947e357bfdfe411be6c97af6559fd1cdc5c9d6f5cea122bf174d124ee03d2de8.bin
Classification: Malicious
947e357bfdfe411be6c97af6559fd1cdc5c9d6f5cea122bf174d124ee03d2de8.bin is a malicious file sample. Linked to Hellokitty malware.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: HELLOKITTY (S0617)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| HelloKitty | MalwareBazaar Abuse.ch | 2021-12-22 14:33:01 | 2021-12-22 14:33:01 | malicious-activity | S0617 HELLOKITTY |
| Generic.Malware | MalwareBazaar Abuse.ch | 2021-12-22 14:33:01 | 2021-12-22 14:33:01 | malicious-activity |
Sample information
- Filenames
- 947e357bfdfe411be6c97af6559fd1cdc5c9d6f5cea122bf174d124ee03d2de8.bin
- File type
- application/x-dosexec
- MD5
22d35005e926fe29379cb07b810a6075- SHA-1
a0181227dcb49b9417b468eeb38a2f8655553409- SHA-256
947e357bfdfe411be6c97af6559fd1cdc5c9d6f5cea122bf174d124ee03d2de8- First indexed
- 2021-12-22 16:15:08
- Last updated
- 2026-02-14 15:21:42
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Multi.GenericML.4!c |
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.Encoder.33886 |
| MicroWorld-eScan | Gen:Variant.Zusy.375932 |
| FireEye | Generic.mg.22d35005e926fe29 |
| CAT-QuickHeal | Ransom.PFiveHands.S20412053 |
| ALYac | Trojan.Ransom.DEATHRansom |
| Cylance | Unsafe |
| Zillya | Trojan.Filecoder.Win32.18232 |
| Sangfor | Ransom.Win32.Hellokit.gen |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | Trojan:Win32/DeathRansom.45e30f91 |
| K7GW | Riskware ( 0040eff71 ) |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| Cyren | W32/Trojan.TDFN-0202 |
| Symantec | Trojan.Gen.MBT |
| ESET-NOD32 | a variant of Win32/Filecoder.DeathRansom.F |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | HEUR:Trojan-Ransom.Win32.Hellokit.gen |
| BitDefender | Gen:Variant.Zusy.375932 |
| NANO-Antivirus | Trojan.Win32.Redcap.itrfgt |
| Avast | Win32:TrojanX-gen [Trj] |
| Tencent | Malware.Win32.Gencirc.11c5d0a0 |
| Ad-Aware | Gen:Variant.Zusy.375932 |
| Sophos | Mal/Generic-S + Troj/FiveHand-A |
| Comodo | Malware@#1y0gw9ndcjnrb |
| VIPRE | Trojan.Win32.Generic!BT |
| TrendMicro | Trojan.Win32.FIVEHANDS.A |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.dc |
| Emsisoft | Gen:Variant.Zusy.375932 (B) |
| Ikarus | Trojan-Ransom.DeathRansom |
| GData | Gen:Variant.Zusy.375932 |
| Jiangmin | Trojan.Multi.um |
| Webroot | W32.Malware.Gen |
| Avira | TR/Redcap.pmyji |
| Antiy-AVL | Trojan/Generic.ASMalwS.32D48EB |
| Gridinsoft | Ransom.Win32.DeathRansom.oa!s1 |
| Arcabit | Trojan.Zusy.D5BC7C |
| ViRobot | Trojan.Win32.S.Agent.255504.E |
| Microsoft | Ransom:MacOS/Filecoder |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Malware/Win32.Trojan.C4370403 |
| McAfee | Ransom-HelloKitty |
| MAX | malware (ai score=100) |
| VBA32 | Trojan.Tiggre |
| Malwarebytes | Malware.AI.1416248720 |
| TrendMicro-HouseCall | Trojan.Win32.FIVEHANDS.A |
| Rising | [email protected] (RDML:q25Z/SUcbdC0acMbB3a0mQ) |
| Yandex | Trojan.Filecoder!m/qb9S5q1wk |
| SentinelOne | Static AI - Malicious PE |
| eGambit | Unsafe.AI_Score_99% |
| Fortinet | W32/Filecoder_DeathRansom.F!tr |
| AVG | Win32:TrojanX-gen [Trj] |
| Cybereason | malicious.7dcb49 |
| Panda | Trj/CI.A |
| MaxSecure | Trojan.Malware.82199810.susgen |