2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin
Classification: Malicious
2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin is a malicious file sample. Linked to Empire malware. Detected by 51 antivirus engines.
Detection summary
- 51 antivirus detections
- 1 IDS alerts
- 0 processes observed
- 1 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: EMPIRE (S0363)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-05-21 07:45:05 | 2026-05-21 07:45:05 | ||
| Empire | Triage | 2026-05-21 06:51:18 | 2026-05-21 06:51:18 | malicious-activity | S0363 Empire |
Tags
empire downloader evasiveSample information
- Filenames
- 2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin, 2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.exe
- File type
- PE32 executable for MS Windows 4.00 (GUI), Intel i ...
- MD5
dcd9ed6e7367dfeec74b8928c8a27747- SHA-1
a811c0f18918ba42ed58de5ba1fc04347b8a102e- SHA-256
2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257- First indexed
- 2026-05-21 06:51:18
- Last updated
- 2026-05-21 08:11:13
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Generic.Trojan.Empire.A.7AA8D82F |
| APEX | Malicious |
| AVG | Win32:Sharpire-A [Hack] |
| AhnLab-V3 | Trojan/Win.Generic.C5339692 |
| Alibaba | Trojan:MSIL/Shempire.53b01691 |
| Arcabit | Generic.Trojan.Empire.A.7AA8D82F |
| Avast | Win32:Sharpire-A [Hack] |
| Avira | HEUR/AGEN.1374794 |
| BitDefender | Generic.Trojan.Empire.A.7AA8D82F |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Ghanarava.1681146120a27747 |
| CTX | exe.trojan.empire |
| ClamAV | Win.Packed.Empire-9941915-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.GruntNET.1 |
| ESET-NOD32 | a variant of MSIL/Agent.DLY |
| Elastic | malicious (high confidence) |
| Emsisoft | Generic.Trojan.Empire.A.7AA8D82F (B) |
| F-Secure | Heuristic.HEUR/AGEN.1374794 |
| FireEye | Generic.mg.dcd9ed6e7367dfee |
| Fortinet | MSIL/Agent.DLY!tr |
| GData | Generic.Trojan.Empire.A.7AA8D82F |
| Detected | |
| K7AntiVirus | Trojan ( 0057fcac1 ) |
| K7GW | Trojan ( 0057fcac1 ) |
| Kaspersky | HEUR:Trojan.MSIL.Empire.b |
| Kingsoft | malware.kb.c.998 |
| Lionic | Trojan.Win32.Empire.4!c |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.73938054.susgen |
| McAfeeD | Real Protect-LS!DCD9ED6E7367 |
| MicroWorld-eScan | Generic.Trojan.Empire.A.7AA8D82F |
| Microsoft | VirTool:MSIL/Shempire.B |
| NANO-Antivirus | Trojan.Win32.Empire.jwjbes |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Trojan.Empire!8.104E7 (CLOUD) |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.nm |
| Sophos | ATK/Empire-AF |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Msil.Trojan.Empire.Uwhl |
| Trapmine | malicious.moderate.ml.score |
| VIPRE | Generic.Trojan.Empire.A.7AA8D82F |
| Varist | W32/MSIL_Agent.FJE.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Yandex | Trojan.Empire!gw+QflQYwZI |
| Zillya | Trojan.Injector.Win32.499575 |
| huorong | Trojan/MSIL.Empire.a |