c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c

Classification: Malicious

c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c is a malicious file sample. Linked to Zerot malware. Detected by 46 antivirus engines.

Detection summary

  • 46 antivirus detections
  • 0 IDS alerts
  • 5 processes observed
  • 1 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Malware families: ZEROT (S0230)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-08-26 08:45:13 2025-08-26 08:45:13
ZeroT ThreatFox Abuse.ch 2024-05-30 14:51:50 2024-06-01 14:20:03 S0230 ZeroT

Tags

win.zerot evasive malicious

Sample information

Filenames
c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c
File type
PE32+ executable for MS Windows 5.02 (GUI), x86-64 ...
Size
864897 bytes
MD5
1eaae465bda927c1893a5744301cde9b
SHA-1
6d5f62d54dda0a61f5f7a8b2cbbff86cf2ac2ae9
SHA-256
c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c
First indexed
2024-05-30 15:18:42
Last updated
2025-08-31 00:07:37

Antivirus detections

EngineDetection
ALYacTrojan.Hulk.Gen.5
APEXMalicious
AVGWin64:Malware-gen
AlibabaBackdoor:Win32/Glupteba.76aa800a
ArcabitTrojan.Hulk.Gen.5
AvastWin64:Malware-gen
AviraTR/AVI.Agent.uvblx
BitDefenderTrojan.Hulk.Gen.5
CAT-QuickHealBackdoor.Farfli
CrowdStrikewin/malicious_confidence_70% (W)
Cybereasonmalicious.5bda92
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebTrojan.MulDrop26.27889
ESET-NOD32a variant of Win32/Kryptik.HWJL
Elasticmalicious (high confidence)
EmsisoftTrojan.Hulk.Gen.5 (B)
F-SecureTrojan:W32/GenInflated.B
FireEyeGeneric.mg.1eaae465bda927c1
GDataTrojan.Hulk.Gen.5
GoogleDetected
GridinsoftTrojan.Win64.Kryptik.sa
IkarusTrojan.Win32.Crypt
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
KasperskyUDS:DangerousObject.Multi.Generic
KingsoftWin32.Hack.Farfli.gen
LionicTrojan.Win32.Hulk.4!c
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2282942247
McAfeeArtemis!1EAAE465BDA9
McAfeeDti!C297E02F804F
MicroWorld-eScanTrojan.Hulk.Gen.5
MicrosoftTrojan:Win32/Glupteba.AMMA!MTB
Paloaltogeneric.ml
PandaTrj/CI.A
RisingTrojan.SmokeLoader!1.F600 (CLASSIC)
SangforVirus.Win32.Save.a
SkyhighBehavesLike.Win64.Expiro.cc
SophosMal/Generic-R
SymantecTrojan.Gen.MBT
TencentWin32.Backdoor.Farfli.Wylw
TrendMicro-HouseCallTROJ_GEN.R002H01ES24
VIPRETrojan.Hulk.Gen.5
ZoneAlarmHEUR:Backdoor.Win32.Farfli.gen
alibabacloudMalware

Network contacts

156.238.237.180

DNS requests

www.exiles.site

Process list

NameCommand line
c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c.exe
csrss.exe
Jufrxnb.exe
Jufrxnb.exe
Jufrxnb.exe