MB-6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443
high
📛 Threat Title
Unknown: SecuriteInfo.com.W64.Agent.MYZ.gen.Eldorado.28580.7668
Description
File type: exe. Size: 1251840 bytes. Tags: exe. Reporter: SecuriteInfoCom. First seen: 2026-09-25 09:29:51.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443
VT 15 / 75
IOC database
- Type
- hash_sha256
- Value
6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 15 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.C5922751 |
| Arcabit | malicious | Trojan.Generic.D4DC70FA |
| CTX | malicious | dll.trojan.generic |
| Emsisoft | malicious | Trojan.GenericKD.81555706 (B) |
| GData | malicious | Trojan.GenericKD.81555706 |
| malicious | Detected |
|
| MaxSecure | malicious | Trojan.Malware.8328611.susgen |
| McAfeeD | malicious | ti!6C06E2D9918C |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81555706 |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Generic!8.C3 (CLOUD) |
| Tencent | malicious | Trojan.Win32.Loader.16005304 |
| Varist | malicious | W64/Agent.MYZ.gen!Eldorado |
| VIPRE | malicious | Trojan.GenericKD.81555706 |
Details From VirusTotal
Basic Properties
| MD5 | d9d21b6d6de5d987166f5fa75a7924fc |
| SHA-1 | 3b722d1d56abe86faf763f986575b40824cefae4 |
| SHA-256 | 6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443 |
| VHash | 1160d76d156d05555c051az55?z1 |
| SSDEEP | 24576:RyOKZxkuusuUD7FWKJ3VsSUvbnSpF3OFQ8:RyOKZTVuIFv3VsPvbSpFoQ8 |
| TLSH | T134456C07E2A320ECC13BC274475BAB73B931B8145134BEBF9994DB312E61E50676EB25 |
| File type | Win32 DLL |
| File type tag | pedll |
| File extension | dll |
| Magic | PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows |
| File size | 1.2 MB |
History
| Creation date | 2026-09-16 11:41 UTC |
| First seen on VirusTotal | 2026-09-18 15:04 UTC |
| Last submission | 2026-09-25 10:48 UTC |
| Last analysis | 2026-09-25 21:36 UTC |
| Last modified on VirusTotal | 2026-09-26 00:07 UTC |
Known Names
SuperWrapper.dll6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443.exexoz4r92cx.exedcdvl9b9.exed9d21b6d6de5d987166f5fa75a7924fc
hash_sha1
3b722d1d56abe86faf763f986575b40824cefae4
VT 15 / 75
IOC database
- Type
- hash_sha1
- Value
3b722d1d56abe86faf763f986575b40824cefae4- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 15 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.C5922751 |
| Arcabit | malicious | Trojan.Generic.D4DC70FA |
| CTX | malicious | dll.trojan.generic |
| Emsisoft | malicious | Trojan.GenericKD.81555706 (B) |
| GData | malicious | Trojan.GenericKD.81555706 |
| malicious | Detected |
|
| MaxSecure | malicious | Trojan.Malware.8328611.susgen |
| McAfeeD | malicious | ti!6C06E2D9918C |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.GenericKD.81555706 |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Generic!8.C3 (CLOUD) |
| Tencent | malicious | Trojan.Win32.Loader.16005304 |
| Varist | malicious | W64/Agent.MYZ.gen!Eldorado |
| VIPRE | malicious | Trojan.GenericKD.81555706 |
Details From VirusTotal
Basic Properties
| MD5 | d9d21b6d6de5d987166f5fa75a7924fc |
| SHA-1 | 3b722d1d56abe86faf763f986575b40824cefae4 |
| SHA-256 | 6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443 |
| VHash | 1160d76d156d05555c051az55?z1 |
| SSDEEP | 24576:RyOKZxkuusuUD7FWKJ3VsSUvbnSpF3OFQ8:RyOKZTVuIFv3VsPvbSpFoQ8 |
| TLSH | T134456C07E2A320ECC13BC274475BAB73B931B8145134BEBF9994DB312E61E50676EB25 |
| File type | Win32 DLL |
| File type tag | pedll |
| File extension | dll |
| Magic | PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows |
| File size | 1.2 MB |
History
| Creation date | 2026-09-16 11:41 UTC |
| First seen on VirusTotal | 2026-09-18 15:04 UTC |
| Last submission | 2026-09-25 10:48 UTC |
| Last analysis | 2026-09-25 21:36 UTC |
| Last modified on VirusTotal | 2026-09-26 00:07 UTC |
Known Names
SuperWrapper.dll6c06e2d9918c672531dc36981ba3f0eaaaf6d93ab5846bb0035df9b0366f5443.exexoz4r92cx.exedcdvl9b9.exed9d21b6d6de5d987166f5fa75a7924fc
hash_md5
d9d21b6d6de5d987166f5fa75a7924fc
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/d9d21b6d6de5d987166f5fa75a7924fc
IOC database
- Type
- hash_md5
- Value
d9d21b6d6de5d987166f5fa75a7924fc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/d9d21b6d6de5d987166f5fa75a7924fc
hash_imphash
b5e84c13fad4746d56bfe40f133a0087
IOC database
- Type
- hash_imphash
- Value
b5e84c13fad4746d56bfe40f133a0087- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 1251840 bytes. Tags: exe. Reporter: SecuriteInfoCom. First seen: 2026-09-25 09:29:51.
Remediations (10)
-
web:any.run
Online sandbox report for SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156, tagged as telegram, vidar, stealer, verdict: Malicious activity
-
web:any.run
Online sandbox report for SecuriteInfo.com.W64.Agent.IKW.gen.Eldorado.19678.19551, tagged as goinjector, lumma, stealer, verdict: Malicious activity
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:hackread.com
"The Eldorado group has managed to develop and deploy a highly effective ransomware builder, which has been used to target both Windows and Linux systems," researchers wrote in a blog post. For your information, this group runs a RaaS business providing affiliates with the tools and support needed to carry out ransomware attacks.
-
web:ransomwarewire.com
ElDorado is a Rust-based ransomware-as-a-service operation that emerged in March 2024 with cross-platform capabilities targeting both Windows and VMware ESXi environments. Active through 2026, the group has claimed victims across finance, healthcare, real estate, and manufacturing.
-
web:www.joesandbox.com
SecuriteInfo.com.W64.Agent.IKW.gen.Eldorado.16971.8931.exe (PID: 6824 cmdline: "C:\Users\ user\Deskt op\Securit eInfo.com. W64.Agent. IKW.gen.El dorado.169 71.8931.ex ...
-
web:www.joesandbox.com
AV Detection Machine Learning detection for sample Source: SecuriteInfo.com.W64.Agent.IIK.gen.Eldorado.5946.15516.dll Joe Sandbox ML: detected
-
web:www.pcrisk.com
MSIL:Agent trojan disguised as an adult video dating app: MSIL:Agent trojan process in Windows Task Manager: Instant automatic malware removal: Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware.
-
web:www.pcrisk.com
What kind of malware is El Dorado? El Dorado (Eldorado) is ransomware derived from another ransomware known as LostTrust. It encrypts files, appends the ".00000001 " extension to filenames, and creates a ransom note (" HOW_RETURN_YOUR_DATA.TXT "). An example of how El Dorado changes filenames: it renames " 1.jpg" to " 1.jpg.00000001 ", " 2.png " to " 2.png.00000001 ", and so forth. Screenshot ...
-
web:www.reddit.com
true Assuming it's not a generic launcher, which would explain the date discrepancy, the creation time being earlier than the release date isn't surprising, and being seen in the wild just means an AV supported by VirusTotal was installed on the dev's system and scanned the file.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.