file
Classification: Malicious
file is a malicious file sample. Linked to Invisimole malware. Reported by 2 threat sources, last seen 2023-04-01. Detected by 42 antivirus engines.
Detection summary
- 42 antivirus detections (51% detection ratio)
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: INVISIMOLE (S0260)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Invisimole | Maltiverse | 2023-03-31 04:13:54 | 2023-04-01 00:17:31 | malicious-activity | S0260 InvisiMole |
| Ghostwriter | Maltiverse | 2023-03-31 04:13:54 | 2023-04-01 00:17:25 | malicious-activity | |
| Trojan.Win64.Patched | Hybrid-Analysis | 2020-11-25 10:17:08 | 2020-11-25 10:17:08 |
Tags
aptSample information
- Filenames
- file
- File type
- PE32+ executable (GUI) x86-64, for MS Windows
- Size
- 10507264 bytes
- MD5
38032a4d12d9e3029f00b120200e8e68- SHA-1
382bdd11c605882ccb149f0d23707a7ee5f4b89a- SHA-256
adce894e3ce69c9822da57196707c7a15acee11319ccc963b84d83c23c3ea802- First indexed
- 2020-11-25 10:17:08
- Last updated
- 2026-05-03 04:51:34
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Agent.1054607L |
| AhnLab-V3 | Trojan/Win64.Agent.C4180606 |
| Alibaba | Trojan:Win64/NukeSped.bc3cc400 |
| Antiy-AVL | Trojan[APT]/Win32.Lazarus |
| Arcabit | Trojan.Generic.D20E2615 |
| BitDefender | Trojan.GenericKD.34481685 |
| CTX | exe.trojan.nukesped |
| ClamAV | Win.Malware.Agent-9378216-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.NukeSped.98 |
| ESET-NOD32 | Win64/NukeSped.EY trojan |
| Emsisoft | Trojan.GenericKD.34481685 (B) |
| Fortinet | W64/Patched.NETYYH!tr |
| GData | Trojan.GenericKD.34481685 |
| Detected | |
| K7AntiVirus | Trojan ( 005da7261 ) |
| K7GW | Trojan ( 005da7261 ) |
| Kaspersky | Trojan.Win64.Patched.netyyh |
| Kingsoft | Win32.Troj.Unknown.a |
| Lionic | Trojan.Win32.NukeSped.4!c |
| Malwarebytes | Malware.AI.4027951942 |
| MaxSecure | Trojan.Malware.106042850.susgen |
| McAfeeD | ti!ADCE894E3CE6 |
| MicroWorld-eScan | Trojan.GenericKD.34481685 |
| NANO-Antivirus | Trojan.Win64.Mlw.hrtyxb |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.NukeSped!8.3184 (KTSE) |
| Sangfor | Trojan.Win32.Lazarus.IOC |
| Skyhigh | BehavesLike.Win64.Dropper.vc |
| Sophos | Mal/Generic-S |
| Tencent | Malware.Win32.Gencirc.11c9330c |
| TrellixENS | Artemis!38032A4D12D9 |
| TrendMicro-HouseCall | TROJ_FRS.0NA103JM24 |
| VIPRE | Trojan.GenericKD.34481685 |
| Varist | W64/Patched.JKHR-7597 |
| ViRobot | Trojan.Win64.S.Agent.10507264 |
| Xcitium | Malware@#3hakj5lotlong |
| alibabacloud | Trojan:Win/NukeSped.EN |
| huorong | Trojan/Generic!839C2CB4AF26E230 |