fafc62b9215345003160cbde5263ebd5.exe
Classification: Malicious
fafc62b9215345003160cbde5263ebd5.exe is a malicious file sample. Linked to Redline Stealer malware. Reported by 1 threat source, last seen 2023-09-27.
Detection summary
- 51 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: REDLINE STEALER (S1240)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RedLineStealer | MalwareBazaar Abuse.ch | 2023-09-27 02:30:31 | 2023-09-27 02:30:31 | malicious-activity | S1240 RedLine Stealer |
Sample information
- Filenames
- fafc62b9215345003160cbde5263ebd5.exe
- File type
- application/x-dosexec
- MD5
fafc62b9215345003160cbde5263ebd5- SHA-1
80650b4a0c9ec5b2afad5ac06c18b204c9869a51- SHA-256
b92114283b26e5d05da5f89a206c7f680082a01caf5831b3b1afc8ea4741102d- First indexed
- 2023-09-27 03:20:45
- Last updated
- 2026-09-02 14:58:14
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetectMalware |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Heur.Crifi.1 |
| CAT-QuickHeal | Trojan.Amadey |
| McAfee | Artemis!FAFC62B92153 |
| Malwarebytes | MachineLearning/Anomalous.94% |
| VIPRE | Gen:Heur.Crifi.1 |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 005aad751 ) |
| K7GW | Trojan ( 005aad751 ) |
| CrowdStrike | win/malicious_confidence_60% (W) |
| Cyren | W32/Kryptik.JKR.gen!Eldorado |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | multiple detections |
| APEX | Malicious |
| ClamAV | Win.Malware.Doina-10001799-0 |
| Kaspersky | UDS:Trojan-PSW.Win32.Stealerc.gen |
| BitDefender | Gen:Heur.Crifi.1 |
| NANO-Antivirus | Trojan.Win32.Deyma.jznztl |
| SUPERAntiSpyware | Trojan.Agent/Gen-Downloader |
| Avast | Win32:PWSX-gen [Trj] |
| Rising | Downloader.Deyma!8.1093B (TFE:5:x1KJS1Uk8EV) |
| Emsisoft | Gen:Heur.Crifi.1 (B) |
| F-Secure | Trojan.TR/AD.Nekark.svgaq |
| DrWeb | Trojan.KillProc2.21523 |
| TrendMicro | TrojanSpy.Win32.TRICKBOT.SMC |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.tc |
| Trapmine | malicious.high.ml.score |
| FireEye | Gen:Heur.Crifi.1 |
| Sophos | Troj/PlugX-EC |
| Ikarus | Trojan.Spy.Stealer |
| GData | Win32.Trojan-Downloader.Amadey.D (2x) |
| Jiangmin | TrojanDownloader.Deyma.arg |
| Detected | |
| Avira | TR/AD.Nekark.svgaq |
| MAX | malware (ai score=88) |
| Antiy-AVL | Trojan/Win32.Sabsik |
| Kingsoft | malware.kb.a.974 |
| Gridinsoft | Spy.Win32.Redline.lu!heur |
| Xcitium | Malware@#201xseck53xax |
| Arcabit | Trojan.Crifi.1 |
| ZoneAlarm | HEUR:Trojan-PSW.Win32.Stealerc.gen |
| Microsoft | Trojan:Script/Phonzy.B!ml |
| Cynet | Malicious (score: 99) |
| Acronis | suspicious |
| ALYac | Gen:Heur.Crifi.1 |
| TrendMicro-HouseCall | TrojanSpy.Win32.TRICKBOT.SMC |
| SentinelOne | Static AI - Suspicious SFX |
| Fortinet | W32/Kryptik.JKR!tr |
| AVG | Win32:PWSX-gen [Trj] |
| Cybereason | malicious.a0c9ec |