s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224 medium

📛 Threat Title

File hash (SHA256): c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224

Category: malware-hash Published: Source updated: First seen: Last updated:

Description

Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain abuse.ch VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
abuse.ch
First seen
Last seen
Attached to this threat
Appears in
4019 threats
Description
Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDch
History
Last analysis2026-05-24 09:28 UTC
Last modified on VirusTotal2026-05-24 16:38 UTC
WHOIS record date2026-03-29 11:09 UTC
hash_sha256 c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224 VT 60 / 75 1 feed

IOC database

Type
hash_sha256
Value
c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Amadey

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 60 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.C5809069
Alibaba malicious TrojanPSW:Win64/MalwareX.3e6a9c27
alibabacloud malicious RiskWare:Win/Qwexlafiba.Gen
ALYac malicious Gen:Variant.Zusy.477261
Antiy-AVL malicious Trojan/Win64.Amadey
Arcabit malicious Trojan.Zusy.D7484D
Avast malicious Win64:Agent-HU [Pws]
AVG malicious Win64:Agent-HU [Pws]
Avira malicious TR/W64.Agent.HU
BitDefender malicious Gen:Variant.Zusy.477261
Bkav malicious W32.Malware.ADBBD003
CAT-QuickHeal malicious Trojan.Amadey
ClamAV malicious Win.Keylogger.Zusy-10017136-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious dll.trojan.stealer
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Amadey.833
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.Zusy.477261 (B)
ESET-NOD32 malicious Win64/PSW.Agent.CW trojan
F-Secure malicious Trojan.TR/W64.Agent.HU
Fortinet malicious W64/Agent.CW!tr
GData malicious Gen:Variant.Zusy.477261
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Agent.oa!s1
huorong malicious TrojanSpy/Stealer.ij
Ikarus malicious Trojan-PSW.Agent
K7AntiVirus malicious Password-Stealer ( 005cf6c91 )
K7GW malicious Password-Stealer ( 005cf6c91 )
Kaspersky malicious UDS:Trojan-Spy.Win32.Stealer
Kingsoft malicious Win32.Trojan-Spy.Stealer.a
Lionic malicious Trojan.Win32.Stealer.12!c
Malwarebytes malicious Malware.AI.3327139488
McAfeeD malicious ti!C2C6A1E3C750
Microsoft malicious Trojan:Win32/Qwexlafiba!rfn
MicroWorld-eScan malicious Gen:Variant.Zusy.477261
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Spyware.Stealer!8.3090 (TFE:5:79I7EMKuNSC)
Sangfor malicious Trojan.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious BehavesLike.Win64.Dropper.th
Sophos malicious Troj/Steal-DCI
SUPERAntiSpyware malicious Trojan.Agent/Gen-Kryptik
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Malware.Win32.Gencirc.10c43b9d
TrellixENS malicious Trojan-JBGP!870FECBAF57D
TrendMicro malicious Trojan.Win32.ZYX.USBLED26
TrendMicro-HouseCall malicious Trojan.Win32.ZYX.USBLED26
Varist malicious W64/ABTrojan.WODN-1852
VBA32 malicious TrojanSpy.Stealer
VIPRE malicious Gen:Variant.Zusy.477261
VirIT malicious Trojan.Win32.GenusT.EPRA
ViRobot malicious Trojan.Win.Z.Zusy.1282048.CL
Webroot malicious Win.Trojan.Gen
Yandex malicious TrojanSpy.Stealer!BPQEPzTMF0g
Zillya malicious Trojan.Stealer.Win32.197378
ZoneAlarm malicious Troj/Steal-DCI

Details From VirusTotal

Basic Properties
MD5870fecbaf57d7cd9e69d78b4123577ce
SHA-178258318ee41ade0351c7c3c0e8623768eafe291
SHA-256c2c6a1e3c750956b61ceb6748a73802b4676ab726d52d980d615cb4aa47a8224
VHash116076655d1565151550d3z12z9bhz27zbaz2
SSDEEP24576:frR0NaOy0mK9yCksn6JCc2YkxfUyamitsDw+mLRi/OnW:fkHmiyCkhh2Bamituw+UMt
TLSHT1C2557C0BA26141BCD4BBE1789A175A47F775704603709AEB07E446A63F13FE1AEBE310
File typeWin32 DLL
File type tagpedll
File extensiondll
MagicPE32+ executable (DLL) (GUI) x86-64, for MS Windows
File size1.2 MB
History
Creation date2026-05-09 05:36 UTC
First seen on VirusTotal2026-05-13 00:19 UTC
Last submission2026-05-14 04:39 UTC
Last analysis2026-05-20 06:03 UTC
Last modified on VirusTotal2026-05-20 21:25 UTC
Known Names
  • cred64.dll
  • wprqyhxw.exe

References (1)

  • VirusTotal report

    Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.