Classification: Malicious
sub_2d563dd113a0.bin is a malicious file sample. Linked to Egregor malware. Reported by 2 threat sources, last seen 2026-05-24.
Detection summary
- 28 antivirus detections (41% detection ratio)
- 0 IDS alerts
- 3 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Egregor |
Triage |
2026-05-24 02:03:13 |
2026-05-24 02:03:13 |
malicious-activity
|
S0554 Egregor
|
| Gen:Variant.Mikey |
Hybrid-Analysis |
2020-10-09 09:15:06 |
2020-10-09 09:15:06 |
|
|
Tags
egregor
discovery
ransomware
Sample information
- Filenames
- sub_2d563dd113a0.bin, q.dll
- File type
- PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
- Size
- 785408 bytes
- MD5
3c18331989cb006506338ed1f838430d
- SHA-1
0579da0b8bfdfce7ca4a45baf9df7ec23989e28b
- SHA-256
2d563dd113a02fdf452544ae2fd7c94162be6db8fb7a287a3474a6ab998159fd
- First indexed
- 2020-10-09 09:15:06
- Last updated
- 2026-07-15 22:10:40
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectVM.malware1 |
| McAfee | Artemis!3C18331989CB |
| Alibaba | Trojan:Win32/Kryptik.79e2fac0 |
| CrowdStrike | win/malicious_confidence_60% (D) |
| Invincea | ML/PE-A |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Kryptik.HGHT |
| Paloalto | generic.ml |
| BitDefender | Gen:Variant.Mikey.115731 |
| MicroWorld-eScan | Gen:Variant.Mikey.115731 |
| Avast | Win32:CrypterX-gen [Trj] |
| Ad-Aware | Gen:Variant.Mikey.115731 |
| McAfee-GW-Edition | Artemis!Trojan |
| FireEye | Gen:Variant.Mikey.115731 |
| Emsisoft | Gen:Variant.Mikey.115731 (B) |
| Webroot | W32.Trojan.Gen |
| MAX | malware (ai score=89) |
| Antiy-AVL | Trojan/Win32.Kryptik |
| Microsoft | Trojan:Win32/Wacatac.C!ml |
| Arcabit | Trojan.Mikey.D1C413 |
| AegisLab | Trojan.Win32.Mikey.4!c |
| GData | Gen:Variant.Mikey.115731 |
| AhnLab-V3 | Trojan/Win32.Cryptor.C4064147 |
| ALYac | Gen:Variant.Mikey.115731 |
| Rising | Trojan.Kryptik!8.8 (TFE:5:TQnB9jm946K) |
| Ikarus | Trojan.Win32.Crypt |
| eGambit | Unsafe.AI_Score_98% |
| AVG | Win32:CrypterX-gen [Trj] |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\q.dll",#1 |
| rundll32.exe | "C:\q.dll",#3 |