Classification: Malicious
bounty-26274900544419549 is a malicious file sample. Linked to Earth Lusca activity. Reported by 2 threat sources, last seen 2023-08-20.
Detection summary
- 61 antivirus detections (60% detection ratio)
- 0 IDS alerts
- 4 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Earth Lusca |
Maltiverse |
2023-08-19 05:11:12 |
2023-08-20 21:20:30 |
malicious-activity
|
G1006 Earth Lusca
|
| Generic Malware |
Hybrid-Analysis |
2023-07-28 02:45:03 |
2023-07-28 02:45:03 |
|
|
Sample information
- Filenames
- bounty-26274900544419549
- File type
- PE32+ executable (DLL) (GUI) x86-64, for MS Windows
- Size
- 246784 bytes
- MD5
5ce55d096480e6a072e1f57cef776e80
- SHA-1
622e7ff96bafdc701c01cf6d3336829734a13d94
- SHA-256
d6f184dae03d4ddae8e839dd2161d9cd03d3b25421b4795edab0f5ad9850d091
- First indexed
- 2023-07-28 02:35:13
- Last updated
- 2025-10-24 01:12:04
Antivirus detections
| Engine | Detection |
| Bkav | W32.Common.92BA761C |
| Lionic | Trojan.Win32.Dllhijacker.4!c |
| MicroWorld-eScan | Gen:Variant.Tedy.299289 |
| FireEye | Gen:Variant.Tedy.299289 |
| ALYac | Gen:Variant.Tedy.299289 |
| Cylance | unsafe |
| VIPRE | Gen:Variant.Tedy.299289 |
| Sangfor | Trojan.Win64.Dllhijacker.Vif4 |
| Alibaba | Trojan:Win64/Dllhijacker.14c89528 |
| K7GW | Trojan ( 005a15031 ) |
| K7AntiVirus | Trojan ( 005a15031 ) |
| Symantec | Meterpreter |
| ESET-NOD32 | Win64/Agent.CEY |
| Cynet | Malicious (score: 99) |
| Kaspersky | Trojan.Win64.Dllhijacker.ahj |
| BitDefender | Gen:Variant.Tedy.299289 |
| NANO-Antivirus | Trojan.Win64.Redcap.jvhknw |
| Avast | Win64:TrojanX-gen [Trj] |
| Tencent | Malware.Win32.Gencirc.13b3a016 |
| Emsisoft | Gen:Variant.Tedy.299289 (B) |
| F-Secure | Trojan.TR/Redcap.jlpyz |
| DrWeb | BackDoor.ShadowPad.45 |
| Zillya | Trojan.Dllhijacker.Win64.13 |
| TrendMicro | Backdoor.Win64.SHADOWPAD.AS |
| McAfee-GW-Edition | RDN/Generic.dx |
| Sophos | Mal/Generic-S |
| GData | Gen:Variant.Tedy.299289 |
| Avira | TR/Redcap.jlpyz |
| Antiy-AVL | Trojan/Win64.Dllhijacker |
| Arcabit | Trojan.Tedy.D49119 |
| ZoneAlarm | Trojan.Win64.Dllhijacker.ahj |
| Microsoft | Trojan:Win32/Bitrep.B |
| McAfee | RDN/Generic.dx |
| MAX | malware (ai score=84) |
| Malwarebytes | Neshta.Virus.FileInfector.DDS |
| Panda | Trj/Chgt.AD |
| TrendMicro-HouseCall | Backdoor.Win64.SHADOWPAD.AS |
| Rising | Trojan.Dllhijacker!8.ABDA (CLOUD) |
| MaxSecure | Trojan.Malware.124430950.susgen |
| Fortinet | W32/PossibleThreat |
| AVG | Win64:TrojanX-gen [Trj] |
| DeepInstinct | MALICIOUS |
| ALYac | Backdoor.Agent.ShadowPad |
| AhnLab-V3 | Trojan/Win.Generic.C5458128 |
| Alibaba | Trojan:Win64/Dllhijacker.354dd8f4 |
| CAT-QuickHeal | Trojan.Ghanarava.1692374728776e80 |
| CTX | dll.trojan.dllhijacker |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Elastic | malicious (high confidence) |
| Google | Detected |
| Ikarus | Trojan.Win64.Agent |
| Kingsoft | win32.troj.undef.a |
| McAfee | Artemis!5CE55D096480 |
| McAfeeD | ti!D6F184DAE03D |
| Microsoft | Trojan:Win32/Casdet!rfn |
| Sangfor | Trojan.Win64.Dllhijacker.Vet2 |
| Skyhigh | Artemis!Trojan |
| Varist | W64/Msil.MIM |
| ViRobot | Trojan.Win.S.Agent.246784 |
| alibabacloud | Trojan:Win/Dllhijacker.aqQ |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\bounty-26274900544419549.dll",#18 |
| rundll32.exe | "C:\bounty-26274900544419549.dll",#19 |
| rundll32.exe | "C:\bounty-26274900544419549.dll",#28 |