ecd2137d877e8dc118703e966d54f389
Classification: Malicious
ecd2137d877e8dc118703e966d54f389 is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-12-17.
Detection summary
- 44 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | MalwareBazaar Abuse.ch | 2021-12-17 22:35:25 | 2021-12-17 22:35:25 | malicious-activity | S0382 ServHelper |
| Generic.Malware | MalwareBazaar Abuse.ch | 2021-12-17 22:35:25 | 2021-12-17 22:35:25 | malicious-activity |
Sample information
- Filenames
- ecd2137d877e8dc118703e966d54f389
- File type
- application/x-dosexec
- MD5
ecd2137d877e8dc118703e966d54f389- SHA-1
dd7197b70c0fb2e6d2ebeb604f63c74ad0ac8a03- SHA-256
efa22ab0015899c95aa6582cc90314de8d4cf2f52d3267eba50482b75d060ac5- First indexed
- 2021-12-18 00:15:06
- Last updated
- 2026-04-08 13:11:48
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Cobalt.trRF |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Trojan.GenericKD.38204953 |
| FireEye | Trojan.GenericKD.38204953 |
| CAT-QuickHeal | TrojanDropper.MSIL |
| ALYac | Trojan.GenericKD.38204953 |
| Cylance | Unsafe |
| Sangfor | Riskware.Win32.Agent.ky |
| K7AntiVirus | Trojan ( 00580cbe1 ) |
| Alibaba | TrojanDropper:Win64/GoCLR.9a0a3f69 |
| K7GW | Trojan ( 00580cbe1 ) |
| Symantec | Trojan.Gen.MBT |
| ESET-NOD32 | a variant of WinGo/GoCLR.B |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | Trojan-Dropper.MSIL.Agent.seskra |
| BitDefender | Trojan.GenericKD.38204953 |
| Avast | FileRepMalware |
| Tencent | Win32.Trojan.Goclr.Aosw |
| Ad-Aware | Trojan.GenericKD.38204953 |
| Sophos | Mal/Generic-S |
| DrWeb | Trojan.Packed.18626 |
| TrendMicro | TROJ_GEN.R002C0DL921 |
| McAfee-GW-Edition | BehavesLike.Win64.Generic.rh |
| Emsisoft | Trojan.GenericKD.38204953 (B) |
| SentinelOne | Static AI - Suspicious PE |
| GData | Script.Malware.Sapybisma.NUKNOT |
| Webroot | W32.Trojan.GenKD |
| Avira | HEUR/AGEN.1201987 |
| ViRobot | Trojan.Win32.Z.Goclr.4802560.A |
| Microsoft | Trojan:Win64/GoCLR!MSR |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Generic.R458300 |
| McAfee | Artemis!ECD2137D877E |
| MAX | malware (ai score=80) |
| VBA32 | TrojanDropper.MSIL.Agent |
| Malwarebytes | Trojan.Agent.GO |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DL921 |
| Rising | HackTool.GoCLR!1.D71D (CLASSIC) |
| Ikarus | Trojan.WinGo.Goclr |
| Fortinet | W64/GoCLR.B!tr |
| AVG | FileRepMalware |
| Panda | Trj/CI.A |
| CrowdStrike | win/malicious_confidence_60% (W) |