Classification: Malicious
2 is a malicious file sample. Linked to Earth Lusca activity. Reported by 2 threat sources, last seen 2023-08-20. Detected by 50 antivirus engines.
Detection summary
- 50 antivirus detections (57% detection ratio)
- 0 IDS alerts
- 4 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Earth Lusca |
Maltiverse |
2023-08-19 05:11:12 |
2023-08-20 21:20:29 |
malicious-activity
|
G1006 Earth Lusca
|
| Generic Malware |
Hybrid-Analysis |
2023-08-03 06:00:03 |
2023-08-03 06:00:03 |
|
|
Sample information
- Filenames
- 2
- File type
- PE32+ executable (DLL) (GUI) x86-64, for MS Windows
- Size
- 245760 bytes
- MD5
e8907b9a27eb9c9fa7fbdf4b2db9ea18
- SHA-1
03628c20be2462e50e1e94c600d10d8979f4b879
- SHA-256
4e3a455e7f0b8f34385cd8320022719a8fc59d8bc091472990ac9a56e982a965
- First indexed
- 2023-08-03 05:50:45
- Last updated
- 2025-10-24 01:49:27
Antivirus detections
| Engine | Detection |
| Bkav | W32.Common.D9CAECFF |
| Lionic | Trojan.Win64.Dllhijacker.4!c |
| MicroWorld-eScan | Trojan.GenericKD.65944515 |
| FireEye | Trojan.GenericKD.65944515 |
| ALYac | Trojan.GenericKD.65944515 |
| Malwarebytes | Neshta.Virus.FileInfector.DDS |
| Zillya | Trojan.Dllhijacker.Win64.16 |
| Sangfor | Trojan.Win64.Agent.Vtoy |
| K7AntiVirus | Trojan ( 005a15031 ) |
| K7GW | Trojan ( 005a15031 ) |
| CrowdStrike | win/malicious_confidence_70% (W) |
| Cyren | W64/ABTrojan.MEEL-4260 |
| Symantec | Trojan Horse |
| ESET-NOD32 | a variant of Win64/Agent.CEY |
| APEX | Malicious |
| Kaspersky | Trojan.Win64.Dllhijacker.afw |
| BitDefender | Trojan.GenericKD.65944515 |
| Avast | Win64:Malware-gen |
| Tencent | Malware.Win32.Gencirc.13ea2de7 |
| Emsisoft | Trojan.GenericKD.65944515 (B) |
| VIPRE | Trojan.GenericKD.65944515 |
| TrendMicro | Backdoor.Win64.SHADOWPAD.AS |
| McAfee-GW-Edition | BehavesLike.Win64.BadFile.dh |
| Sophos | Mal/Generic-S |
| GData | Trojan.GenericKD.65944515 |
| MAX | malware (ai score=81) |
| Antiy-AVL | Trojan/Win64.Dllhijacker |
| Arcabit | Trojan.Generic.D3EE3BC3 |
| ViRobot | Trojan.Win.Z.Agent.245760.EII |
| ZoneAlarm | Trojan.Win64.Dllhijacker.afw |
| Google | Detected |
| AhnLab-V3 | Trojan/Win.Generic.C5279768 |
| McAfee | Artemis!E8907B9A27EB |
| Cylance | unsafe |
| Panda | Trj/Chgt.AD |
| TrendMicro-HouseCall | Backdoor.Win64.SHADOWPAD.AS |
| Rising | Trojan.Bitrep!8.F596 (TFE:5:F20F4m3CyY) |
| MaxSecure | Trojan.Malware.124430950.susgen |
| AVG | Win64:Malware-gen |
| DeepInstinct | MALICIOUS |
| ALYac | Backdoor.Agent.ShadowPad |
| Bkav | W64.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Elastic | malicious (moderate confidence) |
| Ikarus | Trojan.Win64.Agent |
| Lionic | Trojan.Win32.Dllhijacker.4!c |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Sangfor | Trojan.Win64.Agent.Vykg |
| Skyhigh | BehavesLike.Win64.Infected.dh |
| Varist | W64/ABTrojan.MEEL-4260 |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\2.dll",#16 |
| rundll32.exe | "C:\2.dll",#17 |
| rundll32.exe | "C:\2.dll",#18 |