2026-03-13_0cb4c08c70d54ef2967f7a0b62a0b11a_amadey_elex_play
Classification: Malicious
2026-03-13_0cb4c08c70d54ef2967f7a0b62a0b11a_amadey_elex_play is a malicious file sample. Linked to Play activity. Detected by 40 antivirus engines.
Detection summary
- 40 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: PLAY (G1040)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Play | Triage | 2026-03-13 03:10:08 | 2026-03-13 03:10:08 | malicious-activity | G1040 Play |
Tags
play discovery ransomware spyware stealerSample information
- Filenames
- 2026-03-13_0cb4c08c70d54ef2967f7a0b62a0b11a_amadey_elex_play
- MD5
0cb4c08c70d54ef2967f7a0b62a0b11a- SHA-1
1a80b6bdcea29ef7a49514ed6e79bb12b8cdf1ae- SHA-256
bbd84d10f6a56bfeca23fd5d11d9e370fdfa91be73aa60c9d460b2671145c109- SHA-512
0496ca715f474003bb4dce66653a54035eab2933710e75e658930e948d872be4e173578bd2ebee90956f9c49572624c44fbdb645afd0003bf400728179b80b1d- First indexed
- 2026-03-13 03:10:08
- Last updated
- 2026-03-13 03:10:08
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Ransom.Filecoder |
| APEX | Malicious |
| AhnLab-V3 | Ransomware/Win.Ransom.C5236645 |
| Alibaba | Backdoor:Win32/CobaltStrike.a5239f2a |
| Antiy-AVL | Trojan[Ransom]/Win32.PLAY |
| Arcabit | Trojan.Fugrafa.D40834 |
| Avira | TR/Crypt.XPACK.Gen8 |
| Bkav | W32.AIDetectMalware |
| ClamAV | Win.Ransomware.Play-10059714-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Fugrafa.264244 (B) |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen8 |
| Fortinet | W32/Filecoder.PLAY!tr.ransom |
| GData | Gen:Variant.Fugrafa.264244 |
| Detected | |
| Jiangmin | Trojan.Agent.eeyh |
| K7AntiVirus | Ransomware ( 005ce6d61 ) |
| K7GW | Ransomware ( 005ce6d61 ) |
| Kingsoft | malware.kb.a.994 |
| Lionic | Trojan.Win32.Agent.Y!c |
| Malwarebytes | Ransom.Play |
| MaxSecure | Trojan.Malware.592852672.susgen |
| McAfeeD | ti!BBD84D10F6A5 |
| MicroWorld-eScan | Gen:Variant.Fugrafa.264244 |
| Microsoft | Ransom:Win32/Play.D |
| NANO-Antivirus | Trojan.Win32.Encoder.jskekv |
| Paloalto | generic.ml |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Suspicious PE |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.10be2208 |
| TrendMicro | Ransom.Win32.PLAYDE.SMYXCIW |
| TrendMicro-HouseCall | Ransom.Win32.PLAYDE.SMYXCIW |
| VIPRE | Gen:Variant.Fugrafa.264244 |
| ViRobot | Trojan.Win.Z.Play.229376 |
| alibabacloud | Ransomware:Win/PLAY.B |