8d4c3091ce2448c130326c53547a8a45
Classification: Malicious
8d4c3091ce2448c130326c53547a8a45 is a malicious file sample. Linked to Apt38 activity. Reported by 1 threat source, last seen 2023-02-15.
Detection summary
- 53 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: APT38 (G0082)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| BlueNoroff | MalwareBazaar Abuse.ch | 2023-02-15 02:32:06 | 2023-02-15 02:32:06 | G0082 APT38 | |
| Generic.Malware | MalwareBazaar Abuse.ch | 2023-02-15 02:32:06 | 2023-02-15 02:32:06 | malicious-activity |
Sample information
- Filenames
- 8d4c3091ce2448c130326c53547a8a45
- File type
- application/octet-stream
- MD5
8d4c3091ce2448c130326c53547a8a45- SHA-1
74896758c69b493ba78bb0f774b87cc8afc20ec5- SHA-256
60701bdae4b33de7c53e4a0708b7187f313730bd09c4c553847134f268160a73- First indexed
- 2023-02-15 02:32:06
- Last updated
- 2025-11-05 18:00:22
Antivirus detections
| Engine | Detection |
|---|---|
| MicroWorld-eScan | Heur.BZC.YAX.Boxter.581.2804AE5E |
| FireEye | Heur.BZC.YAX.Boxter.581.2804AE5E |
| McAfee | BlueNoroff!lnk |
| VIPRE | Heur.BZC.YAX.Boxter.581.2804AE5E |
| Cyren | LNK/Powershell.AQ.gen!Eldorado |
| Symantec | Trojan.Gen.NPE.C |
| Avast | Other:Malware-gen [Trj] |
| Kaspersky | HEUR:Trojan.Multi.Powedon.c |
| BitDefender | Heur.BZC.YAX.Boxter.581.2804AE5E |
| Sophos | Mal/DownLnk-D |
| TrendMicro | HEUR_LNKEXEC.A |
| Emsisoft | Heur.BZC.YAX.Boxter.581.2804AE5E (B) |
| SentinelOne | Static AI - Suspicious LNK |
| GData | Heur.BZC.YAX.Boxter.581.2804AE5E |
| Arcabit | Heur.BZC.YAX.Boxter.581.2804AE5E |
| Microsoft | Trojan:Script/Wacatac.B!ml |
| Detected | |
| ALYac | Heur.BZC.YAX.Boxter.581.2804AE5E |
| MAX | malware (ai score=83) |
| VBA32 | suspected of Trojan.Link.URL |
| Zoner | Probably Heur.LNKScript |
| Rising | Trojan.PSRunner/LNK!1.BADE (CLASSIC) |
| Fortinet | LNK/Agent.AB54!tr |
| AVG | Other:Malware-gen [Trj] |
| ALYac | Trojan.Agent.LNK.Gen |
| Arcabit | Heur.BZC.YAX.Boxter.581.2B4B2A94 |
| Avira | LNK/Dldr.Agent.VPUW |
| BitDefender | Heur.BZC.YAX.Boxter.581.2B4B2A94 |
| CAT-QuickHeal | cld.lnk.trojan.1693909094 |
| CTX | lnk.trojan.generic |
| Cynet | Malicious (score: 99) |
| DrWeb | Trojan.DownLoader45.60913 |
| ESET-NOD32 | LNK/NukeSped.S |
| Emsisoft | Heur.BZC.YAX.Boxter.581.2B4B2A94 (B) |
| F-Secure | Trojan-Downloader:W32/Kataja.C |
| FireEye | Heur.BZC.YAX.Boxter.581.2B4B2A94 |
| Fortinet | LNK/Agent.D!tr |
| GData | Heur.BZC.YAX.Boxter.581.2B4B2A94 |
| Ikarus | Trojan-Downloader.LNK.Agent |
| Kaspersky | HEUR:Trojan.Multi.GenBadur.genw |
| Kingsoft | Script.Troj.cmdexecLnk.2023063 |
| Lionic | Trojan.WinLNK.Boxter.4!c |
| MicroWorld-eScan | Heur.BZC.YAX.Boxter.581.2B4B2A94 |
| Skyhigh | BehavesLike.Trojan.xx |
| Symantec | Trojan Horse |
| Tencent | Win32.Trojan.Powedon.Mgil |
| TrendMicro | Trojan.LNK.DANGERPASSLNK.ZJKE |
| TrendMicro-HouseCall | Trojan.LNK.DANGERPASSLNK.ZJKE |
| VIPRE | Heur.BZC.YAX.Boxter.581.2B4B2A94 |
| Varist | LNK/Powershell.AQ.gen!Eldorado |
| Zillya | Trojan.NukeSped.Script.95 |
| alibabacloud | Trojan[downloader]:Win/NukeSped.S |
| huorong | TrojanDownloader/LNK.NetLoader.y |