482b160ee2e8d94fa6e4749f77e87da89c9658e7567459bc633d697430e3ad9a.bin
Classification: Malicious
482b160ee2e8d94fa6e4749f77e87da89c9658e7567459bc633d697430e3ad9a.bin is a malicious file sample. Linked to Cuba malware. Detected by 63 antivirus engines.
Detection summary
- 63 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: CUBA (S0625)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Cuba | MalwareBazaar Abuse.ch | 2021-12-24 18:12:22 | 2021-12-24 18:12:22 | malicious-activity | S0625 Cuba |
| Generic.Malware | MalwareBazaar Abuse.ch | 2021-12-24 18:12:22 | 2021-12-24 18:12:22 | malicious-activity |
Sample information
- Filenames
- 482b160ee2e8d94fa6e4749f77e87da89c9658e7567459bc633d697430e3ad9a.bin
- File type
- application/x-dosexec
- MD5
20a04e7fc12259dfd4172f5232ed5ccf- SHA-1
82f194e6baeef6eefb42f0685c49c1e6143ec850- SHA-256
482b160ee2e8d94fa6e4749f77e87da89c9658e7567459bc633d697430e3ad9a- First indexed
- 2021-12-24 19:15:06
- Last updated
- 2025-02-16 03:07:23
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Ransom.Filecoder |
| APEX | Malicious |
| AVG | Win32:RansomX-gen [Ransom] |
| AhnLab-V3 | Trojan/Win.Generic.C4546294 |
| Alibaba | Ransom:Win32/Abucrosm.371ddd57 |
| Antiy-AVL | Trojan/Win32.Unc2596 |
| Arcabit | Dump:Generic.Ransom.Cuba.C32CFE13 |
| Avast | Win32:RansomX-gen [Ransom] |
| Avira | HEUR/AGEN.1372109 |
| BitDefender | Dump:Generic.Ransom.Cuba.C32CFE13 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.1732909191ed5ccf |
| CTX | exe.trojan.cuba |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Encoder.34137 |
| ESET-NOD32 | a variant of Win32/Filecoder.Cuba.A |
| Elastic | Windows.Ransomware.Cuba |
| Emsisoft | Dump:Generic.Ransom.Cuba.C32CFE13 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1372109 |
| FireEye | Generic.mg.20a04e7fc12259df |
| Fortinet | W32/Filecoder.OHL!tr |
| GData | Win32.Trojan-Ransom.CubaCrypt.B |
| Detected | |
| Gridinsoft | Ransom.Win32.Gen.oa!s1 |
| Ikarus | Trojan-Ransom.FileCrypter |
| Jiangmin | Trojan.Generic.hekoy |
| K7AntiVirus | Trojan ( 0057e5ff1 ) |
| K7GW | Trojan ( 0057e5ff1 ) |
| Kaspersky | HEUR:Trojan-Ransom.Win32.Cuba.gen |
| Kingsoft | malware.kb.a.887 |
| Lionic | Trojan.Win32.Cuba.j!c |
| Malwarebytes | Malware.AI.4206937161 |
| MaxSecure | Trojan.Malware.73859634.susgen |
| McAfee | Ransomware-HKQ!20A04E7FC122 |
| McAfeeD | ti!482B160EE2E8 |
| MicroWorld-eScan | Dump:Generic.Ransom.Cuba.C32CFE13 |
| Microsoft | Ransom:Win32/Abucrosm.AD!MTB |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Ransom.Gen!8.DE83 (CLOUD) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | BehavesLike.Win32.Generic.ch |
| Sophos | Troj/RansCuba-A |
| Symantec | Downloader |
| Tencent | Malware.Win32.Gencirc.10bdf795 |
| Trapmine | suspicious.low.ml.score |
| TrendMicro | Ransom.Win32.BACUCRYPT.YXBGH |
| TrendMicro-HouseCall | Ransom.Win32.BACUCRYPT.YXBGH |
| VBA32 | BScope.Trojan.Invader |
| VIPRE | Dump:Generic.Ransom.Cuba.C32CFE13 |
| Varist | W32/ABRansom.UKAO-7344 |
| ViRobot | Trojan.Win32.Z.Ransom.148480 |
| VirIT | Trojan.Win32.GenusT.DXZP |
| Webroot | W32.Ransom.Cuba |
| Xcitium | Malware@#15wgzsbpvrkvn |
| Yandex | Trojan.Filecoder!SBr9aWQb0is |
| Zillya | Trojan.Filecoder.Win32.24741 |
| alibabacloud | Ransomware:Win/Cuba.A |
| huorong | Ransom/Genasom.p |