42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed
Classification: Malicious
42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed is a malicious file sample. Linked to Sunburst malware. Detected by 33 antivirus engines.
Detection summary
- 33 antivirus detections (47% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic.Sunburst. |
Hybrid-Analysis |
2020-12-28 06:00:13 |
2020-12-28 06:00:13 |
|
|
| SUNBURST |
Abuse.ch |
2020-12-28 05:46:48 |
2020-12-28 05:46:48 |
malicious-activity
|
S0559 SUNBURST
|
Sample information
- Filenames
- 42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed, SolarWinds.Orion.Core.BusinessLayer.dll
- File type
- application/x-dosexec
- Size
- 1015296 bytes
- MD5
553bb0993c7261e1b1adfb92ecfaf9f2
- SHA-1
de850f75f4e4d9491cb624e5af5fa1ce1a6438d0
- SHA-256
42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed
- First indexed
- 2020-12-28 06:00:13
- Last updated
- 2026-05-01 06:52:00
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Generic.Sunburst.!s!.2.1A41019D |
| McAfee | Artemis!553BB0993C72 |
| Cylance | Unsafe |
| K7GW | Riskware ( 0040eff71 ) |
| Symantec | Backdoor.Sunburst!gen1 |
| ESET-NOD32 | a variant of Generik.ICUFWQU |
| Paloalto | generic.ml |
| ClamAV | Win.Countermeasure.Sunburst-9809152-0 |
| Kaspersky | HEUR:Backdoor.MSIL.SunBurst.gen |
| BitDefender | Generic.Sunburst.!s!.2.1A41019D |
| Rising | Backdoor.SunBurst/APT#APT29!1.D029 (CLASSIC) |
| Ad-Aware | Generic.Sunburst.!s!.2.1A41019D |
| Sophos | Mal/Sunburst-A |
| TrendMicro | TROJ_GEN.R002C0DLM20 |
| McAfee-GW-Edition | Artemis!Trojan |
| FireEye | Generic.Sunburst.!s!.2.1A41019D |
| Emsisoft | Trojan.Win32.Sunburst (A) |
| Ikarus | Win32.Outbreak |
| Jiangmin | Backdoor.MSIL.ebal |
| Microsoft | Trojan:MSIL/Solorigate.BR!dha |
| Arcabit | Generic.Sunburst.!s!.2.1A41019D |
| AegisLab | Trojan.MSIL.SunBurst.m!c |
| ZoneAlarm | HEUR:Backdoor.MSIL.SunBurst.gen |
| GData | Generic.Sunburst.!s!.2.1A41019D |
| ALYac | Generic.Sunburst.!s!.2.1A41019D |
| MAX | malware (ai score=81) |
| Malwarebytes | Backdoor.Sunburst |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DLM20 |
| SentinelOne | Static AI - Malicious PE |
| Fortinet | W32/SunBurst.A!tr.bdr |
| AVG | FileRepMetagen [Malware] |
| Panda | Trj/GdSda.A |
| Qihoo-360 | Generic/Backdoor.7df |
Process list
| Name | Command line |
| <Ignored Process> | |
| regsvr32.exe | /s "C:\42e73c85b07d89956e94db832d6501c823ae00684c50d9c9163194357c3dd3ed.dll" |