d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll

Classification: Malicious

d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll is a malicious file sample. Linked to Squirrelwaffle malware.

Detection summary

  • 30 antivirus detections
  • 0 IDS alerts
  • 3 processes observed
  • 1 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Malware families: SQUIRRELWAFFLE (S1030)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-01-11 08:15:04 2025-01-11 10:00:09
Squirrelwaffle Abuse.ch 2021-10-01 04:26:03 2021-10-01 04:26:03 malicious-activity S1030 Squirrelwaffle

Tags

adwind agenttesla alienspy banker bladabindi chanitor chthonic cridex crimson darkcomet dofoil dridex dyre dyreza emotet fareit gootkit gozi hancitor hawkeye infostealer isfb keylogger lokibot maldoc malicious msil nanocore netwire neutrino neverquest njrat papras poisonivy pony predator qakbot ransomware rat smokeloader stealer trojan troldesh ursnif vawtrak wanacrypt0r wannacry wcry zbot zeus

Sample information

Filenames
d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll, stage2.bin
File type
application/x-dosexec
Size
77824 bytes
MD5
e8ae3940c30296d494e534e0379f15d6
SHA-1
3bcb5e7bc9c317c3c067f36d7684a419da79506c
SHA-256
d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167
First indexed
2021-10-01 05:15:04
Last updated
2025-04-25 14:07:18

Antivirus detections

EngineDetection
MicroWorld-eScanGen:Variant.Zusy.402255
ALYacGen:Variant.Zusy.402255
SangforTrojan.Win32.Squirelwaffle.gen
K7AntiVirusTrojan-Downloader ( 005825f01 )
BitDefenderGen:Variant.Zusy.402255
K7GWTrojan-Downloader ( 005825f01 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Zusy.D6234F
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FWT
KasperskyHEUR:Trojan-Downloader.Win32.Squirelwaffle.gen
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Zusy.402255
EmsisoftGen:Variant.Zusy.402255 (B)
DrWebTrojan.DownLoader43.22421
McAfee-GW-EditionGenericRXQD-HS!E8AE3940C302
FireEyeGeneric.mg.e8ae3940c30296d4
IkarusWin32.Outbreak
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.402255
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.SquirrelWaffle.C4656724
McAfeeGenericRXQD-HS!E8AE3940C302
MAXmalware (ai score=81)
MalwarebytesTrojan.Downloader
TencentWin32.Trojan-downloader.Squirelwaffle.Amck
FortinetW32/Agent.FWT!tr.dldr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A

Network contacts

192.169.167.85

DNS requests

antoniocastroycia.com.co primahills-online.com

Process list

NameCommand line
<Ignored Process>
regsvr32.exe/s "C:\d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll"
rundll32.exe"C:\d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll",#2