Classification: Malicious
CheraxLoader.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 46 antivirus engines.
Detection summary
- 46 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-09-02 14:49:11 |
2026-09-02 14:49:11 |
anomalous-activity
|
|
| Generic Malware |
Triage |
2026-02-03 07:01:36 |
2026-05-07 19:55:35 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2026-01-29 18:35:14 |
2026-02-03 16:45:05 |
|
|
Tags
discovery
persistence
ransomware
adware
spyware
privilege_escalation
defense_evasion
Sample information
- Filenames
- CheraxLoader.exe, CheraxLoader (2).exe, ae348abf0227e0fe4c20c39c6ce043ca66ad81a885727801649d240a08e7599f.bin
- File type
- PE32+ executable for MS Windows 6.00 (GUI), x86-64 ...
- MD5
497224172d017166b71489fb91b25bbb
- SHA-1
865890c4001cae75530a5a21512538749024cf7c
- SHA-256
ae348abf0227e0fe4c20c39c6ce043ca66ad81a885727801649d240a08e7599f
- SHA-512
d83c1b2340fcd067af9ce9d58f3e76cfc0ce4b3388aabe18261346ee103ce539830ceaa7fe4cc6707b148c59cd05cfbd7807546b9bb420e0270d669afdaa47f5
- First indexed
- 2026-01-29 17:42:56
- Last updated
- 2026-09-02 14:55:13
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Mikey.183834 |
| AVG | Win64:MalwareX-gen [Misc] |
| AhnLab-V3 | Trojan/Win.Generic.C5833492 |
| Alibaba | Trojan:Win32/Malgent.58bf5458 |
| Antiy-AVL | Trojan/Win32.Sabsik |
| Arcabit | Trojan.Mikey.D2CE1A |
| Avast | Win64:MalwareX-gen [Misc] |
| BitDefender | Gen:Variant.Mikey.183834 |
| Bkav | W64.AIDetectMalware |
| CAT-QuickHeal | Trojan.Malgent |
| CTX | exe.trojan.malgent |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | Win64/Agent_AGen.IWX trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Mikey.183834 (B) |
| Fortinet | W64/Agent_AGen.IWX!tr |
| GData | Gen:Variant.Mikey.183834 |
| Google | Detected |
| Gridinsoft | Ransom.Win64.Sabsik.sa |
| Ikarus | Trojan.Win64.Agent |
| K7AntiVirus | Trojan ( 006d54e91 ) |
| K7GW | Trojan ( 006d54e91 ) |
| Lionic | Trojan.Win32.Malgent.4!c |
| Malwarebytes | Malware.AI.3542213673 |
| MaxSecure | Trojan.Malware.338148470.susgen |
| MicroWorld-eScan | Gen:Variant.Mikey.183834 |
| Microsoft | Trojan:Win32/Malgent!MSR |
| Paloalto | generic.ml |
| Rising | Malware.Undefined!8.C (TFE:5:1vgogTPQeMC) |
| Sangfor | Trojan.Win32.Malgent.Vksy |
| Skyhigh | BehavesLike.Win64.Dropper.vh |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.14a8914f |
| TrellixENS | Artemis!497224172D01 |
| TrendMicro | TROJ_GEN.R002C0DB626 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DB626 |
| VIPRE | Gen:Variant.Mikey.183834 |
| Varist | W64/ABTrojan.KZMR-2848 |
| ViRobot | Trojan.Win.Z.Mikey.6727680 |
| Yandex | Trojan.Igent.b52tVu.8 |
| Zillya | Trojan.AgentAGen.Win64.27925 |
| alibabacloud | Trojan:Win/Agent_AGen.IIF |