c80656fe59bdeb3e701d1f7eeaaba2ef673368b2c4947945f598e3e84a6cb7f8
Classification: Malicious
c80656fe59bdeb3e701d1f7eeaaba2ef673368b2c4947945f598e3e84a6cb7f8 is a malicious file sample. Linked to Sandworm Team activity.
Detection summary
- 29 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-04-27 04:27:30 | 2023-04-28 14:38:31 | malicious-activity | G0034 Sandworm Team |
Tags
aptSample information
- SHA-256
c80656fe59bdeb3e701d1f7eeaaba2ef673368b2c4947945f598e3e84a6cb7f8- First indexed
- 2023-04-28 14:38:31
- Last updated
- 2023-04-28 14:38:31
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.ZIP.Stealer.4!c |
| K7AntiVirus | Trojan ( 0059df7d1 ) |
| BitDefender | Gen:Variant.Barys.382627 |
| K7GW | Trojan ( 0059df7d1 ) |
| Baidu | Archive.Bomb |
| Symantec | Trojan.Gen.NPE |
| ESET-NOD32 | a variant of MSIL/Kryptik.AHUA |
| Cynet | Malicious (score: 70) |
| Kaspersky | HEUR:Trojan-Spy.MSIL.Stealer.gen |
| Alibaba | TrojanSpy:MSIL/Stealer.1f5bc412 |
| MicroWorld-eScan | Gen:Variant.Barys.382627 |
| Tencent | Msil.Trojan-Spy.Stealer.Czlw |
| Emsisoft | Gen:Variant.Barys.382627 (B) |
| F-Secure | Trojan.TR/Crypt.OPACK.Gen |
| VIPRE | Gen:Variant.Barys.382627 |
| McAfee-GW-Edition | Artemis |
| FireEye | Gen:Variant.Barys.382627 |
| Sophos | Mal/MSIL-VD |
| Avira | HEUR/Pumpar.Gen |
| Microsoft | Trojan:MSIL/AgentTesla!MSR |
| Arcabit | Trojan.Barys.D5D6A3 |
| ViRobot | Trojan.Win.S.Agent.688283232 |
| ZoneAlarm | HEUR:Trojan-Spy.MSIL.Stealer.gen |
| GData | Gen:Variant.Barys.382627 |
| Acronis | suspicious |
| Rising | Malware.SwollenFile!1.E38A (CLASSIC) |
| MAX | malware (ai score=84) |
| MaxSecure | Trojan.Malware.73709669.susgen |
| Panda | Trj/GdSda.A |