VT-F6C21F8189CED6AE150F9EF2E82A3A57843B587D
high
📛 Threat Title
VirusTotal: F6C21F8189CED6AE150F9EF2E82A3A57843B587D
Description
VirusTotal verdict: 46 malicious / 0 suspicious of 75 engines. Suggested label: trojan.industroyer/idtroyer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha1
f6c21f8189ced6ae150f9ef2e82a3a57843b587d
VT 46 / 75
IOC database
- Type
- hash_sha1
- Value
f6c21f8189ced6ae150f9ef2e82a3a57843b587d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Submitted to VirusTotal for analysis.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 46 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.Industroyer.R202368 |
| Alibaba | malicious | Trojan:Win32/Industroyer.b83d7d5c |
| alibabacloud | malicious | Trojan:Win/Industroyer.A |
| Antiy-AVL | malicious | Trojan[APT]/Win32.Industroyer |
| APEX | malicious | Malicious |
| Avira | malicious | HEUR/AGEN.1317429 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Industroyer.8 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Variant.Industroyer.2 (B) |
| ESET-NOD32 | malicious | Win32/Industroyer.A trojan |
| F-Secure | malicious | Heuristic.HEUR/AGEN.1317429 |
| Fortinet | malicious | W32/Industroyer.A!tr |
| GData | malicious | Win32.Backdoor.Industroyer.E |
| malicious | Detected |
|
| huorong | malicious | Trojan/Generic!7D37F29011C652CF |
| Ikarus | malicious | Trojan.Win32.Industroyer |
| Jiangmin | malicious | Trojan.Industroyer.f |
| K7AntiVirus | malicious | Trojan ( 00652b0f1 ) |
| K7GW | malicious | Trojan ( 00652b0f1 ) |
| Kingsoft | malicious | Win32.Trojan.Industroyer.g |
| Lionic | malicious | Trojan.Win32.Industroyer.4!c |
| Malwarebytes | malicious | Malware.AI.3185837447 |
| McAfeeD | malicious | ti!37D54E3D5E8B |
| Microsoft | malicious | Trojan:Win32/CrashOverride.A!dha |
| MicroWorld-eScan | malicious | Gen:Variant.Industroyer.2 |
| NANO-Antivirus | malicious | Trojan.Win32.Industroyer.epyhrs |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Sophos | malicious | Troj/Idtroyer-A |
| Symantec | malicious | Backdoor.Industroyer |
| TACHYON | malicious | Trojan/W32.Industroyer.10752 |
| tehtris | malicious | Generic.Malware |
| Tencent | malicious | Malware.Win32.Gencirc.115d7d23 |
| Trapmine | malicious | malicious.high.ml.score |
| TrendMicro-HouseCall | malicious | BKDR_INDUSTROYER.A |
| Varist | malicious | W32/Industroyer.A.gen!Eldorado |
| VirIT | malicious | Trojan.Win32.Industroyer.I |
| ViRobot | malicious | Trojan.Win32.Industroyer.10752.A |
| Webroot | malicious | W32.Trojan.Gen |
| Zillya | malicious | Trojan.Industroyer.Win32.7 |
| ZoneAlarm | malicious | Troj/Idtroyer-A |
Details From VirusTotal
Basic Properties
| MD5 | f67b65b9346ee75a26f491b70bf6091b |
| SHA-1 | f6c21f8189ced6ae150f9ef2e82a3a57843b587d |
| SHA-256 | 37d54e3d5e8b838f366b9c202f75fa264611a12444e62ae759c31a0d041aa6e4 |
| VHash | 014056551d055550d8z27hz2020102fz |
| SSDEEP | 192:7YmE5zgvM3cGfjnhDVYPp6GSDyBESi3eiKxWvJCDpFnTZ0k:7YVgk3VjnFVRJp39GWJCDpFTZ |
| TLSH | T125224B922C208573D7E740B70216B836EB7FAB256175BD43E648978209E5BC1F70E74B |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 10.5 KB |
History
| First seen on VirusTotal | 2016-12-20 09:21 UTC |
| Last submission | 2026-05-06 08:32 UTC |
| Last analysis | 2026-05-12 06:34 UTC |
| Last modified on VirusTotal | 2026-05-12 08:41 UTC |
Known Names
2max4.exeF67B65B9346EE75A26F491B70BF6091Bf67b65b9346ee75a26f491b70bf6091bIndustroyer.exef6c21f8189ced6ae150f9ef2e82a3a57843b587df67b65b9346ee75a26f491b70bf6091b.exetrojan.industroyer-bkdr.exeindustroyer_CM-1.exed.exe產.binvirus.exe37d54e3d5e8b838f366b9c202f75fa264611a12444e62ae759c31a0d041aa6e4industroyer2VirusShare_f67b65b9346ee75a26f491b70bf6091bmyfile.exef67b65b9346ee75a26f491b70bf6091b_pWCjYpOe.eXEf67b65b9346ee75a26f491b70bf6091b.virf6c21f8189ced6ae150f9ef2e82a3a57843b587d_avtask.exavtask.exe37.exepepe.exe
References (1)
-
VirusTotal report
VirusTotal verdict: 46 malicious / 0 suspicious of 75 engines. Suggested label: trojan.industroyer/idtroyer.
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:chamindux.medium.com
The vote in the VirusTotal vote section indicates that a user believes the file, URL, or IP address is malicious or harmful. This helps the community by signaling potential threats and contributing to the collective understanding of the item's safety.
-
web:cloud.google.com
VirusTotal Enterprise (VTE) allows a threat analyst to access the entire VirusTotal collection of nearly 2 billion files spanning back to 2006, making them easily searchable via more than 40 search modifiers. Download VTE for Threat Investigations to discover how to leverage the full power of VirusTotal .
-
web:documentation.wazuh.com
Detecting and removing malware using VirusTotal integration Permalink to this headline Wazuh uses the integrator module to connect to external APIs and alerting tools such as VirusTotal . In this use case, you use the Wazuh File Integrity Monitoring (FIM) module to monitor a directory for changes and the VirusTotal API to scan the files in the directory. Then, configure Wazuh to trigger an ...
-
web:en.wikipedia.org
VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. [1][2][3] The company's ownership switched in January 2018 to Google Security Operations, a subsidiary of Google.
-
web:github.com
Domain Threat Assessment: Analyzing Malicious Activity with VirusTotal A hands-on threat assessment using VirusTotal to uncover phishing, malware, and suspicious behavior across three domains.
-
web:www.cisa.gov
VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a variety of tools, to extract signals from the studied content.
-
web:www.iconnectitbs.com
April 2026 cybersecurity vulnerabilities roundup covering critical CVEs, zero-day exploits, active threats, and mitigation steps for enterprise security teams.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.org
Loading... ... Loading...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.