e54a6551dd6e290cbe53d9ceda9e6d2bf36c1010ee939f3192c97de6b5a2650c.exe
Classification: Malicious
e54a6551dd6e290cbe53d9ceda9e6d2bf36c1010ee939f3192c97de6b5a2650c.exe is a malicious file sample. Linked to Sandworm Team, Earth Lusca activity.
Detection summary
- 68 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034) EARTH LUSCA (G1006)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:14 | malicious-activity | G0034 Sandworm Team |
| Earth Lusca | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:11 | malicious-activity | G1006 Earth Lusca |
| Spyware | VM-Ray | 2022-11-29 19:22:16 | 2022-11-29 19:22:16 |
Tags
aptSample information
- Filenames
- e54a6551dd6e290cbe53d9ceda9e6d2bf36c1010ee939f3192c97de6b5a2650c.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- SHA-256
e54a6551dd6e290cbe53d9ceda9e6d2bf36c1010ee939f3192c97de6b5a2650c- First indexed
- 2022-11-29 18:54:26
- Last updated
- 2025-02-14 02:13:11
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Strab.tsdR |
| Elastic | malicious (high confidence) |
| Cynet | Malicious (score: 100) |
| ALYac | Trojan.PSW.Stealer |
| Cylance | Unsafe |
| Zillya | Trojan.Strab.Win32.538 |
| Sangfor | Spyware.Win32.Strab.Vbj3 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | TrojanSpy:Win32/Strab.cf2ea41a |
| K7GW | Trojan ( 0059aca31 ) |
| K7AntiVirus | Trojan ( 0059aca31 ) |
| VirIT | Trojan.Win32.PSWStealer.DDX |
| Cyren | W32/ABRisk.AINI-7684 |
| Symantec | Trojan Horse |
| ESET-NOD32 | a variant of WinGo/Spy.Agent.AI |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | HEUR:Trojan.Win32.Tasker.pef |
| BitDefender | Gen:Variant.Babar.112610 |
| NANO-Antivirus | Trojan.Win32.Strab.jtphgk |
| ViRobot | Trojan.Win32.S.InfoStealer.1869944 |
| MicroWorld-eScan | Gen:Variant.Babar.112610 |
| Avast | Win32:PWSX-gen [Trj] |
| Tencent | Win32.Trojan.Strab.Rsmw |
| Emsisoft | Gen:Variant.Babar.112610 (B) |
| DrWeb | Trojan.PWS.Steam.34233 |
| VIPRE | Gen:Variant.Babar.112610 |
| TrendMicro | TROJ_FRS.0NA103AQ23 |
| McAfee-GW-Edition | BehavesLike.Win32.TrojanVeil.th |
| FireEye | Generic.mg.1dbe3fd4743f6242 |
| Sophos | Troj/Steal-DHD |
| Ikarus | Trojan-Spy.TitanStealer |
| Webroot | W32.Trojan.Gen |
| Avira | TR/Crypt.XPACK.Gen |
| Antiy-AVL | Trojan[Spy]/Win32.Agent |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Microsoft | Trojan:Win32/TitanStealer.PA!MTB |
| Xcitium | Malware@#e2vwl4wx75k9 |
| Arcabit | Trojan.Babar.D1B7E2 |
| ZoneAlarm | HEUR:Trojan.Win32.Tasker.pef |
| GData | Gen:Variant.Babar.112610 |
| Detected | |
| AhnLab-V3 | Infostealer/Win.Titan.R555644 |
| McAfee | Artemis!1DBE3FD4743F |
| MAX | malware (ai score=100) |
| VBA32 | TrojanPSW.Titan |
| TrendMicro-HouseCall | TROJ_FRS.0NA103AQ23 |
| Rising | [email protected] (RDML:XPJieMAovEn1LB7+L3u6SA) |
| SentinelOne | Static AI - Suspicious PE |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | W32/PossibleThreat |
| BitDefenderTheta | AI:Packer.D0CE38A521 |
| AVG | Win32:PWSX-gen [Trj] |
| Cybereason | malicious.4743f6 |
| Panda | Trj/Chgt.AD |
| Bkav | W32.AIDetectMalware |
| ClamAV | Win.Packed.Babar-9993886-0 |
| Cylance | unsafe |
| DeepInstinct | MALICIOUS |
| F-Secure | Trojan.TR/Crypt.XPACK.Gen |
| Kingsoft | Win32.Trojan.Tasker.pef |
| Malwarebytes | Generic.Malware.AI.DDS |
| McAfee | GenericRXAA-AA!1DBE3FD4743F |
| Rising | [email protected] (RDML:XPJieMAovEn1LB7+L3u6SA) |
| Sangfor | Spyware.Win32.Agent.V4wq |
| Skyhigh | BehavesLike.Win32.Trojan.th |
| Varist | W32/ABRisk.AINI-7684 |
| alibabacloud | Trojan |