VT-c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224
medium
📛 Threat Title
File hash (SHA256): c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224
Description
Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
abuse.ch
VT 0 / 91
UrlVoid 1 / 35
IOC database
- Type
- domain
- Value
abuse.ch- First seen
- Last seen
- Attached to this threat
- Appears in
- 4019 threats
- Description
- Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | ch |
History
| Last analysis | 2026-05-24 09:28 UTC |
| Last modified on VirusTotal | 2026-05-24 16:38 UTC |
| WHOIS record date | 2026-03-29 11:09 UTC |
hash_sha256
c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224
VT 60 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Amadey
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 60 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.C5809069 |
| Alibaba | malicious | TrojanPSW:Win64/MalwareX.3e6a9c27 |
| alibabacloud | malicious | RiskWare:Win/Qwexlafiba.Gen |
| ALYac | malicious | Gen:Variant.Zusy.477261 |
| Antiy-AVL | malicious | Trojan/Win64.Amadey |
| Arcabit | malicious | Trojan.Zusy.D7484D |
| Avast | malicious | Win64:Agent-HU [Pws] |
| AVG | malicious | Win64:Agent-HU [Pws] |
| Avira | malicious | TR/W64.Agent.HU |
| BitDefender | malicious | Gen:Variant.Zusy.477261 |
| Bkav | malicious | W32.Malware.ADBBD003 |
| CAT-QuickHeal | malicious | Trojan.Amadey |
| ClamAV | malicious | Win.Keylogger.Zusy-10017136-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | dll.trojan.stealer |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PWS.Amadey.833 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Variant.Zusy.477261 (B) |
| ESET-NOD32 | malicious | Win64/PSW.Agent.CW trojan |
| F-Secure | malicious | Trojan.TR/W64.Agent.HU |
| Fortinet | malicious | W64/Agent.CW!tr |
| GData | malicious | Gen:Variant.Zusy.477261 |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.oa!s1 |
| huorong | malicious | TrojanSpy/Stealer.ij |
| Ikarus | malicious | Trojan-PSW.Agent |
| K7AntiVirus | malicious | Password-Stealer ( 005cf6c91 ) |
| K7GW | malicious | Password-Stealer ( 005cf6c91 ) |
| Kaspersky | malicious | UDS:Trojan-Spy.Win32.Stealer |
| Kingsoft | malicious | Win32.Trojan-Spy.Stealer.a |
| Lionic | malicious | Trojan.Win32.Stealer.12!c |
| Malwarebytes | malicious | Malware.AI.3327139488 |
| McAfeeD | malicious | ti!C2C6A1E3C750 |
| Microsoft | malicious | Trojan:Win32/Qwexlafiba!rfn |
| MicroWorld-eScan | malicious | Gen:Variant.Zusy.477261 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/CI.A |
| Rising | malicious | Spyware.Stealer!8.3090 (TFE:5:79I7EMKuNSC) |
| Sangfor | malicious | Trojan.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | BehavesLike.Win64.Dropper.th |
| Sophos | malicious | Troj/Steal-DCI |
| SUPERAntiSpyware | malicious | Trojan.Agent/Gen-Kryptik |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Malware.Win32.Gencirc.10c43b9d |
| TrellixENS | malicious | Trojan-JBGP!870FECBAF57D |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLED26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLED26 |
| Varist | malicious | W64/ABTrojan.WODN-1852 |
| VBA32 | malicious | TrojanSpy.Stealer |
| VIPRE | malicious | Gen:Variant.Zusy.477261 |
| VirIT | malicious | Trojan.Win32.GenusT.EPRA |
| ViRobot | malicious | Trojan.Win.Z.Zusy.1282048.CL |
| Webroot | malicious | Win.Trojan.Gen |
| Yandex | malicious | TrojanSpy.Stealer!BPQEPzTMF0g |
| Zillya | malicious | Trojan.Stealer.Win32.197378 |
| ZoneAlarm | malicious | Troj/Steal-DCI |
Details From VirusTotal
Basic Properties
| MD5 | 870fecbaf57d7cd9e69d78b4123577ce |
| SHA-1 | 78258318ee41ade0351c7c3c0e8623768eafe291 |
| SHA-256 | c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224 |
| VHash | 116076655d1565151550d3z12z9bhz27zbaz2 |
| SSDEEP | 24576:frR0NaOy0mK9yCksn6JCc2YkxfUyamitsDw+mLRi/OnW:fkHmiyCkhh2Bamituw+UMt |
| TLSH | T1C2557C0BA26141BCD4BBE1789A175A47F775704603709AEB07E446A63F13FE1AEBE310 |
| File type | Win32 DLL |
| File type tag | pedll |
| File extension | dll |
| Magic | PE32+ executable (DLL) (GUI) x86-64, for MS Windows |
| File size | 1.2 MB |
History
| Creation date | 2026-05-09 05:36 UTC |
| First seen on VirusTotal | 2026-05-13 00:19 UTC |
| Last submission | 2026-05-14 04:39 UTC |
| Last analysis | 2026-05-20 06:03 UTC |
| Last modified on VirusTotal | 2026-05-20 21:25 UTC |
Known Names
cred64.dllwprqyhxw.exe
References (1)
-
VirusTotal report
Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).
Remediations (10)
-
web:cybercheck360.com
Calculate the MD5, SHA-1, SHA-256 , and SHA-512 hash of any file directly in your browser. No upload needed, hashes are computed locally.
-
web:eakondratiev.github.io
Validate your downloads quickly — check a file's integrity with a SHA‑256 checksum, or create hashes for any files using this fast, easy tool.
-
web:hashgenerator.co
Free online hash generator for text and files . Generate MD5 hashes, SHA256 hashes, SHA-512, SHA-3 and BLAKE2b checksums with HMAC support in your browser.
-
web:inventivehq.com
Free hash lookup tool. Search MD5, SHA-1, SHA-256 hashes in breach databases to identify compromised passwords, malware, and file integrity.
-
web:safesearchscan.com
Check a file's SHA-256 , MD5, or SHA-1 hash against malware databases. Verify file integrity and authenticity without uploading the file . Free hash lookup tool.
-
web:talosintelligence.com
Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256 .
-
web:tooljot.com
The File Hash Checker computes cryptographic hash values for any file directly in your browser. Drag and drop a file (or click to browse) and instantly see its MD5, SHA-1, SHA-256 , SHA-384, and SHA-512 hashes — all calculated locally using the Web Crypto API.
-
web:www.freecodeformat.com
Verify file integrity online. Calculate MD5, SHA1, SHA256 , SHA512, SHA3, RIPEMD-160, and CRC32 hashes for any file . Fast, secure, and supports multiple files .
-
web:www.getzenquery.com
Verify file integrity instantly with our free online File Hash Checker. Upload any file to compute MD5, SHA-1, SHA-256 , and SHA-512 hashes—then compare with original or expected checksums. Perfect for ensuring downloaded files are intact, validating software authenticity, or detecting corruption. All processing happens locally in your browser for privacy.
-
web:www.toolsley.com
Calculate the hash for any file online. Generate MD5, SHA1, SHA256 or CRC32 instantly in your browser using JavaScript. Make share-able links to validate files . No need to install anything, just drag & drop.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.