s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

VT-F6C21F8189CED6AE150F9EF2E82A3A57843B587D high

📛 Threat Title

VirusTotal: F6C21F8189CED6AE150F9EF2E82A3A57843B587D

Category: ioc First seen: Last updated:

Description

VirusTotal verdict: 46 malicious / 0 suspicious of 75 engines. Suggested label: trojan.industroyer/idtroyer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha1 f6c21f8189ced6ae150f9ef2e82a3a57843b587d VT 46 / 75

IOC database

Type
hash_sha1
Value
f6c21f8189ced6ae150f9ef2e82a3a57843b587d
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Submitted to VirusTotal for analysis.

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 46 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.Industroyer.R202368
Alibaba malicious Trojan:Win32/Industroyer.b83d7d5c
alibabacloud malicious Trojan:Win/Industroyer.A
Antiy-AVL malicious Trojan[APT]/Win32.Industroyer
APEX malicious Malicious
Avira malicious HEUR/AGEN.1317429
CrowdStrike malicious win/malicious_confidence_100% (W)
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Industroyer.8
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.Industroyer.2 (B)
ESET-NOD32 malicious Win32/Industroyer.A trojan
F-Secure malicious Heuristic.HEUR/AGEN.1317429
Fortinet malicious W32/Industroyer.A!tr
GData malicious Win32.Backdoor.Industroyer.E
Google malicious Detected
huorong malicious Trojan/Generic!7D37F29011C652CF
Ikarus malicious Trojan.Win32.Industroyer
Jiangmin malicious Trojan.Industroyer.f
K7AntiVirus malicious Trojan ( 00652b0f1 )
K7GW malicious Trojan ( 00652b0f1 )
Kingsoft malicious Win32.Trojan.Industroyer.g
Lionic malicious Trojan.Win32.Industroyer.4!c
Malwarebytes malicious Malware.AI.3185837447
McAfeeD malicious ti!37D54E3D5E8B
Microsoft malicious Trojan:Win32/CrashOverride.A!dha
MicroWorld-eScan malicious Gen:Variant.Industroyer.2
NANO-Antivirus malicious Trojan.Win32.Industroyer.epyhrs
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
SentinelOne malicious Static AI - Suspicious PE
Sophos malicious Troj/Idtroyer-A
Symantec malicious Backdoor.Industroyer
TACHYON malicious Trojan/W32.Industroyer.10752
tehtris malicious Generic.Malware
Tencent malicious Malware.Win32.Gencirc.115d7d23
Trapmine malicious malicious.high.ml.score
TrendMicro-HouseCall malicious BKDR_INDUSTROYER.A
Varist malicious W32/Industroyer.A.gen!Eldorado
VirIT malicious Trojan.Win32.Industroyer.I
ViRobot malicious Trojan.Win32.Industroyer.10752.A
Webroot malicious W32.Trojan.Gen
Zillya malicious Trojan.Industroyer.Win32.7
ZoneAlarm malicious Troj/Idtroyer-A

Details From VirusTotal

Basic Properties
MD5f67b65b9346ee75a26f491b70bf6091b
SHA-1f6c21f8189ced6ae150f9ef2e82a3a57843b587d
SHA-25637d54e3d5e8b838f366b9c202f75fa264611a12444e62ae759c31a0d041aa6e4
VHash014056551d055550d8z27hz2020102fz
SSDEEP192:7YmE5zgvM3cGfjnhDVYPp6GSDyBESi3eiKxWvJCDpFnTZ0k:7YVgk3VjnFVRJp39GWJCDpFTZ
TLSHT125224B922C208573D7E740B70216B836EB7FAB256175BD43E648978209E5BC1F70E74B
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size10.5 KB
History
First seen on VirusTotal2016-12-20 09:21 UTC
Last submission2026-05-06 08:32 UTC
Last analysis2026-05-12 06:34 UTC
Last modified on VirusTotal2026-05-12 08:41 UTC
Known Names
  • 2max4.exe
  • F67B65B9346EE75A26F491B70BF6091B
  • f67b65b9346ee75a26f491b70bf6091b
  • Industroyer.exe
  • f6c21f8189ced6ae150f9ef2e82a3a57843b587d
  • f67b65b9346ee75a26f491b70bf6091b.exe
  • trojan.industroyer-bkdr.exe
  • industroyer_CM-1.exe
  • d.exe
  • 產.bin
  • virus.exe
  • 37d54e3d5e8b838f366b9c202f75fa264611a12444e62ae759c31a0d041aa6e4
  • industroyer2
  • VirusShare_f67b65b9346ee75a26f491b70bf6091b
  • myfile.exe
  • f67b65b9346ee75a26f491b70bf6091b_pWCjYpOe.eXE
  • f67b65b9346ee75a26f491b70bf6091b.vir
  • f6c21f8189ced6ae150f9ef2e82a3a57843b587d_avtask.ex
  • avtask.exe
  • 37.exe
  • pepe.exe

References (1)

  • VirusTotal report

    VirusTotal verdict: 46 malicious / 0 suspicious of 75 engines. Suggested label: trojan.industroyer/idtroyer.

Remediations (10)

  • web:blackswan-cybersecurity.com

    Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.

  • web:chamindux.medium.com

    The vote in the VirusTotal vote section indicates that a user believes the file, URL, or IP address is malicious or harmful. This helps the community by signaling potential threats and contributing to the collective understanding of the item's safety.

  • web:cloud.google.com

    VirusTotal Enterprise (VTE) allows a threat analyst to access the entire VirusTotal collection of nearly 2 billion files spanning back to 2006, making them easily searchable via more than 40 search modifiers. Download VTE for Threat Investigations to discover how to leverage the full power of VirusTotal .

  • web:documentation.wazuh.com

    Detecting and removing malware using VirusTotal integration Permalink to this headline Wazuh uses the integrator module to connect to external APIs and alerting tools such as VirusTotal . In this use case, you use the Wazuh File Integrity Monitoring (FIM) module to monitor a directory for changes and the VirusTotal API to scan the files in the directory. Then, configure Wazuh to trigger an ...

  • web:en.wikipedia.org

    VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. [1][2][3] The company's ownership switched in January 2018 to Google Security Operations, a subsidiary of Google.

  • web:github.com

    Domain Threat Assessment: Analyzing Malicious Activity with VirusTotal A hands-on threat assessment using VirusTotal to uncover phishing, malware, and suspicious behavior across three domains.

  • web:www.cisa.gov

    VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a variety of tools, to extract signals from the studied content.

  • web:www.iconnectitbs.com

    April 2026 cybersecurity vulnerabilities roundup covering critical CVEs, zero-day exploits, active threats, and mitigation steps for enterprise security teams.

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

  • web:www.virustotal.org

    Loading... ... Loading...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.