2

Classification: Malicious

2 is a malicious file sample. Linked to Earth Lusca activity. Reported by 2 threat sources, last seen 2023-08-20. Detected by 50 antivirus engines.

Detection summary

  • 50 antivirus detections (57% detection ratio)
  • 0 IDS alerts
  • 4 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: EARTH LUSCA (G1006)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Earth Lusca Maltiverse 2023-08-19 05:11:12 2023-08-20 21:20:29 malicious-activity G1006 Earth Lusca
Generic Malware Hybrid-Analysis 2023-08-03 06:00:03 2023-08-03 06:00:03

Tags

apt

Sample information

Filenames
2
File type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Size
245760 bytes
MD5
e8907b9a27eb9c9fa7fbdf4b2db9ea18
SHA-1
03628c20be2462e50e1e94c600d10d8979f4b879
SHA-256
4e3a455e7f0b8f34385cd8320022719a8fc59d8bc091472990ac9a56e982a965
First indexed
2023-08-03 05:50:45
Last updated
2025-10-24 01:49:27

Antivirus detections

EngineDetection
BkavW32.Common.D9CAECFF
LionicTrojan.Win64.Dllhijacker.4!c
MicroWorld-eScanTrojan.GenericKD.65944515
FireEyeTrojan.GenericKD.65944515
ALYacTrojan.GenericKD.65944515
MalwarebytesNeshta.Virus.FileInfector.DDS
ZillyaTrojan.Dllhijacker.Win64.16
SangforTrojan.Win64.Agent.Vtoy
K7AntiVirusTrojan ( 005a15031 )
K7GWTrojan ( 005a15031 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW64/ABTrojan.MEEL-4260
SymantecTrojan Horse
ESET-NOD32a variant of Win64/Agent.CEY
APEXMalicious
KasperskyTrojan.Win64.Dllhijacker.afw
BitDefenderTrojan.GenericKD.65944515
AvastWin64:Malware-gen
TencentMalware.Win32.Gencirc.13ea2de7
EmsisoftTrojan.GenericKD.65944515 (B)
VIPRETrojan.GenericKD.65944515
TrendMicroBackdoor.Win64.SHADOWPAD.AS
McAfee-GW-EditionBehavesLike.Win64.BadFile.dh
SophosMal/Generic-S
GDataTrojan.GenericKD.65944515
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win64.Dllhijacker
ArcabitTrojan.Generic.D3EE3BC3
ViRobotTrojan.Win.Z.Agent.245760.EII
ZoneAlarmTrojan.Win64.Dllhijacker.afw
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5279768
McAfeeArtemis!E8907B9A27EB
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallBackdoor.Win64.SHADOWPAD.AS
RisingTrojan.Bitrep!8.F596 (TFE:5:F20F4m3CyY)
MaxSecureTrojan.Malware.124430950.susgen
AVGWin64:Malware-gen
DeepInstinctMALICIOUS
ALYacBackdoor.Agent.ShadowPad
BkavW64.AIDetectMalware
CrowdStrikewin/malicious_confidence_100% (W)
Elasticmalicious (moderate confidence)
IkarusTrojan.Win64.Agent
LionicTrojan.Win32.Dllhijacker.4!c
MicrosoftTrojan:Win32/Wacatac.B!ml
SangforTrojan.Win64.Agent.Vykg
SkyhighBehavesLike.Win64.Infected.dh
VaristW64/ABTrojan.MEEL-4260

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\2.dll",#16
rundll32.exe"C:\2.dll",#17
rundll32.exe"C:\2.dll",#18