sub_2d563dd113a0.bin

Classification: Malicious

sub_2d563dd113a0.bin is a malicious file sample. Linked to Egregor malware. Reported by 2 threat sources, last seen 2026-05-24.

Detection summary

  • 28 antivirus detections (41% detection ratio)
  • 0 IDS alerts
  • 3 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: EGREGOR (S0554)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Egregor Triage 2026-05-24 02:03:13 2026-05-24 02:03:13 malicious-activity S0554 Egregor
Gen:Variant.Mikey Hybrid-Analysis 2020-10-09 09:15:06 2020-10-09 09:15:06

Tags

egregor discovery ransomware

Sample information

Filenames
sub_2d563dd113a0.bin, q.dll
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
Size
785408 bytes
MD5
3c18331989cb006506338ed1f838430d
SHA-1
0579da0b8bfdfce7ca4a45baf9df7ec23989e28b
SHA-256
2d563dd113a02fdf452544ae2fd7c94162be6db8fb7a287a3474a6ab998159fd
First indexed
2020-10-09 09:15:06
Last updated
2026-07-15 22:10:40

Antivirus detections

EngineDetection
BkavW32.AIDetectVM.malware1
McAfeeArtemis!3C18331989CB
AlibabaTrojan:Win32/Kryptik.79e2fac0
CrowdStrikewin/malicious_confidence_60% (D)
InvinceaML/PE-A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HGHT
Paloaltogeneric.ml
BitDefenderGen:Variant.Mikey.115731
MicroWorld-eScanGen:Variant.Mikey.115731
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Mikey.115731
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Mikey.115731
EmsisoftGen:Variant.Mikey.115731 (B)
WebrootW32.Trojan.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Mikey.D1C413
AegisLabTrojan.Win32.Mikey.4!c
GDataGen:Variant.Mikey.115731
AhnLab-V3Trojan/Win32.Cryptor.C4064147
ALYacGen:Variant.Mikey.115731
RisingTrojan.Kryptik!8.8 (TFE:5:TQnB9jm946K)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_98%
AVGWin32:CrypterX-gen [Trj]

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\q.dll",#1
rundll32.exe"C:\q.dll",#3