FEDEX_CL.EXE
Classification: Malicious
FEDEX_CL.EXE is a malicious file sample. Linked to Lucifer malware. Reported by 1 threat source, last seen 2020-09-07. Detected by 30 antivirus engines.
Detection summary
- 30 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: LUCIFER (S0532)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Lucifer | Abuse.ch | 2020-09-07 07:53:04 | 2020-09-07 07:53:04 | malicious-activity | S0532 Lucifer |
Sample information
- Filenames
- FEDEX_CL.EXE
- File type
- application/x-dosexec
- MD5
b362e0f04e718346cf99ed3364150a1a- SHA-1
ccb760c029ddceeffed76494e65e1f166f140fc8- SHA-256
a777ac93ff0c17ae3f7d317ac3a4f01584bf17dd2d00353adc398e5b1723556b- First indexed
- 2020-09-07 08:15:04
- Last updated
- 2025-09-20 18:22:09
Antivirus detections
| Engine | Detection |
|---|---|
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Variant.Ursu.417006 |
| FireEye | Generic.mg.b362e0f04e718346 |
| McAfee | Artemis!B362E0F04E71 |
| Sangfor | Malware |
| Alibaba | TrojanPSW:MSIL/Agensla.4d4cab68 |
| CrowdStrike | win/malicious_confidence_90% (W) |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | HEUR:Trojan-PSW.MSIL.Agensla.gen |
| BitDefender | Gen:Variant.Ursu.417006 |
| Tencent | Msil.Trojan-qqpass.Qqrob.Pdvm |
| Ad-Aware | Gen:Variant.Ursu.417006 |
| Ikarus | Win32.Outbreak |
| GData | Gen:Variant.Ursu.417006 |
| MaxSecure | Trojan.Malware.300983.susgen |
| Arcabit | Trojan.Ursu.D65CEE |
| ZoneAlarm | HEUR:Trojan-PSW.MSIL.Agensla.gen |
| Microsoft | Trojan:Win32/Woreflint.A!cl |
| BitDefenderTheta | Gen:NN.ZemsilF.34216.Jm0@a45N3De |
| ALYac | Gen:Variant.Ursu.417006 |
| MAX | malware (ai score=80) |
| Malwarebytes | Spyware.AgentTesla |
| ESET-NOD32 | a variant of MSIL/GenKryptik.ERVA |
| Yandex | Trojan.AvsArher.bTJEKx |
| eGambit | Unsafe.AI_Score_99% |
| Fortinet | MSIL/Agent.2483!tr |
| AVG | FileRepMalware |
| Cybereason | malicious.04e718 |
| Qihoo-360 | Win32/Trojan.fc8 |