2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0.dll
Classification: Malicious
2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0.dll is a malicious file sample. Linked to Sunburst malware. Detected by 57 antivirus engines.
Detection summary
- 57 antivirus detections (51% detection ratio)
- 0 IDS alerts
- 4 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-03-28 03:00:06 |
2025-03-28 04:15:17 |
|
|
| Generic.Malware |
Abuse.ch |
2020-12-27 05:49:00 |
2020-12-27 05:49:00 |
malicious-activity
|
|
| SUNBURST |
Abuse.ch |
2020-12-27 05:49:00 |
2020-12-27 05:49:00 |
malicious-activity
|
S0559 SUNBURST
|
| Generic.Sunburst.2 |
Hybrid-Analysis |
2020-12-17 16:00:17 |
2020-12-17 16:00:17 |
|
|
Sample information
- Filenames
- 2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0.dll, tmpwfi0uyqe, SolarWinds.Orion.Core.BusinessLayer.dll
- File type
- application/x-dosexec
- Size
- 1028072 bytes
- MD5
f492697f34c9885035295abdf46acce0
- SHA-1
cba7a712bf00b94f1cea4c476a12ce41e9c40333
- SHA-256
2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0
- First indexed
- 2020-12-17 16:00:17
- Last updated
- 2026-07-10 21:41:56
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.MSIL.SunBurst |
| AVG | MSIL:SunBurst-C [Bd] |
| AhnLab-V3 | Backdoor/Win32.SunBurst.R357806 |
| Antiy-AVL | Trojan/MSIL.SunBurst |
| Arcabit | Trojan.Sunburst.E |
| Avast | MSIL:SunBurst-C [Bd] |
| Avira | HEUR/AGEN.1300870 |
| BitDefender | Trojan.Sunburst.E |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Backdoor.Sunburst.S17554866 |
| CTX | dll.trojan.sunburst |
| ClamAV | Win.Countermeasure.Sunburst-9809152-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.SiggenNET.14 |
| ESET-NOD32 | a variant of MSIL/SunBurst.A |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Sunburst.E (B) |
| F-Secure | Trojan:W32/Sunburst.F |
| FireEye | Generic.mg.f492697f34c98850 |
| Fortinet | W32/Sunburst.A!tr |
| GData | Trojan.Sunburst.E |
| Google | Detected |
| Ikarus | Trojan.MSIL.Sunburst |
| Jiangmin | Backdoor.MSIL.eafu |
| K7AntiVirus | Trojan ( 00574b2b1 ) |
| K7GW | Trojan ( 00574b2b1 ) |
| Kaspersky | HEUR:Backdoor.MSIL.SunBurst.gen |
| Lionic | Trojan.MSIL.SunBurst.trD4 |
| Malwarebytes | Malware.AI.3840279257 |
| MaxSecure | Trojan.Malware.110927998.susgen |
| McAfee | Trojan-Sunburst!F492697F34C9 |
| McAfeeD | ti!2ADE1AC8911A |
| MicroWorld-eScan | Trojan.Sunburst.E |
| Microsoft | Trojan:MSIL/Solorigate!atmn |
| NANO-Antivirus | Trojan.Win32.SunBurst.iebfsd |
| Paloalto | generic.ml |
| Panda | Trj/Solorigate.A |
| Rising | Backdoor.[APT29]SunBurst!1.D029 (CLASSIC) |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | Trojan-Sunburst!F492697F34C9 |
| Sophos | Mal/Generic-S |
| Symantec | Backdoor.Sunburst!gen1 |
| TACHYON | Backdoor/W32.DN-Sunburst.1028072 |
| Tencent | Win32.Trojan.FalseSign.Rwhl |
| TrendMicro | Backdoor.MSIL.SUNBURST.YXAL-Q |
| TrendMicro-HouseCall | Backdoor.MSIL.SUNBURST.YXAL-Q |
| VBA32 | TScope.Trojan.MSIL |
| VIPRE | Trojan.Sunburst.E |
| Varist | W32/MSIL_SunBurst.A.gen!Eldorado |
| ViRobot | Backdoor.Win32.S.SunBurst.1028072 |
| Webroot | W32.Trojan.Sunburst |
| Xcitium | Malware@#3l3eioeqndao7 |
| Yandex | Trojan.Redcap!6bnf+b58KQY |
| alibabacloud | Backdoor:MSIL/SunBurst.A |
| huorong | Backdoor/MSIL.SunBurst.a |
Process list
| Name | Command line |
| <Ignored Process> | |
| regsvr32.exe | /s "C:\2ade1ac8911ad6a23498230a5e119516db47f6e76687f804e2512cc9bcfda2b0.dll" |
| <Ignored Process> | |
| regsvr32.exe | /s "C:\tmpwfi0uyqe.dll" |