2026-02-13_21a7f0057a70e09d29ebd49d7d69315d_amadey_darkgate_elex_redline-stealer_rhadamanthys_smoke-loader_stealc_stop
Classification: Malicious
2026-02-13_21a7f0057a70e09d29ebd49d7d69315d_amadey_darkgate_elex_redline-stealer_rhadamanthys_smoke-loader_stealc_stop is a malicious file sample.
Detection summary
- 67 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Systex |
Triage |
2026-02-13 05:00:28 |
2026-02-13 05:00:28 |
malicious-activity
|
|
Tags
systex
adware
discovery
spyware
trojan
Sample information
- Filenames
- 2026-02-13_21a7f0057a70e09d29ebd49d7d69315d_amadey_darkgate_elex_redline-stealer_rhadamanthys_smoke-loader_stealc_stop
- MD5
21a7f0057a70e09d29ebd49d7d69315d
- SHA-1
95fb2c27ec4424730171f13ecec1b90e4cb2a1c2
- SHA-256
922d12bf6650d753d5319b66679f1f2268ebc28bc954a3e1aebba86fa12cb05e
- SHA-512
991dd36ef572fd444168ff0869d4fb0399e3d0fd44937b0a9b421f7642bac6b2326d8a9c58cde3751dee04901b1d4f1c9e5bc8cab6b29447b4d9ccf50875cd0d
- First indexed
- 2026-02-13 05:00:28
- Last updated
- 2026-09-03 00:17:11
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Generic.7761207 |
| APEX | Malicious |
| AVG | Win32:Agent-AUSD [Rtk] |
| Acronis | suspicious |
| AhnLab-V3 | Dropper/Win32.Daws.R34837 |
| Antiy-AVL | Trojan[Dropper]/Win32.Daws.aumx |
| Arcabit | Trojan.Generic.D766D37 |
| Avast | Win32:Agent-AUSD [Rtk] |
| Avira | TR/Rogue.7909438 |
| Baidu | Win32.Rootkit.Agent.w |
| BitDefender | Trojan.Generic.7761207 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Mauvaise.SL1 |
| CTX | exe.trojan.generic |
| ClamAV | Win.Malware.Mikey-9949492-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Click2.32800 |
| ESET-NOD32 | Win32/Agent.PGA trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Generic.7761207 (B) |
| F-Secure | Trojan.TR/Rogue.7909438 |
| Fortinet | W32/Agent.XAW!tr |
| GData | Win32.Trojan.PSE1.YSVY3N |
| Google | Detected |
| Gridinsoft | Trojan.Win32.Agent.vb!s1 |
| Ikarus | Trojan.SuspectCRC |
| Jiangmin | Trojan/Invader.gje |
| K7AntiVirus | Trojan ( 005565241 ) |
| K7GW | Trojan ( 004c36c31 ) |
| Kaspersky | Trojan.Win32.Tiny.cm |
| Kingsoft | malware.kb.a.978 |
| Malwarebytes | Malware.AI.765186766 |
| MaxSecure | Dropper.Daws.aumx |
| McAfeeD | Real Protect-LS!21A7F0057A70 |
| MicroWorld-eScan | Trojan.Generic.7761207 |
| Microsoft | TrojanDropper:Win32/Systex!pz |
| NANO-Antivirus | Trojan.Win32.Invader.vxfyv |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Agent!1.C16F (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/GenericKD |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Dropper.fh |
| Sophos | Troj/Daws-C |
| Symantec | ML.Attribute.HighConfidence |
| TACHYON | Trojan-Dropper/W32.Daws.369664 |
| Tencent | Trojan.Win32.Nthook.a |
| Trapmine | suspicious.low.ml.score |
| TrellixENS | Generic Dropper.aoe |
| TrendMicro | TSPY_ROGUE_BK084025.TOMC |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9t |
| VBA32 | TrojanDropper.Systex |
| VIPRE | Trojan.Generic.7761207 |
| Varist | W32/Agent.MNVH-5619 |
| ViRobot | Dropper.Daws.Gen.A |
| VirIT | Trojan.Win32.Generic.BPPW |
| Webroot | W32.Invader |
| Xcitium | TrojWare.Win32.Clicker.naf@4qkqfk |
| Yandex | Trojan.GenAsa!fCPsWhzUnE4 |
| Zillya | Dropper.Daws.Win32.2427 |
| ZoneAlarm | Troj/Daws-C |
| Zoner | Trojan.Win32.83500 |
| alibabacloud | Backdoor:Win/Farfli.d02df396 |
| huorong | Trojan/SysTrex |