30c1f93a3d798bb18ef3439db0ada4e0059e1f6ddd5d860ec993393b31a62842
Classification: Malicious
30c1f93a3d798bb18ef3439db0ada4e0059e1f6ddd5d860ec993393b31a62842 is a malicious file sample. Linked to Sandworm Team, Earth Lusca activity.
Detection summary
- 50 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034) EARTH LUSCA (G1006)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:13 | malicious-activity | G0034 Sandworm Team |
| Earth Lusca | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:10 | malicious-activity | G1006 Earth Lusca |
Tags
aptSample information
- SHA-256
30c1f93a3d798bb18ef3439db0ada4e0059e1f6ddd5d860ec993393b31a62842- First indexed
- 2023-03-03 14:34:10
- Last updated
- 2023-03-03 14:34:13
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Strab.tsdR |
| Cynet | Malicious (score: 99) |
| ALYac | Trojan.Stealer.Titan |
| Cylance | Unsafe |
| Zillya | Trojan.Coins.Win32.7583 |
| Sangfor | Infostealer.Win32.Coins.V6yh |
| K7AntiVirus | Trojan ( 0059a78f1 ) |
| Alibaba | TrojanPSW:Win32/Coins.07ca010a |
| K7GW | Trojan ( 0059a78f1 ) |
| Cyren | W32/ABRisk.MHKZ-4244 |
| Symantec | Trojan Horse |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | a variant of WinGo/PSW.Agent.CF |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | Trojan-PSW.Win32.Coins.adwj |
| BitDefender | Gen:Variant.Babar.116134 |
| NANO-Antivirus | Trojan.Win32.Coins.jtiehn |
| MicroWorld-eScan | Gen:Variant.Babar.116134 |
| Avast | Win32:Evo-gen [Trj] |
| Tencent | Win32.Trojan-QQPass.QQRob.Ychl |
| Emsisoft | Gen:Variant.Babar.116134 (B) |
| DrWeb | Trojan.PWS.Stealer.34906 |
| VIPRE | Gen:Variant.Babar.116134 |
| TrendMicro | TROJ_FRS.0NA103AQ23 |
| McAfee-GW-Edition | Artemis!Trojan |
| Trapmine | malicious.moderate.ml.score |
| FireEye | Gen:Variant.Babar.116134 |
| Ikarus | Trojan-Spy.TitanStealer |
| Webroot | W32.Trojan.Gen |
| Avira | TR/PSW.Agent.tzrpp |
| Antiy-AVL | Trojan[PSW]/Win32.Coins |
| Kingsoft | Win32.Troj.Generic.jm.(kcloud) |
| Microsoft | Trojan:Win32/TitanStealer.PA!MTB |
| Xcitium | Malware@#1ytf79syjed5h |
| Arcabit | Trojan.Babar.D1C5A6 |
| ZoneAlarm | Trojan-PSW.Win32.Coins.adwj |
| GData | Gen:Variant.Babar.116134 |
| Detected | |
| AhnLab-V3 | Infostealer/Win.Titan.R555644 |
| McAfee | Artemis!2815DEE54A6B |
| MAX | malware (ai score=100) |
| TrendMicro-HouseCall | TROJ_FRS.0NA103AQ23 |
| Rising | [email protected] (RDML:TQtfChGesXvyGZOWGZ9beA) |
| MaxSecure | Trojan.Malware.192423632.susgen |
| Fortinet | W32/Agent.CF!tr.pws |
| BitDefenderTheta | Gen:NN.ZexaF.36276.LF0@aensIGcO |
| AVG | Win32:Evo-gen [Trj] |
| Panda | Trj/Chgt.AD |
| CrowdStrike | win/malicious_confidence_100% (W) |