7fc6bc7f2cb710cf14da22c9e40b8407dbbe523ba7f8a91f8d67f5bce413d5c5
Classification: Malicious
7fc6bc7f2cb710cf14da22c9e40b8407dbbe523ba7f8a91f8d67f5bce413d5c5 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 44 antivirus detections
- 1 IDS alerts
- 4 processes observed
- 4 contacted hosts
- 3 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-09-18 03:15:09 |
2026-09-02 14:45:05 |
malicious-activity
|
|
| Vidar |
ThreatFox Abuse.ch |
2024-09-15 20:42:52 |
2024-09-17 20:19:05 |
|
|
Tags
win.vidar
evasive
infostealer
Sample information
- Filenames
- 7fc6bc7f2cb710cf14da22c9e40b8407dbbe523ba7f8a91f8d67f5bce413d5c5, 7fc6b.Stealer.exe
- File type
- PE32 executable (console) Intel 80386 Mono/.Net as ...
- Size
- 290344 bytes
- MD5
c252b6cf66b0de7e3b34c180bab3b0fa
- SHA-1
cba15dad617651223885f6c032b65cd598dcce5c
- SHA-256
7fc6bc7f2cb710cf14da22c9e40b8407dbbe523ba7f8a91f8d67f5bce413d5c5
- First indexed
- 2024-09-15 21:17:06
- Last updated
- 2026-09-02 14:45:05
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | Win32:PWSX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.C5670639 |
| Alibaba | TrojanSpy:MSIL/Stealer.f5db6e38 |
| Arcabit | Trojan.MSILHeracles.D2BE19 |
| Avast | Win32:PWSX-gen [Trj] |
| Avira | TR/AD.Stealc.hjqcx |
| BitDefender | Gen:Variant.MSILHeracles.179737 |
| Bkav | W32.AIDetectMalware.CS |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of MSIL/GenKryptik.HBHS |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.MSILHeracles.179737 (B) |
| F-Secure | Trojan.TR/AD.Stealc.hjqcx |
| FireEye | Generic.mg.c252b6cf66b0de7e |
| Fortinet | MSIL/GenKryptik.HBHS!tr |
| GData | Win32.Trojan.Kryptik.YCF8Y2 |
| Google | Detected |
| Gridinsoft | Spy.Win32.Vidar.tr |
| Ikarus | Trojan-Spy.LummaStealer |
| Kaspersky | HEUR:Trojan-Spy.MSIL.Stealer.gen |
| Kingsoft | MSIL.Trojan-Spy.Stealer.gen |
| Lionic | Trojan.Win32.Stealer.12!c |
| McAfee | Artemis!C252B6CF66B0 |
| McAfeeD | ti!7FC6BC7F2CB7 |
| MicroWorld-eScan | Gen:Variant.MSILHeracles.179737 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Stealer.Agent!8.C2 (CLOUD) |
| Sangfor | Infostealer.Msil.Agent.Vgl1 |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.FalseSign.Cujl |
| TrendMicro | Trojan.Win32.PRIVATELOADER.YXEIOZ |
| TrendMicro-HouseCall | Trojan.Win32.PRIVATELOADER.YXEIOZ |
| VIPRE | Gen:Variant.MSILHeracles.179737 |
| ZoneAlarm | HEUR:Trojan-Spy.MSIL.Stealer.gen |
| alibabacloud | Trojan[spy]:MSIL/Wacatac.B9nj |
| huorong | Trojan/MSIL.Agent.li |
Process list
| Name | Command line |
| 7fc6b.Stealer.exe | |
| RegAsm.exe | |
| cmd.exe | /c timeout /t 10 & del /f /q "%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" & rd /s /q "%ALLUSERSPROFILE%\IIJKJDAFHJDH" & exit |
| timeout.exe | timeout /t 10 |