40b479d2688a659e57197715395f78c1801d4ed2ff275d59149c52ec9fb01498
Classification: Malicious
40b479d2688a659e57197715395f78c1801d4ed2ff275d59149c52ec9fb01498 is a malicious file sample. Linked to Flawedammyy malware. Detected by 85 antivirus engines.
Detection summary
- 85 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: FLAWEDAMMYY (S0381)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic.Malware | Abuse.ch | 2021-09-21 08:37:41 | 2021-09-21 08:37:41 | malicious-activity | |
| FlawedAmmyy | Abuse.ch | 2021-09-21 08:37:41 | 2021-09-21 08:37:41 | malicious-activity | S0381 FlawedAmmyy |
Sample information
- Filenames
- 40b479d2688a659e57197715395f78c1801d4ed2ff275d59149c52ec9fb01498
- File type
- application/x-dosexec
- MD5
396516050d0007c1c88d579bbe2a8f2e- SHA-1
0c8275a4e2b41bddbf164eccd020c55f8e436fb7- SHA-256
40b479d2688a659e57197715395f78c1801d4ed2ff275d59149c52ec9fb01498- First indexed
- 2021-09-21 09:15:08
- Last updated
- 2025-11-05 21:15:15
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetect.malware1 |
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.DownLoad3.28161 |
| MicroWorld-eScan | Trojan.Agent.BAVE |
| FireEye | Generic.mg.396516050d0007c1 |
| ALYac | Trojan.Agent.BAVE |
| Cylance | Unsafe |
| VIPRE | Trojan.Win32.Generic.pak!cobra |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan-Downloader ( 0040f6bd1 ) |
| K7GW | Trojan-Downloader ( 0040f6bd1 ) |
| Cybereason | malicious.50d000 |
| BitDefenderTheta | AI:Packer.EEA0F0D31E |
| Cyren | W32/Upatre.KZ.gen!Eldorado |
| Symantec | SMG.Heur!gen |
| ESET-NOD32 | Win32/TrojanDownloader.Small.AAB |
| Zoner | Trojan.Win32.19328 |
| ClamAV | Win.Downloader.Upatre-5744087-0 |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| BitDefender | Trojan.Agent.BAVE |
| NANO-Antivirus | Trojan.Win32.DownLoad3.eykfyi |
| SUPERAntiSpyware | Trojan.Agent/Gen-Dropper |
| Avast | Win32:TrojanX-gen [Trj] |
| Tencent | Malware.Win32.Gencirc.10b07999 |
| Ad-Aware | Trojan.Agent.BAVE |
| Sophos | ML/PE-A + Troj/Agent-AEUC |
| Comodo | Packed.Win32.MUPX.Gen@24tbus |
| Baidu | Win32.Trojan.Kryptik.mp |
| McAfee-GW-Edition | BehavesLike.Win32.Cutwail.dh |
| Emsisoft | Trojan.Agent.BAVE (B) |
| Ikarus | Trojan.Win32.Badur |
| GData | Trojan.Agent.BAVE |
| Jiangmin | Trojan/Bublik.ggf |
| Avira | TR/Yarwi.AD.5 |
| Antiy-AVL | Trojan/Generic.ASMalwS.2B37E7F |
| Gridinsoft | Malware.Win32.Gen.bot!se30272 |
| Microsoft | Trojan:Win32/Zbot.RT!MTB |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win32.Upatre.R257559 |
| Acronis | suspicious |
| McAfee | PWS-FBLG!396516050D00 |
| MAX | malware (ai score=81) |
| VBA32 | Trojan.Download |
| Malwarebytes | Upatre.Trojan.Downloader.DDS |
| APEX | Malicious |
| Rising | Downloader.Waski!1.A489 (CLASSIC) |
| SentinelOne | Static AI - Malicious PE |
| eGambit | RAT.Ammyy |
| Fortinet | W32/Small.AAB!tr.dldr |
| AVG | Win32:TrojanX-gen [Trj] |
| Panda | Trj/Genetic.gen |
| CrowdStrike | win/malicious_confidence_100% (W) |
| MaxSecure | Trojan.Upatre.Gen |
| Alibaba | Malware:Win32/km_24b041.None |
| Antiy-AVL | Virus/Win32.Expiro.imp |
| Arcabit | Trojan.Agent.BAVE |
| Bkav | W32.AIDetectMalware |
| CTX | exe.trojan.upatre |
| ClamAV | Win.Malware.Lineage-9935190-0 |
| DeepInstinct | MALICIOUS |
| F-Secure | Trojan.TR/Yarwi.AD.5 |
| Detected | |
| Kaspersky | HEUR:Trojan-Downloader.Win32.Upatre.gen |
| Kingsoft | malware.kb.a.1000 |
| Lionic | Trojan.Win32.Generic.4!c |
| Malwarebytes | Generic.Malware.AI.DDS |
| McAfeeD | Real Protect-LS!396516050D00 |
| Microsoft | TrojanDownloader:Win32/Upatre!pz |
| Paloalto | generic.ml |
| Skyhigh | BehavesLike.Win32.Cutwail.dh |
| Sophos | Troj/Agent-AEUC |
| Tencent | Trojan-DL.Win32.Small.cc |
| Trapmine | malicious.high.ml.score |
| TrendMicro | TROJ_GEN.R014C0CH524 |
| TrendMicro-HouseCall | TROJ_GEN.R014C0CH524 |
| VBA32 | BScope.Trojan.Delf |
| VIPRE | Trojan.Agent.BAVE |
| VirIT | Trojan.Win32.DownLoad3.BPRD |
| Webroot | W32.Trojan.Gen |
| Xcitium | Packed.Win32.MUPX.Gen@24tbus |
| Yandex | Trojan.GenAsa!4FxEc4PI3eE |
| ZoneAlarm | HEUR:Trojan-Downloader.Win32.Upatre.gen |
| alibabacloud | Trojan:Win/Slugin |
| huorong | VirTool/Upatre.c |
| tehtris | Generic.Malware |