jivarthr edis.exe
Classification: Malicious
jivarthr edis.exe is a malicious file sample. Linked to Crimson malware. Reported by 1 threat source, last seen 2025-02-16. Detected by 51 antivirus engines.
Detection summary
- 51 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: CRIMSON (S0115)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| CrimsonRAT | MalwareBazaar Abuse.ch | 2025-02-16 20:16:29 | 2025-02-16 20:16:29 | malicious-activity | S0115 Crimson |
Sample information
- Filenames
- jivarthr edis.exe
- File type
- application/x-dosexec
- MD5
3a231bcc60569143aa899295e4a5ce8a- SHA-1
8916cceb3f1b309d866bea10da41465baf720b00- SHA-256
b5c8e2afa1091e9513da06cfaa1ceed25e091692cdfe7f304e367c58957e2d63- First indexed
- 2025-02-16 21:24:17
- Last updated
- 2025-02-16 21:24:17
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | IL:Trojan.MSILZilla.171909 |
| AVG | Win32:BackdoorX-gen [Trj] |
| AhnLab-V3 | Malware/Win32.RL_Generic.C4268806 |
| Alibaba | Backdoor:MSIL/CrimsonRat.ce19f5f3 |
| Antiy-AVL | Trojan/MSIL.Agent |
| Arcabit | IL:Trojan.MSILZilla.D29F85 |
| Avast | Win32:BackdoorX-gen [Trj] |
| Avira | TR/Agent.epvoa |
| BitDefender | IL:Trojan.MSILZilla.171909 |
| CAT-QuickHeal | Trojan.Ghanarava.1738930471a5ce8a |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.CrimsonNET.14 |
| ESET-NOD32 | a variant of MSIL/Agent.BNY |
| Elastic | malicious (high confidence) |
| Emsisoft | IL:Trojan.MSILZilla.171909 (B) |
| F-Secure | Trojan.TR/Agent.epvoa |
| FireEye | Generic.mg.3a231bcc60569143 |
| Fortinet | MSIL/Agent.BNY!tr |
| GData | IL:Trojan.MSILZilla.171909 |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.sa |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 0053965f1 ) |
| K7GW | Trojan ( 0053965f1 ) |
| Kaspersky | HEUR:Backdoor.MSIL.CrimsonRat.gen |
| Kingsoft | MSIL.Backdoor.CrimsonRat.gen |
| Lionic | Trojan.Win32.CrimsonRat.m!c |
| Malwarebytes | Malware.AI.4283621955 |
| McAfee | Artemis!3A231BCC6056 |
| McAfeeD | ti!B5C8E2AFA109 |
| MicroWorld-eScan | IL:Trojan.MSILZilla.171909 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Backdoor.Crimson!1.EA63 (CLASSIC) |
| Sangfor | Backdoor.Msil.Agent.Vrum |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.1431def8 |
| TrendMicro-HouseCall | TROJ_GEN.R002H09B625 |
| VBA32 | Backdoor.MSIL.Crimson.Heur |
| VIPRE | IL:Trojan.MSILZilla.171909 |
| Varist | W32/ABTrojan.UWKK-1312 |
| Zillya | Trojan.Agent.Win32.4157503 |
| alibabacloud | Trojan:MSIL/MSILHeracles.Gen |
| huorong | Backdoor/MSIL.CrimsonRat.b |