01e2a830989de3a870e4a2dac876487a.exe
Classification: Malicious
01e2a830989de3a870e4a2dac876487a.exe is a malicious file sample. Linked to Sandworm Team, Earth Lusca activity. Detected by 53 antivirus engines.
Detection summary
- 53 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034) EARTH LUSCA (G1006)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:13 | malicious-activity | G0034 Sandworm Team |
| Earth Lusca | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:10 | malicious-activity | G1006 Earth Lusca |
| TitanStealer | MalwareBazaar Abuse.ch | 2022-12-25 13:52:52 | 2022-12-25 13:52:52 | malicious-activity |
Tags
aptSample information
- Filenames
- 01e2a830989de3a870e4a2dac876487a.exe
- File type
- application/x-dosexec
- MD5
01e2a830989de3a870e4a2dac876487a- SHA-1
70f91a528227f6746fb932deb2b3f1e4011953ee- SHA-256
af58e830feef2f4086fb52dafda6084b3b85c6200f4cbc35a5460fb703dd39df- First indexed
- 2022-12-27 12:19:21
- Last updated
- 2023-03-03 14:34:13
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Strab.tsdR |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Trojan.Generic.32765657 |
| McAfee | Artemis!01E2A830989D |
| Cylance | Unsafe |
| Sangfor | Spyware.Win32.Agent.Vzkk |
| K7AntiVirus | Trojan ( 0059aca31 ) |
| Alibaba | TrojanSpy:Win32/PackBackdoor.93eb099d |
| K7GW | Trojan ( 0059aca31 ) |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cyren | W32/ABSpyware.XGTW-5559 |
| Symantec | Trojan Horse |
| ESET-NOD32 | a variant of WinGo/Spy.Agent.AI |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | HEUR:Trojan-PSW.Win32.Coins.pef |
| BitDefender | Trojan.Generic.32765657 |
| ViRobot | Trojan.Win32.S.Agent.2068480.AK |
| Rising | [email protected] (RDML:ji1XAJQ/KZiaooy8Hk6Zeg) |
| Emsisoft | Trojan.Generic.32765657 (B) |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen |
| DrWeb | Trojan.PWS.Steam.34259 |
| VIPRE | Trojan.Generic.32765657 |
| TrendMicro | TROJ_FRS.VSNTKE22 |
| McAfee-GW-Edition | BehavesLike.Win32.Ctsinf.tm |
| FireEye | Generic.mg.01e2a830989de3a8 |
| Sophos | Troj/Steal-DHD |
| SentinelOne | Static AI - Suspicious PE |
| GData | Trojan.Generic.32765657 |
| Webroot | W32.Trojan.Gen |
| Detected | |
| Avira | TR/Crypt.XPACK.Gen |
| Antiy-AVL | Trojan[Spy]/Win32.Agent |
| Kingsoft | Win32.PSWTroj.Undef.(kcloud) |
| Xcitium | Malware@#1w7rh0e4sqnep |
| Arcabit | Trojan.Generic.D1F3F6D9 |
| ZoneAlarm | HEUR:Trojan-PSW.Win32.Coins.pef |
| Microsoft | Trojan:Win32/TitanStealer.PA!MTB |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Infostealer/Win.Titan.R555644 |
| BitDefenderTheta | Gen:NN.ZexaF.36276.!zW@aaVNQTf |
| ALYac | Trojan.Stealer.Titan |
| MAX | malware (ai score=83) |
| VBA32 | TrojanPSW.Titan |
| Malwarebytes | Malware.AI.3268927761 |
| Panda | Trj/Chgt.AD |
| TrendMicro-HouseCall | TROJ_FRS.VSNTKE22 |
| Tencent | Win32.Trojan.Strab.Wimw |
| Ikarus | Trojan-Spy.TitanStealer |
| MaxSecure | Trojan.Malware.101228155.susgen |
| Fortinet | W32/PossibleThreat |
| AVG | Win32:Trojan-gen |
| Avast | Win32:Trojan-gen |