faceshop.io_new.exe
Classification: Malicious
faceshop.io_new.exe is a malicious file sample. Linked to Nanocore malware. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 47 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: NANOCORE (S0336)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Nanocore | Triage | 2026-09-02 23:58:58 | 2026-09-02 23:58:58 | malicious-activity | S0336 NanoCore |
Tags
nanocore defense_evasion discovery execution keylogger persistence privilege_escalation spyware stealer trojanSample information
- Filenames
- faceshop.io_new.exe
- SHA-256
5ef782879f60fa676de554c5916d0fb24c83ddfd2e82169459c24a3d28081259- First indexed
- 2026-09-02 23:58:58
- Last updated
- 2026-09-02 23:58:58
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Generic.Dacic.21342.D619AD76 |
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Expl] |
| AhnLab-V3 | Malware/Win.BypassUAC.R773333 |
| Antiy-AVL | Trojan[Exploit]/Win32.BypassUAC |
| Arcabit | Generic.Dacic.21342.D619AD76 |
| Avast | Win32:MalwareX-gen [Expl] |
| Avira | TR/Dropper.Gen |
| BitDefender | Generic.Dacic.21342.D619AD76 |
| Bkav | W32.Malware.4A3BB5CC |
| CTX | exe.unknown.dacic |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen32.40519 |
| ESET-NOD32 | MSIL/Agent.YGX trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Generic.Dacic.21342.D619AD76 (B) |
| F-Secure | Trojan.TR/Dropper.Gen |
| Fortinet | MSIL/Agent.YGX!tr |
| GData | Generic.Dacic.21342.D619AD76 |
| Detected | |
| K7AntiVirus | Trojan ( 700000201 ) |
| K7GW | Trojan ( 700000201 ) |
| Kaspersky | HEUR:Exploit.Win32.Convagent.gen |
| Kingsoft | malware.kb.c.980 |
| Malwarebytes | Spyware.KeyLogger |
| MaxSecure | Trojan.Malware.121218.susgen |
| McAfeeD | Real Protect-LS!CF92040D8EC7 |
| MicroWorld-eScan | Generic.Dacic.21342.D619AD76 |
| Microsoft | Trojan:MSIL/BypassUAC.MKB!MTB |
| Panda | Trj/GdSda.A |
| Rising | Malware.Undefined!8.C (TFE:dGZlOg0IX+HYb2O4gA) |
| Sangfor | Suspicious.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Troj/NanoCr-PK |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Msil.Agent.16004535 |
| TrellixENS | GenericRXWW-MF!CF92040D8EC7 |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04CA5 |
| VBA32 | TScope.Trojan.MSIL |
| VIPRE | Generic.Dacic.21342.D619AD76 |
| Varist | W32/NanoCore.P.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.B |
| Webroot | W32.Malware.Gen |
| ZoneAlarm | Troj/NanoCr-PK |
| huorong | HEUR:Trojan/Agent.bz |