d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll
Classification: Malicious
d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll is a malicious file sample. Linked to Squirrelwaffle malware.
Detection summary
- 30 antivirus detections
- 0 IDS alerts
- 3 processes observed
- 1 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-01-11 08:15:04 |
2025-01-11 10:00:09 |
|
|
| Squirrelwaffle |
Abuse.ch |
2021-10-01 04:26:03 |
2021-10-01 04:26:03 |
malicious-activity
|
S1030 Squirrelwaffle
|
Tags
adwind
agenttesla
alienspy
banker
bladabindi
chanitor
chthonic
cridex
crimson
darkcomet
dofoil
dridex
dyre
dyreza
emotet
fareit
gootkit
gozi
hancitor
hawkeye
infostealer
isfb
keylogger
lokibot
maldoc
malicious
msil
nanocore
netwire
neutrino
neverquest
njrat
papras
poisonivy
pony
predator
qakbot
ransomware
rat
smokeloader
stealer
trojan
troldesh
ursnif
vawtrak
wanacrypt0r
wannacry
wcry
zbot
zeus
Sample information
- Filenames
- d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll, stage2.bin
- File type
- application/x-dosexec
- Size
- 77824 bytes
- MD5
e8ae3940c30296d494e534e0379f15d6
- SHA-1
3bcb5e7bc9c317c3c067f36d7684a419da79506c
- SHA-256
d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167
- First indexed
- 2021-10-01 05:15:04
- Last updated
- 2025-04-25 14:07:18
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Gen:Variant.Zusy.402255 |
| ALYac | Gen:Variant.Zusy.402255 |
| Sangfor | Trojan.Win32.Squirelwaffle.gen |
| K7AntiVirus | Trojan-Downloader ( 005825f01 ) |
| BitDefender | Gen:Variant.Zusy.402255 |
| K7GW | Trojan-Downloader ( 005825f01 ) |
| CrowdStrike | win/malicious_confidence_70% (W) |
| Arcabit | Trojan.Zusy.D6234F |
| Symantec | Trojan.Gen.MBT |
| ESET-NOD32 | a variant of Win32/TrojanDownloader.Agent.FWT |
| Kaspersky | HEUR:Trojan-Downloader.Win32.Squirelwaffle.gen |
| Avast | Win32:DropperX-gen [Drp] |
| Ad-Aware | Gen:Variant.Zusy.402255 |
| Emsisoft | Gen:Variant.Zusy.402255 (B) |
| DrWeb | Trojan.DownLoader43.22421 |
| McAfee-GW-Edition | GenericRXQD-HS!E8AE3940C302 |
| FireEye | Generic.mg.e8ae3940c30296d4 |
| Ikarus | Win32.Outbreak |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| GData | Gen:Variant.Zusy.402255 |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Downloader/Win.SquirrelWaffle.C4656724 |
| McAfee | GenericRXQD-HS!E8AE3940C302 |
| MAX | malware (ai score=81) |
| Malwarebytes | Trojan.Downloader |
| Tencent | Win32.Trojan-downloader.Squirelwaffle.Amck |
| Fortinet | W32/Agent.FWT!tr.dldr |
| AVG | Win32:DropperX-gen [Drp] |
| Panda | Trj/GdSda.A |
Process list
| Name | Command line |
| <Ignored Process> | |
| regsvr32.exe | /s "C:\d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll" |
| rundll32.exe | "C:\d6caf64597bd5e0803f7d0034e73195e83dae370450a2e890b82f77856830167.dll",#2 |