2e942eab2c5befacb890b69e79044057.exe
Classification: Malicious
2e942eab2c5befacb890b69e79044057.exe is a malicious file sample. Linked to Runningrat malware. Reported by 1 threat source, last seen 2024-09-27.
Detection summary
- 63 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: RUNNINGRAT (S0253)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RunningRAT | MalwareBazaar Abuse.ch | 2024-09-27 09:00:33 | 2024-09-27 09:00:33 | malicious-activity | S0253 RunningRAT |
Sample information
- Filenames
- 2e942eab2c5befacb890b69e79044057.exe
- File type
- application/x-dosexec
- MD5
2e942eab2c5befacb890b69e79044057- SHA-1
4d920e9e3b579ecff2169e245349ff04cee06a91- SHA-256
d1347d9e940bd05c1e34f37c9c716314b88fe6edd243719307df79dbaaedebfd- First indexed
- 2024-09-27 10:20:32
- Last updated
- 2026-02-11 12:56:05
Antivirus detections
| Engine | Detection |
|---|---|
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Drp] |
| AhnLab-V3 | Trojan/Win32.Agent.R128989 |
| Alibaba | Backdoor:Win32/YoungLotus.07a97656 |
| Antiy-AVL | Trojan/Win32.Farfli |
| Arcabit | Trojan.RI.1 |
| Avast | Win32:MalwareX-gen [Drp] |
| Avira | TR/AD.Farfli.qqkhu |
| BitDefender | Gen:Heur.RI.1 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Younglotus.20397 |
| CTX | exe.trojan.farfli |
| ClamAV | Win.Dropper.Gh0stRAT-7073897-1 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.DownLoader12.47777 |
| ESET-NOD32 | Win32/Farfli.BGW |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Heur.RI.1 (B) |
| F-Secure | Trojan.TR/AD.Farfli.qqkhu |
| Fortinet | W32/Farfli.BGW!tr |
| GData | Gen:Heur.RI.1 |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.vl!n |
| Ikarus | Trojan.Win32.Farfli |
| Jiangmin | Trojan/YoungLotus.e |
| K7AntiVirus | Trojan ( 0055e3e41 ) |
| K7GW | Trojan ( 0055e3e41 ) |
| Kaspersky | Trojan.Win32.YoungLotus.t |
| Kingsoft | Win32.Trojan.YoungLotus.t |
| Lionic | Trojan.Win32.YoungLotus.tsAS |
| Malwarebytes | Malware.AI.4194114185 |
| McAfeeD | ti!D1347D9E940B |
| MicroWorld-eScan | Gen:Heur.RI.1 |
| Microsoft | Backdoor:Win32/Venik!pz |
| NANO-Antivirus | Trojan.Win32.YoungLotus.dpanmc |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Farfli!1.C639 (KTSE) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Zusy |
| Sangfor | Backdoor.Win32.Farfli.Vkvf |
| Skyhigh | BehavesLike.Win32.Backdoor.pm |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| TACHYON | Trojan/W32.Agent.49152.CCZ |
| Tencent | Malware.Win32.Gencirc.10b39405 |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | BackDoor-FCWQ!2E942EAB2C5B |
| TrendMicro | BKDR_ZEGOST.SM29 |
| TrendMicro-HouseCall | BKDR_ZEGOST.SM29 |
| VBA32 | BScope.Backdoor.Caphaw |
| VIPRE | Gen:Heur.RI.1 |
| Varist | W32/S-0f55ee81!Eldorado |
| VirIT | Backdoor.Win32.Generic.JUY |
| Webroot | Trojan.Younglotus |
| Xcitium | TrojWare.Win32.YoungLotus.TCM@5ruomd |
| Yandex | Trojan.GenAsa!BZKdUv1dR3c |
| Zillya | Trojan.YoungLotus.Win32.4 |
| Zoner | Trojan.Win32.97590 |
| alibabacloud | Backdoor:Win/Farfli |
| huorong | Backdoor/Farfli.bn |