81325d0c1a73cad7402d2020c15304cba466ecc7919061cd16762f655019c038
Classification: Malicious
81325d0c1a73cad7402d2020c15304cba466ecc7919061cd16762f655019c038 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 44 antivirus detections
- 1 IDS alerts
- 3 processes observed
- 4 contacted hosts
- 3 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-02-29 15:15:03 |
2026-09-02 16:45:04 |
malicious-activity
|
|
Tags
evasive
infostealer
windows-server-utility
Sample information
- Filenames
- 81325d0c1a73cad7402d2020c15304cba466ecc7919061cd16762f655019c038, 2c816bef3cd7f3f367e6b94761c2bab2.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 245760 bytes
- MD5
2c816bef3cd7f3f367e6b94761c2bab2
- SHA-1
791c10407dd5df2abee9b87afa09306bd5d7d93c
- SHA-256
81325d0c1a73cad7402d2020c15304cba466ecc7919061cd16762f655019c038
- First indexed
- 2024-02-29 15:08:09
- Last updated
- 2026-09-02 16:45:04
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | FileRepMalware [Cryp] |
| Acronis | suspicious |
| AhnLab-V3 | Trojan/Win.Generic.C5595082 |
| Antiy-AVL | Trojan/Win32.Kryptik |
| Arcabit | Trojan.Generic.D4477C10 |
| Avast | FileRepMalware [Cryp] |
| BitDefender | Trojan.GenericKD.71793680 |
| BitDefenderTheta | Gen:NN.ZexaF.36744.pq0@ayW@9Nfi |
| Bkav | W32.AIDetectMalware |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of Win32/Kryptik.HWLE |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.GenericKD.71793680 (B) |
| FireEye | Generic.mg.2c816bef3cd7f3f3 |
| Fortinet | W32/Kryptik.HWLA!tr |
| GData | Trojan.GenericKD.71793680 |
| Google | Detected |
| Ikarus | Trojan.Win32.Crypt |
| K7AntiVirus | Riskware ( 00584baa1 ) |
| K7GW | Riskware ( 00584baa1 ) |
| Kaspersky | HEUR:Trojan-PSW.Win32.Vidar.gen |
| Kingsoft | Win32.Troj.Unknown.a |
| Lionic | Trojan.Win32.Vidar.i!c |
| MAX | malware (ai score=86) |
| Malwarebytes | Crypt.Trojan.Malicious.DDS |
| McAfee | Artemis!2C816BEF3CD7 |
| MicroWorld-eScan | Trojan.GenericKD.71793680 |
| Microsoft | Trojan:Win32/Vidar.AMMB!MTB |
| Panda | Trj/Chgt.AD |
| Rising | [email protected] (RDML:SgXYQ8th0xivXkMJtgayag) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Trojan.dc |
| Sophos | Troj/Krypt-ADH |
| Symantec | Packed.Generic.525 |
| Trapmine | malicious.high.ml.score |
| TrendMicro | TrojanSpy.Win32.VIDAR.YXEB3Z |
| TrendMicro-HouseCall | TrojanSpy.Win32.VIDAR.YXEB3Z |
| ZoneAlarm | HEUR:Trojan-PSW.Win32.Vidar.gen |
| tehtris | Generic.Malware |
Process list
| Name | Command line |
| 2c816bef3cd7f3f367e6b94761c2bab2.exe | |
| WerFault.exe | -u -p 6892 -s 2172 |
| WerFault.exe | -pss -s 464 -p 6892 -ip 6892 |