faceshop.io_new.exe

Classification: Malicious

faceshop.io_new.exe is a malicious file sample. Linked to Nanocore malware. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 47 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: NANOCORE (S0336)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Nanocore Triage 2026-09-02 23:58:58 2026-09-02 23:58:58 malicious-activity S0336 NanoCore

Tags

nanocore defense_evasion discovery execution keylogger persistence privilege_escalation spyware stealer trojan

Sample information

Filenames
faceshop.io_new.exe
SHA-256
5ef782879f60fa676de554c5916d0fb24c83ddfd2e82169459c24a3d28081259
First indexed
2026-09-02 23:58:58
Last updated
2026-09-02 23:58:58

Antivirus detections

EngineDetection
ALYacGeneric.Dacic.21342.D619AD76
APEXMalicious
AVGWin32:MalwareX-gen [Expl]
AhnLab-V3Malware/Win.BypassUAC.R773333
Antiy-AVLTrojan[Exploit]/Win32.BypassUAC
ArcabitGeneric.Dacic.21342.D619AD76
AvastWin32:MalwareX-gen [Expl]
AviraTR/Dropper.Gen
BitDefenderGeneric.Dacic.21342.D619AD76
BkavW32.Malware.4A3BB5CC
CTXexe.unknown.dacic
CrowdStrikewin/malicious_confidence_100% (D)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebTrojan.Siggen32.40519
ESET-NOD32MSIL/Agent.YGX trojan
Elasticmalicious (high confidence)
EmsisoftGeneric.Dacic.21342.D619AD76 (B)
F-SecureTrojan.TR/Dropper.Gen
FortinetMSIL/Agent.YGX!tr
GDataGeneric.Dacic.21342.D619AD76
GoogleDetected
K7AntiVirusTrojan ( 700000201 )
K7GWTrojan ( 700000201 )
KasperskyHEUR:Exploit.Win32.Convagent.gen
Kingsoftmalware.kb.c.980
MalwarebytesSpyware.KeyLogger
MaxSecureTrojan.Malware.121218.susgen
McAfeeDReal Protect-LS!CF92040D8EC7
MicroWorld-eScanGeneric.Dacic.21342.D619AD76
MicrosoftTrojan:MSIL/BypassUAC.MKB!MTB
PandaTrj/GdSda.A
RisingMalware.Undefined!8.C (TFE:dGZlOg0IX+HYb2O4gA)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SophosTroj/NanoCr-PK
SymantecML.Attribute.HighConfidence
TencentTrojan.Msil.Agent.16004535
TrellixENSGenericRXWW-MF!CF92040D8EC7
TrendMicro-HouseCallTrojan.Win32.VSX.PE04CA5
VBA32TScope.Trojan.MSIL
VIPREGeneric.Dacic.21342.D619AD76
VaristW32/NanoCore.P.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.B
WebrootW32.Malware.Gen
ZoneAlarmTroj/NanoCr-PK
huorongHEUR:Trojan/Agent.bz