c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c
Classification: Malicious
c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c is a malicious file sample. Linked to Zerot malware. Detected by 46 antivirus engines.
Detection summary
- 46 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-08-26 08:45:13 |
2025-08-26 08:45:13 |
|
|
| ZeroT |
ThreatFox Abuse.ch |
2024-05-30 14:51:50 |
2024-06-01 14:20:03 |
|
S0230 ZeroT
|
Tags
win.zerot
evasive
malicious
Sample information
- Filenames
- c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c
- File type
- PE32+ executable for MS Windows 5.02 (GUI), x86-64 ...
- Size
- 864897 bytes
- MD5
1eaae465bda927c1893a5744301cde9b
- SHA-1
6d5f62d54dda0a61f5f7a8b2cbbff86cf2ac2ae9
- SHA-256
c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c
- First indexed
- 2024-05-30 15:18:42
- Last updated
- 2025-08-31 00:07:37
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Hulk.Gen.5 |
| APEX | Malicious |
| AVG | Win64:Malware-gen |
| Alibaba | Backdoor:Win32/Glupteba.76aa800a |
| Arcabit | Trojan.Hulk.Gen.5 |
| Avast | Win64:Malware-gen |
| Avira | TR/AVI.Agent.uvblx |
| BitDefender | Trojan.Hulk.Gen.5 |
| CAT-QuickHeal | Backdoor.Farfli |
| CrowdStrike | win/malicious_confidence_70% (W) |
| Cybereason | malicious.5bda92 |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop26.27889 |
| ESET-NOD32 | a variant of Win32/Kryptik.HWJL |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Hulk.Gen.5 (B) |
| F-Secure | Trojan:W32/GenInflated.B |
| FireEye | Generic.mg.1eaae465bda927c1 |
| GData | Trojan.Hulk.Gen.5 |
| Google | Detected |
| Gridinsoft | Trojan.Win64.Kryptik.sa |
| Ikarus | Trojan.Win32.Crypt |
| K7AntiVirus | Riskware ( 00584baa1 ) |
| K7GW | Riskware ( 00584baa1 ) |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| Kingsoft | Win32.Hack.Farfli.gen |
| Lionic | Trojan.Win32.Hulk.4!c |
| MAX | malware (ai score=80) |
| Malwarebytes | Malware.AI.2282942247 |
| McAfee | Artemis!1EAAE465BDA9 |
| McAfeeD | ti!C297E02F804F |
| MicroWorld-eScan | Trojan.Hulk.Gen.5 |
| Microsoft | Trojan:Win32/Glupteba.AMMA!MTB |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Trojan.SmokeLoader!1.F600 (CLASSIC) |
| Sangfor | Virus.Win32.Save.a |
| Skyhigh | BehavesLike.Win64.Expiro.cc |
| Sophos | Mal/Generic-R |
| Symantec | Trojan.Gen.MBT |
| Tencent | Win32.Backdoor.Farfli.Wylw |
| TrendMicro-HouseCall | TROJ_GEN.R002H01ES24 |
| VIPRE | Trojan.Hulk.Gen.5 |
| ZoneAlarm | HEUR:Backdoor.Win32.Farfli.gen |
| alibabacloud | Malware |
Process list
| Name | Command line |
| c297e02f804f7c95762ada2efb98866c6a509db4ace8bf06f95af3a41c8e702c.exe | |
| csrss.exe | |
| Jufrxnb.exe | |
| Jufrxnb.exe | |
| Jufrxnb.exe | |