Third_stage (1).bin
Classification: Malicious
Third_stage (1).bin is a malicious file sample. Linked to Runningrat malware. Reported by 1 threat source, last seen 2022-04-21.
Detection summary
- 50 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: RUNNINGRAT (S0253)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RunningRAT | MalwareBazaar Abuse.ch | 2022-04-21 11:56:14 | 2022-04-21 11:56:14 | malicious-activity | S0253 RunningRAT |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-04-21 11:56:14 | 2022-04-21 11:56:14 | malicious-activity |
Sample information
- Filenames
- Third_stage (1).bin
- File type
- application/x-dosexec
- MD5
61c814616000cd347996e23aec7089d0- SHA-1
1f8753239b02acec6143d1cd31f3412bbbcd6bbc- SHA-256
9b959bf0c464f0d1384276f4f88ee629019e51b84a4d582902aeca49900e4750- First indexed
- 2022-04-21 12:15:05
- Last updated
- 2026-04-08 04:48:09
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.SlaviaB.Trojan |
| Elastic | malicious (high confidence) |
| Cynet | Malicious (score: 100) |
| CAT-QuickHeal | Backdoor.LotokRI.S21280961 |
| McAfee | GenericRXHZ-GJ!61C814616000 |
| Malwarebytes | Backdoor.Farfli |
| Sangfor | [ARMADILLO V1.71] |
| CrowdStrike | win/malicious_confidence_90% (D) |
| BitDefender | Gen:Variant.Zusy.317906 |
| K7GW | Trojan ( 0056e0231 ) |
| K7AntiVirus | Trojan ( 0056e0231 ) |
| Cyren | W32/Farfli.BW.gen!Eldorado |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Farfli.CUY |
| APEX | Malicious |
| ClamAV | Win.Malware.Farfli-9832713-0 |
| Kaspersky | HEUR:Backdoor.Win32.Lotok.gen |
| NANO-Antivirus | Trojan.Win32.Farfli.hjycgq |
| MicroWorld-eScan | Gen:Variant.Zusy.317906 |
| Avast | Win32:BackdoorX-gen [Trj] |
| Rising | Backdoor.Gh0st!1.D1DA (RDMK:cmRtazoFFLkYAMPMnDQ) |
| Ad-Aware | Gen:Variant.Zusy.317906 |
| Emsisoft | Gen:Variant.Zusy.317906 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1207659 |
| DrWeb | Trojan.DownLoader33.36856 |
| Zillya | Trojan.Farfli.Win32.35172 |
| McAfee-GW-Edition | GenericRXHZ-GJ!61C814616000 |
| FireEye | Generic.mg.61c814616000cd34 |
| Sophos | ML/PE-A |
| SentinelOne | Static AI - Malicious PE |
| GData | Gen:Variant.Zusy.317906 |
| Jiangmin | Backdoor.Lotok.gt |
| Webroot | W32.Trojan.Gen |
| Avira | HEUR/AGEN.1207659 |
| Antiy-AVL | Trojan/Generic.ASMalwS.3060D56 |
| Arcabit | Trojan.Zusy.D4D9D2 |
| Microsoft | Trojan:Win32/Farfli.EGZV!MTB |
| AhnLab-V3 | Backdoor/Win32.Farfli.R335712 |
| Acronis | suspicious |
| VBA32 | Backdoor.Lotok |
| ALYac | Gen:Variant.Zusy.317906 |
| MAX | malware (ai score=84) |
| Cylance | Unsafe |
| Tencent | Trojan.Win32.lotok.xa |
| Yandex | Trojan.Farfli!vV8IZj6XO8E |
| Ikarus | Trojan.Win32.Farfli |
| Fortinet | W32/Farfli.BSS!tr |
| BitDefenderTheta | Gen:NN.ZedlaF.34606.cu5@aafRaibj |
| AVG | Win32:BackdoorX-gen [Trj] |
| Panda | Trj/GdSda.A |