignored Process>
rundll32.exe%WINDIR%\System32\rundll32.exe "C:\lkwgbwlr.dll",#1
rundll32.exe"C:\lkwgbwlr.dll",#1
rundll32.exe%WINDIR%\System32\rundll32.exe "C:\lkwgbwlr.dll",#2
rundll32.exe"C:\lkwgbwlr.dll",#2