2026-07-08_d0de43d78ced368c984869237350ec82_cobalt-strike_elex_glassworm_icedid_luca-stealer_njrat

Classification: Malicious

2026-07-08_d0de43d78ced368c984869237350ec82_cobalt-strike_elex_glassworm_icedid_luca-stealer_njrat is a malicious file sample.

Detection summary

  • 53 antivirus detections
  • 2 IDS alerts
  • 0 processes observed
  • 7 contacted hosts
  • 7 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Triage 2026-07-07 16:41:39 2026-07-08 19:56:32 malicious-activity
Generic Malware Hybrid-Analysis 2026-07-07 17:45:06 2026-07-07 17:45:06 malicious-activity

Tags

collection credential_access discovery persistence spyware stealer evasive infostealer adware ransomware

Sample information

Filenames
2026-07-08_d0de43d78ced368c984869237350ec82_cobalt-strike_elex_glassworm_icedid_luca-stealer_njrat, b6e3edc8309e574d4cef309b18b2db7bec607f0b0003bc2fef3675a6d8c74bf4.bin, b6e3edc8309e574d4cef309b18b2db7bec607f0b0003bc2fef3675a6d8c74bf4.exe
File type
PE32 executable for MS Windows 4.00 (GUI), Intel i ...
MD5
d0de43d78ced368c984869237350ec82
SHA-1
cfee0bdc26288128e4ababa07a98225bc38fb0f0
SHA-256
b6e3edc8309e574d4cef309b18b2db7bec607f0b0003bc2fef3675a6d8c74bf4
First indexed
2026-07-07 16:41:39
Last updated
2026-09-03 00:35:17

Antivirus detections

EngineDetection
ALYacDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541
APEXMalicious
AVGWin64:DmpBrowserSec-C [Hack]
AhnLab-V3Trojan/Win.Generic.C5896460
AlibabaTrojanPSW:MSIL/ClipBanker.ffc8bf80
Antiy-AVLTrojan[PSW]/MSIL.Stealer
ArcabitDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541
AvastWin64:DmpBrowserSec-C [Hack]
AviraTR/W64.DmpBrowserSe.C
BitDefenderDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541
BkavW32.Malware.7CAEBD66
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
CTXexe.trojan.msil
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DrWebTrojan.PWS.StealerNET.75
ESET-NOD32MSIL/Spy.Agent.DRY trojan
Elasticmalicious (high confidence)
EmsisoftDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541 (B)
F-SecureTrojan.TR/W64.DmpBrowserSe.C
FortinetMSIL/Agent.DRY!tr
GDataDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541
GoogleDetected
GridinsoftTrojan.Win32.Agent.sa
K7AntiVirusTrojan ( 700000201 )
K7GWTrojan ( 700000201 )
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
LionicTrojan.Win32.Dump.i!c
MalwarebytesAsyncRAT.Backdoor.Rat.DDS
MaxSecureTrojan.Malware.121218.susgen
McAfeeDReal Protect-LS!D0DE43D78CED
MicroWorld-eScanDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541
MicrosoftTrojan:MSIL/ClipBanker.GC!MTB
Paloaltogeneric.ml
PandaTrj/GdSda.A
RisingSpyware.Agent!8.C6 (C64:YzY0Or56XQaZTif1)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Infected.bh
SophosTroj/Steal-FIT
SymantecML.Attribute.HighConfidence
TencentTrojan.Msil.Spy.16004187
TrellixENSArtemis!D0DE43D78CED
TrendMicroTrojan.Win32.ZYX.USBLG426
TrendMicro-HouseCallTrojan.Win32.ZYX.USBLG426
VBA32Trojan.MSIL.InfoStealer.gen.D
VIPREDump:Generic.Trojan.TangoStealer.Marte.A.F9A28541
VaristW32/MSIL_Stealer.W.gen!Eldorado
ViRobotTrojan.Win.Z.Stealer.763904.Y
VirITTrojan.Win32.MSIL_Heur.B
ZoneAlarmTroj/Steal-FIT
alibabacloudTrojan[spy]:MSIL/Cerbu.Gen
huorongTrojanSpy/MSIL.Agent.cb

Network contacts

104.16.184.241 149.154.166.110 142.251.219.46 142.251.218.193 150.171.110.193 216.239.38.223 150.171.109.73

DNS requests

api.telegram.org clients2.google.com clients2.googleusercontent.com edge-consumer-static.azureedge.net edgeassetservice.azureedge.net icanhazip.com www.googleapis.com