file

Classification: Malicious

file is a malicious file sample. Linked to Invisimole malware. Reported by 2 threat sources, last seen 2023-04-01. Detected by 42 antivirus engines.

Detection summary

  • 42 antivirus detections (51% detection ratio)
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: INVISIMOLE (S0260)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Invisimole Maltiverse 2023-03-31 04:13:54 2023-04-01 00:17:31 malicious-activity S0260 InvisiMole
Ghostwriter Maltiverse 2023-03-31 04:13:54 2023-04-01 00:17:25 malicious-activity
Trojan.Win64.Patched Hybrid-Analysis 2020-11-25 10:17:08 2020-11-25 10:17:08

Tags

apt

Sample information

Filenames
file
File type
PE32+ executable (GUI) x86-64, for MS Windows
Size
10507264 bytes
MD5
38032a4d12d9e3029f00b120200e8e68
SHA-1
382bdd11c605882ccb149f0d23707a7ee5f4b89a
SHA-256
adce894e3ce69c9822da57196707c7a15acee11319ccc963b84d83c23c3ea802
First indexed
2020-11-25 10:17:08
Last updated
2026-05-03 04:51:34

Antivirus detections

EngineDetection
ALYacTrojan.Agent.1054607L
AhnLab-V3Trojan/Win64.Agent.C4180606
AlibabaTrojan:Win64/NukeSped.bc3cc400
Antiy-AVLTrojan[APT]/Win32.Lazarus
ArcabitTrojan.Generic.D20E2615
BitDefenderTrojan.GenericKD.34481685
CTXexe.trojan.nukesped
ClamAVWin.Malware.Agent-9378216-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebBackDoor.NukeSped.98
ESET-NOD32Win64/NukeSped.EY trojan
EmsisoftTrojan.GenericKD.34481685 (B)
FortinetW64/Patched.NETYYH!tr
GDataTrojan.GenericKD.34481685
GoogleDetected
K7AntiVirusTrojan ( 005da7261 )
K7GWTrojan ( 005da7261 )
KasperskyTrojan.Win64.Patched.netyyh
KingsoftWin32.Troj.Unknown.a
LionicTrojan.Win32.NukeSped.4!c
MalwarebytesMalware.AI.4027951942
MaxSecureTrojan.Malware.106042850.susgen
McAfeeDti!ADCE894E3CE6
MicroWorld-eScanTrojan.GenericKD.34481685
NANO-AntivirusTrojan.Win64.Mlw.hrtyxb
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingTrojan.NukeSped!8.3184 (KTSE)
SangforTrojan.Win32.Lazarus.IOC
SkyhighBehavesLike.Win64.Dropper.vc
SophosMal/Generic-S
TencentMalware.Win32.Gencirc.11c9330c
TrellixENSArtemis!38032A4D12D9
TrendMicro-HouseCallTROJ_FRS.0NA103JM24
VIPRETrojan.GenericKD.34481685
VaristW64/Patched.JKHR-7597
ViRobotTrojan.Win64.S.Agent.10507264
XcitiumMalware@#3hakj5lotlong
alibabacloudTrojan:Win/NukeSped.EN
huorongTrojan/Generic!839C2CB4AF26E230