2026-02-15_5d1bbeaa83c50744eee24f6ddc3970c6_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
Classification: Malicious
2026-02-15_5d1bbeaa83c50744eee24f6ddc3970c6_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee is a malicious file sample. Linked to Dcrat malware.
Detection summary
- 61 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: DCRAT (S9017)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Dcrat | Triage | 2026-02-15 13:25:51 | 2026-02-15 13:25:51 | malicious-activity | S9017 DCRAT |
Tags
dcrat defense_evasion discovery execution infostealer persistence rat trojanSample information
- Filenames
- 2026-02-15_5d1bbeaa83c50744eee24f6ddc3970c6_drokbk_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
- MD5
5d1bbeaa83c50744eee24f6ddc3970c6- SHA-1
35b460045de6c26005700dd2729e135069ef14f8- SHA-256
aa64f1e8594ed4db44a140de1550d8e7ea1f6a0eddbd66461f2da1cac3b5b1be- SHA-512
339cc6d5555d1d3d1ace2ff432ef8cdfdec10fa5ec79912cd4763b4f32c338033ddfd1f08cd5b55cca63da91e302c1411946f8dcb8978be66f402f2dab2d9217- First indexed
- 2026-02-15 13:25:51
- Last updated
- 2026-09-03 00:22:15
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.GPZU |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.DCRat.R729785 |
| Alibaba | Backdoor:Win32/DCRat.cda6f45a |
| Antiy-AVL | Trojan[Backdoor]/MSIL.DCRat |
| Arcabit | Trojan.Agent.GPZU |
| Avast | Win32:Evo-gen [Trj] |
| Avira | HEUR/AGEN.1323984 |
| BitDefender | Trojan.Agent.GPZU |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.17711656883970c6 |
| CTX | exe.trojan.dcrat |
| ClamAV | Win.Malware.Gpzu-10058391-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen31.31069 |
| ESET-NOD32 | MSIL/Agent.VRB trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Agent.GPZU (B) |
| F-Secure | Heuristic.HEUR/AGEN.1323984 |
| Fortinet | W32/Agent.VRB!tr |
| GData | Trojan.Agent.GPZU |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0001140e1 ) |
| K7GW | Trojan ( 0001140e1 ) |
| Kaspersky | HEUR:Backdoor.MSIL.DcRat.pef |
| Kingsoft | MSIL.Backdoor.DcRat.pef |
| Lionic | Trojan.Win32.DCRat.m!c |
| Malwarebytes | Spyware.Passwordstealer |
| MaxSecure | Trojan.Malware.120990306.susgen |
| McAfeeD | Real Protect-LS!5D1BBEAA83C5 |
| MicroWorld-eScan | Trojan.Agent.GPZU |
| Microsoft | Trojan:Win32/DCRat.MX!MTB |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Stealer.Agent!8.C2 (CLOUD) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Stealer |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Injector.tc |
| Sophos | Troj/DCRat-AC |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Msil.Agent.hbf |
| TrellixENS | GenericRXWS-LY!5D1BBEAA83C5 |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9z |
| VBA32 | Backdoor.MSIL.DcRat |
| VIPRE | Trojan.Agent.GPZU |
| Varist | W32/Trojan.DAIU-7549 |
| ViRobot | Trojan.Win.Z.Agent.2078720.TPB |
| VirIT | Trojan.Win32.GenusT.EXYL |
| Webroot | Win.Malware.Gen |
| Zillya | Trojan.Stealer.Win32.199293 |
| ZoneAlarm | Troj/DCRat-AC |
| alibabacloud | Backdoor:MSIL/DCRat.MD8PHU |
| huorong | Backdoor/MSIL.DCRat.x |
| tehtris | Generic.Malware |