2026-03-14_1785faf841354f0a7ba4eaa16caf9c9f_coinminer_glassworm_icedid_njrat_ryuk_sliver
Classification: Malicious
2026-03-14_1785faf841354f0a7ba4eaa16caf9c9f_coinminer_glassworm_icedid_njrat_ryuk_sliver is a malicious file sample. Detected by 33 antivirus engines.
Detection summary
- 33 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Meshagent |
Triage |
2026-03-14 17:15:09 |
2026-03-14 17:15:09 |
malicious-activity
|
|
Sample information
- Filenames
- 2026-03-14_1785faf841354f0a7ba4eaa16caf9c9f_coinminer_glassworm_icedid_njrat_ryuk_sliver
- MD5
1785faf841354f0a7ba4eaa16caf9c9f
- SHA-1
fafe5e6cc114b6baf95d275bdf16c17717ee98bb
- SHA-256
37870b35bf7606391b43886ccd8445ce44a7b41bbdc3cb1f4896d2e629b6363a
- SHA-512
08f7ee5c41cc6a2be54a885a228ed3b5db2fb9881899948f83dd183a4c4dcec8f86eefbb61aa3abbfc70ae66876d0323e15b371ca2f0aef730ae5531d8ba4005
- First indexed
- 2026-03-14 17:15:09
- Last updated
- 2026-09-03 01:01:40
Antivirus detections
| Engine | Detection |
| AhnLab-V3 | Unwanted/Win.MeshCmd.R702482 |
| Antiy-AVL | RiskWare[RemoteAdmin]/Win32.MeshAgent |
| Bkav | W32.Malware.97487579 |
| CAT-QuickHeal | PUA.MeshAgent.S37934379 |
| CTX | exe.remote-access-trojan.meshagent |
| CrowdStrike | win/grayware_confidence_60% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Program.MeshAgent.3 |
| Elastic | malicious (high confidence) |
| Fortinet | Riskware/Application |
| Google | Detected |
| Gridinsoft | Risk.Win64.Gen.oa!s1 |
| K7AntiVirus | RemoteTool ( 005cedd21 ) |
| K7GW | RemoteTool ( 005cedd21 ) |
| Kaspersky | not-a-virus:UDS:RemoteAdmin.Win32.MeshAgent.gen |
| Kingsoft | Win32.HACKTOOL.RemoteAdmin.v |
| Lionic | Riskware.Win32.MeshAgent.1!c |
| Malwarebytes | Malware.AI.1335020330 |
| MaxSecure | Trojan.Malware.74716356.susgen |
| McAfeeD | ti!37870B35BF76 |
| Microsoft | Trojan:Win32/Qwexlafiba!rfn |
| Paloalto | generic.ml |
| Sangfor | PUP.Win32.Meshagent.V1rl |
| SentinelOne | Static AI - Suspicious PE |
| Sophos | Generic Reputation PUA (PUA) |
| Symantec | PUA.Gen.2 |
| TrellixENS | Remote-MeshAgent.a |
| TrendMicro-HouseCall | Trojan.Win32.ZYX.USBLG326 |
| VBA32 | Riskware.Win64.MeshAgent |
| Varist | W64/ABlApplication.BXEP-1452 |
| Webroot | Win.Trojan.Gen |
| alibabacloud | Backdoor[rat]:Win/MeshAgent.gyf |