2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin

Classification: Malicious

2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin is a malicious file sample. Linked to Empire malware. Detected by 51 antivirus engines.

Detection summary

  • 51 antivirus detections
  • 1 IDS alerts
  • 0 processes observed
  • 1 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: EMPIRE (S0363)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2026-05-21 07:45:05 2026-05-21 07:45:05
Empire Triage 2026-05-21 06:51:18 2026-05-21 06:51:18 malicious-activity S0363 Empire

Tags

empire downloader evasive

Sample information

Filenames
2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin, 2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.exe
File type
PE32 executable for MS Windows 4.00 (GUI), Intel i ...
MD5
dcd9ed6e7367dfeec74b8928c8a27747
SHA-1
a811c0f18918ba42ed58de5ba1fc04347b8a102e
SHA-256
2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257
First indexed
2026-05-21 06:51:18
Last updated
2026-05-21 08:11:13

Antivirus detections

EngineDetection
ALYacGeneric.Trojan.Empire.A.7AA8D82F
APEXMalicious
AVGWin32:Sharpire-A [Hack]
AhnLab-V3Trojan/Win.Generic.C5339692
AlibabaTrojan:MSIL/Shempire.53b01691
ArcabitGeneric.Trojan.Empire.A.7AA8D82F
AvastWin32:Sharpire-A [Hack]
AviraHEUR/AGEN.1374794
BitDefenderGeneric.Trojan.Empire.A.7AA8D82F
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.Ghanarava.1681146120a27747
CTXexe.trojan.empire
ClamAVWin.Packed.Empire-9941915-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebBackDoor.GruntNET.1
ESET-NOD32a variant of MSIL/Agent.DLY
Elasticmalicious (high confidence)
EmsisoftGeneric.Trojan.Empire.A.7AA8D82F (B)
F-SecureHeuristic.HEUR/AGEN.1374794
FireEyeGeneric.mg.dcd9ed6e7367dfee
FortinetMSIL/Agent.DLY!tr
GDataGeneric.Trojan.Empire.A.7AA8D82F
GoogleDetected
K7AntiVirusTrojan ( 0057fcac1 )
K7GWTrojan ( 0057fcac1 )
KasperskyHEUR:Trojan.MSIL.Empire.b
Kingsoftmalware.kb.c.998
LionicTrojan.Win32.Empire.4!c
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.73938054.susgen
McAfeeDReal Protect-LS!DCD9ED6E7367
MicroWorld-eScanGeneric.Trojan.Empire.A.7AA8D82F
MicrosoftVirTool:MSIL/Shempire.B
NANO-AntivirusTrojan.Win32.Empire.jwjbes
Paloaltogeneric.ml
PandaTrj/GdSda.A
RisingTrojan.Empire!8.104E7 (CLOUD)
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.nm
SophosATK/Empire-AF
SymantecML.Attribute.HighConfidence
TencentMsil.Trojan.Empire.Uwhl
Trapminemalicious.moderate.ml.score
VIPREGeneric.Trojan.Empire.A.7AA8D82F
VaristW32/MSIL_Agent.FJE.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A
YandexTrojan.Empire!gw+QflQYwZI
ZillyaTrojan.Injector.Win32.499575
huorongTrojan/MSIL.Empire.a

Network contacts

167.172.141.2