Dark.exe
Classification: Malicious
Dark.exe is a malicious file sample. Linked to Sandworm Team, Earth Lusca activity. Reported by 2 threat sources, last seen 2023-03-03.
Detection summary
- 30 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: SANDWORM TEAM (G0034) EARTH LUSCA (G1006)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Electrum | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:15 | malicious-activity | G0034 Sandworm Team |
| Earth Lusca | Maltiverse | 2023-03-02 04:15:22 | 2023-03-03 14:34:12 | malicious-activity | G1006 Earth Lusca |
| Injector | VM-Ray | 2022-11-14 00:23:36 | 2022-11-14 00:23:36 |
Tags
aptSample information
- Filenames
- Dark.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- SHA-256
eb8faad12b1bc7657060878a8b672344c95a0a6cdedeedf7b2702c7add6a815d- First indexed
- 2022-11-13 23:46:09
- Last updated
- 2023-03-03 14:34:15
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetect.malware2 |
| MicroWorld-eScan | Trojan.GenericKDZ.93532 |
| Cylance | Unsafe |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 004f58c41 ) |
| K7GW | Trojan ( 004f58c41 ) |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Symantec | ML.Attribute.HighConfidence |
| Elastic | malicious (high confidence) |
| APEX | Malicious |
| Kaspersky | VHO:Backdoor.Win32.Convagent.gen |
| Avast | PWSX-gen [Trj] |
| Emsisoft | Trojan.GenericKDZ.93532 (B) |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.tc |
| Trapmine | malicious.moderate.ml.score |
| FireEye | Generic.mg.5e79869f7f8ba836 |
| Sophos | Generic ML PUA (PUA) |
| SentinelOne | Static AI - Suspicious PE |
| GData | Trojan.GenericKDZ.93532 |
| Detected | |
| MAX | malware (ai score=87) |
| Microsoft | Trojan:Win32/Sabsik.FL.B!ml |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Generic.C5142678 |
| Acronis | suspicious |
| Rising | Backdoor.Pandora!8.7729 (TFE:5:tgPCJW39YPB) |
| Ikarus | Trojan.Win32.Crypt |
| BitDefenderTheta | Gen:NN.ZexaF.34784.2rW@aO@RRFn |
| AVG | PWSX-gen [Trj] |
| Cybereason | malicious.ede50e |