SecuriteInfo.com.BackDoor.CrimsonNET.14.26407.16542
Classification: Malicious
SecuriteInfo.com.BackDoor.CrimsonNET.14.26407.16542 is a malicious file sample. Linked to Crimson malware. Reported by 1 threat source, last seen 2023-12-22.
Detection summary
- 53 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: CRIMSON (S0115)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| CrimsonRAT | MalwareBazaar Abuse.ch | 2023-12-22 07:19:32 | 2023-12-22 07:19:32 | malicious-activity | S0115 Crimson |
Sample information
- Filenames
- SecuriteInfo.com.BackDoor.CrimsonNET.14.26407.16542
- File type
- application/x-dosexec
- MD5
b4008dc1b878578905f1a01d2938c8ea- SHA-1
2f7fd3f24c7ff9aaab6a22a15cb5951adc80958b- SHA-256
503d4b9bd0a158dbfd9179ac51341404f32f9fc1765d375f4c92eb7d0ed8ba18- First indexed
- 2023-12-22 08:19:39
- Last updated
- 2025-04-15 04:03:24
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Gen:Variant.Lazy.451217 |
| AVG | Win32:TrojanX-gen [Trj] |
| AhnLab-V3 | Malware/Win.AGEN.C5561522 |
| Alibaba | Trojan:MSIL/Finac.2058367d |
| Antiy-AVL | Trojan/MSIL.Finac |
| Arcabit | Trojan.Lazy.D6E291 |
| Avast | Win32:TrojanX-gen [Trj] |
| Avira | TR/Spy.Gen |
| BitDefender | Gen:Variant.Lazy.451217 |
| Bkav | W32.AIDetectMalware.CS |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.CrimsonNET.14 |
| ESET-NOD32 | a variant of MSIL/Agent.DUB |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Lazy.451217 (B) |
| F-Secure | Trojan.TR/Spy.Gen |
| FireEye | Gen:Variant.Lazy.451217 |
| GData | Gen:Variant.Lazy.451217 |
| Detected | |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0058eb4e1 ) |
| K7GW | Trojan ( 0058eb4e1 ) |
| Kaspersky | HEUR:Trojan.MSIL.Finac.gen |
| Kingsoft | MSIL.Trojan.Finac.gen |
| Lionic | Trojan.Win32.Finac.4!c |
| MaxSecure | Trojan.Malware.210054105.susgen |
| McAfee | Artemis!B4008DC1B878 |
| McAfeeD | ti!503D4B9BD0A1 |
| MicroWorld-eScan | Gen:Variant.Lazy.451217 |
| Microsoft | Backdoor:Win32/Multiverze |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.Finac!8.17AF8 (CLOUD) |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | Artemis |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.11ba2950 |
| Trapmine | suspicious.low.ml.score |
| TrendMicro | TROJ_GEN.R002C0XGJ24 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0XGJ24 |
| VBA32 | TScope.Trojan.MSIL |
| VIPRE | Gen:Variant.Lazy.451217 |
| Varist | W32/ABRisk.PGLB-1174 |
| VirIT | Trojan.Win32.Genus.USO |
| Webroot | W32.Trojan.Gen |
| Zillya | Trojan.Agent.Win32.3790014 |
| ZoneAlarm | HEUR:Trojan.MSIL.Finac.gen |
| alibabacloud | Trojan:MSIL/Finac.gen |
| huorong | Trojan/MSIL.Agent.fs |