5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd.exe
Classification: Malicious
5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd.exe is a malicious file sample. Reported by 5 threat sources, last seen 2026-09-02.
Detection summary
- 52 antivirus detections
- 1 IDS alerts
- 19 processes observed
- 2 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-09-02 10:16:23 |
2026-09-02 10:16:23 |
anomalous-activity
|
|
| Generic Malware |
Cyber Threat Alliance |
2026-08-27 10:13:37 |
2026-08-27 10:13:37 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2025-01-17 12:15:05 |
2025-06-06 22:00:05 |
|
|
| Unknown malware |
ThreatFox Abuse.ch |
2025-01-13 06:57:39 |
2025-01-15 06:20:30 |
|
|
| RustyStealer |
MalwareBazaar Abuse.ch |
2025-01-12 17:46:00 |
2025-01-12 17:46:00 |
malicious-activity
|
|
Tags
unknown
evasive
onion
execution
defense_evasion
discovery
Sample information
- Filenames
- 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd.exe, 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd
- File type
- application/x-dosexec
- Size
- 5482496 bytes
- MD5
834c7fd865eee5f7e17a3a1fb62e7051
- SHA-1
0246696395c8514494435f645cdff034d70d0951
- SHA-256
5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd
- First indexed
- 2025-01-12 19:25:07
- Last updated
- 2026-08-27 10:13:37
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.GenericKD.75301847 |
| AVG | Win64:CrypterX-gen [Trj] |
| Alibaba | Trojan:Win64/DelShad.5d395361 |
| Antiy-AVL | Trojan/Win32.Sonbokli |
| Arcabit | Trojan.Generic.D47D03D7 |
| Avast | Win64:CrypterX-gen [Trj] |
| Avira | TR/AVI.Agent.thksu |
| BitDefender | Trojan.GenericKD.75301847 |
| Bkav | W32.Common.29D84B2B |
| CAT-QuickHeal | Ransom.Funksec.S34839865 |
| CTX | exe.trojan.funksec |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen30.46525 |
| ESET-NOD32 | a variant of Win64/Filecoder.RN |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.GenericKD.75301847 (B) |
| F-Secure | Trojan.TR/AVI.Agent.thksu |
| FireEye | Trojan.GenericKD.75301847 |
| Fortinet | W32/PossibleThreat |
| GData | Trojan.GenericKD.75301847 |
| Google | Detected |
| Ikarus | Trojan.Win64.Krypt |
| K7AntiVirus | Trojan ( 005bf3b01 ) |
| K7GW | Trojan ( 005bf3b01 ) |
| Kaspersky | Trojan.Win32.DelShad.myi |
| Kingsoft | Win32.Trojan.DelShad.myi |
| Lionic | Trojan.Win32.FunkSec.4!c |
| Malwarebytes | Trojan.Crypt.Generic |
| MaxSecure | Trojan.Malware.318124991.susgen |
| McAfee | FunkLocker-HVH!834C7FD865EE |
| McAfeeD | ti!5226EA8E0F51 |
| MicroWorld-eScan | Trojan.GenericKD.75301847 |
| Microsoft | Ransom:Win64/FunkSec.CCJT!MTB |
| Paloalto | generic.ml |
| Panda | Trj/RansomGen.A |
| Rising | Ransom.LockFile!8.12D75 (CLOUD) |
| Skyhigh | BehavesLike.Win64.Rootkit.th |
| Sophos | Troj/FunkSec-A |
| Symantec | Ransom.Funk |
| Tencent | Malware.Win32.Gencirc.10c091e2 |
| TrendMicro | Ransom.Win64.FUNKSEC.THAOFBE |
| TrendMicro-HouseCall | Ransom.Win64.FUNKSEC.THAOFBE |
| VIPRE | Trojan.GenericKD.75301847 |
| Varist | W64/Ransom.SB.gen!Eldorado |
| VirIT | Trojan.Win64.Genus.HOL |
| alibabacloud | Trojan:Win/DelShad.mgR |
| huorong | Ransom/LockFile.au |
| Alibaba | Trojan:Win64/DelShad.9a45c1a8 |
| CTX | exe.trojan.delshad |
| NANO-Antivirus | Trojan.Win64.DelShad.kuwarl |
Process list
| Name | Command line |
| 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd.exe | funksec |
| net.exe | "net" session |
| net1.exe | %WINDIR%\system32\net1 session |
| tasklist.exe | "tasklist" /fi "IMAGENAME eq vmware" |
| powershell.exe | "powershell" -Command "Set-MpPreference -DisableRealtimeMonitoring $true" |
| powershell.exe | "powershell" -Command "wevtutil sl Security /e:false" |
| wevtutil.exe | sl Security /e:false |
| powershell.exe | "powershell" -Command "wevtutil sl Application /e:false" |
| wevtutil.exe | sl Application /e:false |
| powershell.exe | "powershell" -Command "Set-ExecutionPolicy Bypass -Scope Process -Force" |
| 5226ea8e0f516565ba825a1bbed10020982c16414750237068b602c5b4ac6abd.exe | |
| net.exe | "net" session |
| net1.exe | %WINDIR%\system32\net1 session |
| tasklist.exe | "tasklist" /fi "IMAGENAME eq vmware" |
| powershell.exe | "powershell" -Command "Set-MpPreference -DisableRealtimeMonitoring $true" |
| powershell.exe | "powershell" -Command "wevtutil sl Security /e:false" |
| powershell.exe | "powershell" -Command "wevtutil sl Application /e:false" |
| wevtutil.exe | sl Application /e:false |
| powershell.exe | "powershell" -Command "Set-ExecutionPolicy Bypass -Scope Process -Force" |