aea823d6446fbf9059391125a9b7fceb9f433b846275d28dc5f433645984a683.exe
Classification: Malicious
aea823d6446fbf9059391125a9b7fceb9f433b846275d28dc5f433645984a683.exe is a malicious file sample. Linked to Sandworm Team, Earth Lusca activity.
Detection summary
- 75 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034) EARTH LUSCA (G1006)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:14 | malicious-activity | G0034 Sandworm Team |
| Earth Lusca | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:11 | malicious-activity | G1006 Earth Lusca |
| Spyware | VM-Ray | 2022-12-14 16:37:40 | 2022-12-14 16:37:40 | ||
| Injector | VM-Ray | 2022-12-14 16:37:40 | 2022-12-14 16:37:40 |
Tags
aptSample information
- Filenames
- aea823d6446fbf9059391125a9b7fceb9f433b846275d28dc5f433645984a683.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- SHA-256
aea823d6446fbf9059391125a9b7fceb9f433b846275d28dc5f433645984a683- First indexed
- 2022-12-14 14:42:47
- Last updated
- 2026-01-27 09:38:37
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Strab.4!c |
| MicroWorld-eScan | Gen:Variant.MSILHeracles.56017 |
| McAfee | Artemis!78601B24A38D |
| Cylance | Unsafe |
| Zillya | Trojan.GenKryptik.Win32.161630 |
| Sangfor | Suspicious.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | Trojan:MSIL/TitanStealer.c3224957 |
| K7GW | Trojan ( 0059a3d01 ) |
| K7AntiVirus | Trojan ( 0059a3d01 ) |
| BitDefenderTheta | Gen:NN.ZemsilF.36276.@x0@a0tbUrg |
| VirIT | Trojan.Win32.Genus.NHH |
| Cyren | W32/ABRisk.KUVM-4718 |
| Symantec | Trojan.Gen.2 |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | a variant of MSIL/GenKryptik.GBSP |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | HEUR:Trojan.MSIL.Strab.gen |
| BitDefender | Gen:Variant.MSILHeracles.56017 |
| NANO-Antivirus | Trojan.Win32.Strab.jtwodo |
| Avast | Win32:Trojan-gen |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:UtOvRtNcHTpqWRn7/b1lhg) |
| Emsisoft | Gen:Variant.MSILHeracles.56017 (B) |
| DrWeb | Trojan.PWS.Steam.34324 |
| VIPRE | Gen:Variant.MSILHeracles.56017 |
| TrendMicro | Trojan.Win32.PRIVATELOADER.YXCLNZ |
| McAfee-GW-Edition | Artemis!Trojan |
| Trapmine | suspicious.low.ml.score |
| FireEye | Generic.mg.78601b24a38dd397 |
| Sophos | Mal/Generic-S |
| Ikarus | Trojan.MSIL.Krypt |
| Webroot | W32.Trojan.Gen |
| Detected | |
| Avira | TR/Kryptik.krrbj |
| Antiy-AVL | Trojan/MSIL.GenKryptik |
| Kingsoft | malware.kb.c.(kcloud) |
| Microsoft | Trojan:MSIL/TitanStealer!MTB |
| Gridinsoft | Ransom.Win32.Sabsik.ns |
| Xcitium | Malware@#5zl5tf9b205i |
| Arcabit | Trojan.MSILHeracles.DDAD1 |
| ViRobot | Trojan.Win32.S.Agent.9916928 |
| ZoneAlarm | HEUR:Trojan.MSIL.Strab.gen |
| GData | Gen:Variant.MSILHeracles.56017 |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Injection.C5337031 |
| ALYac | Trojan.Stealer.Titan |
| MAX | malware (ai score=81) |
| VBA32 | CIL.StupidPInvoker-1.Heur |
| Malwarebytes | Trojan.Crypt.MSIL |
| TrendMicro-HouseCall | Trojan.Win32.PRIVATELOADER.YXCLNZ |
| Tencent | Msil.Trojan.Strab.Vimw |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | MSIL/GenKryptik.GBSP!tr |
| AVG | Win32:Trojan-gen |
| Panda | Trj/Chgt.AB |
| Avira | TR/Dropper.MSIL.Gen |
| Bkav | W32.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Ghanarava.1728957315ba52bd |
| CTX | exe.trojan.msil |
| DeepInstinct | MALICIOUS |
| F-Secure | Trojan.TR/Dropper.MSIL.Gen |
| Gridinsoft | Trojan.Heur!.03013281 |
| Ikarus | Trojan.MSIL.Crypt |
| Kingsoft | MSIL.Trojan.Strab.gen |
| MaxSecure | Trojan.Malware.124038686.susgen |
| McAfeeD | ti!AEA823D6446F |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.tc |
| Symantec | Trojan Horse |
| Tencent | Malware.Win32.Gencirc.13b7e15c |
| TrendMicro | TROJ_GEN.R002C0DJ524 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DJ524 |
| Varist | W32/ABRisk.KUVM-4718 |
| alibabacloud | Trojan:MSIL/TitanStealer.Gen |