2026-02-20_3bfa8b4c8bfe544888c80eb60b8d2900_coinminer_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
Classification: Malicious
2026-02-20_3bfa8b4c8bfe544888c80eb60b8d2900_coinminer_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee is a malicious file sample.
Detection summary
- 61 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Snojan |
Triage |
2026-02-20 04:25:27 |
2026-02-20 04:25:27 |
malicious-activity
|
|
Tags
snojan
discovery
downloader
upx
Sample information
- Filenames
- 2026-02-20_3bfa8b4c8bfe544888c80eb60b8d2900_coinminer_elex_rhadamanthys_smoke-loader_stealc_stop_tofsee
- MD5
3bfa8b4c8bfe544888c80eb60b8d2900
- SHA-1
31a9bc56de4180568c1c2525efc63dea827d60ca
- SHA-256
fd1c197b3a91590f2631b77ca6f9f5562fc2080a4ebf0aca852d1847092a1d0d
- SHA-512
c4a7a8529d5f4a2326746e3df0f091ab243ea61c84621659ca00ce04034a8531ecd6e7ebcdd6e0ab4ac1521d32e5b4506d4d21f836a5620903171e51aadc43d0
- First indexed
- 2026-02-20 04:25:27
- Last updated
- 2026-09-03 00:32:04
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Agent.CYZT |
| APEX | Malicious |
| AVG | Win32:Banker-LAA [Trj] |
| AhnLab-V3 | Downloader/Win.Generic.R665906 |
| Antiy-AVL | HackTool[Flooder]/Win32.CoreWarrior |
| Arcabit | Trojan.Agent.CYZT |
| Avast | Win32:Banker-LAA [Trj] |
| Avira | TR/Crypt.ULPM.Gen2 |
| BitDefender | Trojan.Agent.CYZT |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.AgentbPMF.S33725804 |
| CTX | exe.trojan.corewarrior |
| ClamAV | Win.Malware.Cymt-10023133-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Tool.Snojan.1 |
| ESET-NOD32 | Win32/Agent.AAEF trojan |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Trojan.Agent.CYZT (B) |
| F-Secure | Trojan.TR/Crypt.ULPM.Gen2 |
| Fortinet | Riskware/Snojan |
| GData | Win32.Application.Snojan.A |
| Google | Detected |
| Ikarus | Trojan.Agent |
| Jiangmin | Downloader.Snojan.adp |
| K7AntiVirus | Trojan ( 005c835f1 ) |
| K7GW | Trojan ( 005464da1 ) |
| Kaspersky | UDS:Flooder.Win32.CoreWarrior.a |
| Lionic | Hacktool.Win32.CoreWarrior.3!c |
| Malwarebytes | Generic.Malware/Suspicious |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | Real Protect-LS!3BFA8B4C8BFE |
| MicroWorld-eScan | Trojan.Agent.CYZT |
| Microsoft | Trojan:Win32/CoreWarrior.DA!MTB |
| NANO-Antivirus | Trojan.Win32.Snojan.jqzopm |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Trojan.Agent!1.B576 (CLOUD) |
| Sangfor | Suspicious.Win32.Save.pkr |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.NetLoader.dc |
| Sophos | Troj/Bdoor-BHD |
| Symantec | Hacktool.Flooder |
| Tencent | Trojan.Win32.Corewarrior.ca |
| Trapmine | suspicious.low.ml.score |
| TrellixENS | Artemis!3BFA8B4C8BFE |
| TrendMicro | TROJ_GEN.R002C0DBJ26 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DBJ26 |
| VBA32 | Flooder.CoreWarrior |
| VIPRE | Trojan.Agent.CYZT |
| Varist | W32/Agent.FBOO-5422 |
| VirIT | Trojan.Win32.AgentT.DYK |
| Webroot | Win.Trojan.Gen |
| Xcitium | TrojWare.Win32.Snojan.B@7h1cjp |
| Yandex | Riskware.Flooder!j7BYbbJGLUM |
| Zillya | Tool.CoreWarrior.Win32.18 |
| ZoneAlarm | Troj/Bdoor-BHD |
| alibabacloud | DDoS:Win/Nemucod |
| huorong | HVM:TrojanDownloader/Small.gen!A |