2026-02-25_4e36d8d6a46f39f6a5961b54f6b46654_amadey_coinminer_elex_smoke-loader_stop
Classification: Malicious
2026-02-25_4e36d8d6a46f39f6a5961b54f6b46654_amadey_coinminer_elex_smoke-loader_stop is a malicious file sample. Detected by 60 antivirus engines.
Detection summary
- 60 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Blackmoon |
Triage |
2026-02-25 13:10:28 |
2026-02-25 13:10:28 |
malicious-activity
|
|
Tags
blackmoon
banker
discovery
persistence
trojan
upx
Sample information
- Filenames
- 2026-02-25_4e36d8d6a46f39f6a5961b54f6b46654_amadey_coinminer_elex_smoke-loader_stop
- MD5
4e36d8d6a46f39f6a5961b54f6b46654
- SHA-1
3f5d71a29d464c35d4bd70d88171f7ddac31c320
- SHA-256
9475ffde84b7bd44b321d0340b3f09ee34276b7998006936100b7ce6e11eac70
- SHA-512
94673865b0d1d9f2a4780b84653040b40703391f18c20c8a642c80586e9a340127f64649cd24ef1bcf47003856f5203c4d16826aceb49e72a693718350d444fa
- First indexed
- 2026-02-25 13:10:28
- Last updated
- 2026-09-03 00:00:54
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Barys.432740 |
| APEX | Malicious |
| AVG | Win32:Malware-gen |
| AhnLab-V3 | Trojan/Win32.RL_Farfli.R361956 |
| Alibaba | Trojan:Win32/Farfli.1d5d3dd0 |
| Antiy-AVL | Virus/Win32.Expiro.imp |
| Arcabit | Trojan.Barys.D69A64 |
| Avast | Win32:Malware-gen |
| BitDefender | Gen:Variant.Barys.432740 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.BlamonRI.S27047145 |
| CTX | exe.trojan.farfli |
| ClamAV | Win.Packed.Farfli-9778384-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.BlackMoon.15 |
| ESET-NOD32 | Win32/Agent.AAIY trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Barys.432740 (B) |
| Fortinet | W32/Kryptik.GGXP!tr |
| GData | Win32.Trojan.Kryptik.QO |
| Google | Detected |
| Gridinsoft | Malware.Win32.Gen.bot!se30272 |
| Ikarus | Trojan.Win32.Crypt |
| Jiangmin | Backdoor.Farfli.ckm |
| K7AntiVirus | Trojan ( 005690671 ) |
| K7GW | Trojan ( 005690671 ) |
| Kaspersky | HEUR:Trojan.Win32.Blamon.gen |
| Kingsoft | Win32.Trojan.Blamon.gen |
| Lionic | Trojan.Win32.Farfli.4!c |
| Malwarebytes | Crypt.Trojan.Malicious.DDS |
| McAfeeD | ti!9475FFDE84B7 |
| MicroWorld-eScan | Gen:Variant.Barys.432740 |
| Microsoft | Trojan:Win32/Farfli!pz |
| NANO-Antivirus | Trojan.Win32.BlackMoon.flthzb |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Kryptik!1.C776 (CLASSIC) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Dropper.tc |
| Sophos | Troj/Farfli-EH |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Backdoor.Win32.Farfli.zc |
| Trapmine | malicious.high.ml.score |
| TrellixENS | GenericRXHP-JI!4E36D8D6A46F |
| TrendMicro | TrojanSpy.Win32.BLACKMOON.YXGBXZ |
| TrendMicro-HouseCall | TrojanSpy.Win32.BLACKMOON.YXGBXZ |
| VBA32 | Backdoor.Farfli |
| VIPRE | Gen:Variant.Barys.432740 |
| Varist | W32/Kryptik.KEL.gen!Eldorado |
| Webroot | W32.Trojan.Gen |
| Xcitium | Packed.Win32.MUPX.Gen@24tbus |
| Yandex | Trojan.Blamon!8PJhfhCy0wU |
| Zillya | Trojan.Kryptik.Win32.1422302 |
| ZoneAlarm | Troj/Farfli-EH |
| alibabacloud | Trojan:Win/Farfli.Gen |
| huorong | VirTool/Obfuscator.mk |