e1fe8a17884f43cedca54c76ed3e371b64c312c9e00c865b2c6a9266cd1f596c
Classification: Malicious
e1fe8a17884f43cedca54c76ed3e371b64c312c9e00c865b2c6a9266cd1f596c is a malicious file sample. Linked to Backdoordiplomacy activity.
Detection summary
- 47 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BACKDOORDIPLOMACY (G0135)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Backdoordiplomacy | Maltiverse | 2023-01-20 04:17:13 | 2023-01-21 18:45:43 | malicious-activity | G0135 BackdoorDiplomacy |
Tags
aptSample information
- SHA-256
e1fe8a17884f43cedca54c76ed3e371b64c312c9e00c865b2c6a9266cd1f596c- First indexed
- 2023-01-21 18:45:43
- Last updated
- 2023-01-21 18:45:43
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.APosT.4!c |
| MicroWorld-eScan | Gen:Variant.Jaik.94341 |
| FireEye | Generic.mg.912772598521aa24 |
| ALYac | Gen:Variant.Jaik.94341 |
| Cylance | Unsafe |
| Zillya | Trojan.APosT.Win32.2023 |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| Alibaba | Trojan:Win32/APosT.fe75c61f |
| K7GW | Riskware ( 0040eff71 ) |
| Cybereason | malicious.2db2d1 |
| Arcabit | Trojan.Jaik.D17085 |
| Cyren | W32/Trojan.VFAF-9204 |
| Symantec | Trojan.Gen.MBT |
| Elastic | malicious (high confidence) |
| APEX | Malicious |
| Cynet | Malicious (score: 99) |
| Kaspersky | Trojan.Win32.APosT.ocp |
| BitDefender | Gen:Variant.Jaik.94341 |
| NANO-Antivirus | Virus.Win32.Gen.ccmw |
| Avast | Win32:Malware-gen |
| Tencent | Win32.Trojan.FalseSign.Nsmw |
| Sophos | Mal/Generic-R + Mal/Swrort-D |
| F-Secure | Trojan.TR/Agent.lsxfo |
| DrWeb | BackDoor.Siggen2.3609 |
| VIPRE | Gen:Variant.Jaik.94341 |
| TrendMicro | TROJ_GEN.R002C0RL822 |
| McAfee-GW-Edition | Generic trojan.qh |
| Trapmine | malicious.high.ml.score |
| Emsisoft | Gen:Variant.Jaik.94341 (B) |
| Jiangmin | Trojan.Agentb.mzl |
| Webroot | W32.Trojan.Casdet |
| Avira | TR/Agent.lsxfo |
| Antiy-AVL | Trojan/Win32.Swrort |
| Microsoft | Trojan:Win32/Casdet!rfn |
| ZoneAlarm | Trojan.Win32.APosT.ocp |
| GData | Gen:Variant.Jaik.94341 |
| Detected | |
| McAfee | Generic .qh |
| MAX | malware (ai score=100) |
| VBA32 | Heur.Trojan.Hlux |
| TrendMicro-HouseCall | TROJ_GEN.R002C0RL822 |
| Rising | Backdoor.AukRat!8.1740C (TFE:4:XQ8cqZ60qV) |
| MaxSecure | Trojan.Malware.194614115.susgen |
| Fortinet | W32/Swrort.D |
| AVG | Win32:Malware-gen |
| Panda | Trj/CI.A |