6bd3d05aef89cd03d6b49b20716775fe92f0cf8a3c2747094404ef98f96e9376
Classification: Malicious
6bd3d05aef89cd03d6b49b20716775fe92f0cf8a3c2747094404ef98f96e9376 is a malicious file sample. Linked to Wirte activity. Detected by 46 antivirus engines.
Detection summary
- 46 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: WIRTE (G0090)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| WIRTE | MalwarePatrol | 2026-03-03 17:47:21 | 2026-03-03 18:01:41 | malicious-activity | G0090 WIRTE |
| Generic Malware | Hybrid-Analysis | 2026-01-15 12:47:56 | 2026-01-15 13:50:15 |
Tags
wirte ashen lepusSample information
- Filenames
- 6bd3d05aef89cd03d6b49b20716775fe92f0cf8a3c2747094404ef98f96e9376
- File type
- PE32+ executable for MS Windows 6.00 (DLL), x86-64 ...
- MD5
ae4b7ce4ae428829a0dd167bc821435c- SHA-1
a8ecc6d8cfd7e41294fffaece2cd38c43a18b743- SHA-256
6bd3d05aef89cd03d6b49b20716775fe92f0cf8a3c2747094404ef98f96e9376- First indexed
- 2026-01-15 12:24:48
- Last updated
- 2026-07-13 01:41:13
Antivirus detections
| Engine | Detection |
|---|---|
| Antiy-AVL | Trojan/Win32.Alevaul |
| Avira | TR/Agent.xdtip |
| Bkav | W64.AIDetectMalware |
| CTX | dll.trojan.papershell |
| CrowdStrike | win/malicious_confidence_100% (W) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen32.14817 |
| Elastic | malicious (moderate confidence) |
| F-Secure | Trojan.TR/Agent.xdtip |
| Fortinet | W32/UNC_1549.A!tr.bdr |
| Detected | |
| Ikarus | Trojan.Win32.PaperShell |
| Kaspersky | Trojan.Win64.Kryptik.nf |
| Lionic | Trojan.Win32.PaperShell.4!c |
| McAfeeD | ti!6BD3D05AEF89 |
| Microsoft | Trojan:Win32/PaperShell!AMTB |
| Paloalto | generic.ml |
| Rising | Trojan.Kryptik/x64!1.139A5 (CLASSIC) |
| Skyhigh | Generic Trojan.odh |
| Sophos | Troj/FakWtsDl-A |
| Symantec | Trojan.Gen.MBT |
| Tencent | Malware.Win32.Gencirc.14a584d3 |
| TrellixENS | Generic Trojan.odh |
| Varist | W64/ABApplication.SOPN-6441 |
| ViRobot | Trojan.Win.S.PaperShell.165136 |
| Zillya | Trojan.Kryptik.Win64.68715 |
| ZoneAlarm | Troj/FakWtsDl-A |
| alibabacloud | Trojan:Win/PaperShell.Gen |
| ALYac | Trojan.Agent.GQVR |
| AVG | Win64:MalwareX-gen [Misc] |
| Arcabit | Trojan.Agent.GQVR |
| Avast | Win64:MalwareX-gen [Misc] |
| Avira | TR/W64.Agent |
| BitDefender | Trojan.Agent.GQVR |
| Bkav | W32.Malware.DDF1315F |
| Cylance | Unsafe |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Agent.GQVR (B) |
| F-Secure | Trojan.TR/W64.Agent |
| GData | Trojan.Agent.GQVR |
| Malwarebytes | Malware.AI.3816219364 |
| MicroWorld-eScan | Trojan.Agent.GQVR |
| Panda | Trj/GdSda.A |
| TrendMicro | TROJ_GEN.R002C0TLJ25 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0TLJ25 |
| VIPRE | Trojan.Agent.GQVR |