VT-938ea0d64bd83bd4e70a1eaa32620846
high
📛 Threat Title
VirusTotal: 938ea0d64bd83bd4e70a1eaa32620846
Description
VirusTotal verdict: 50 malicious / 0 suspicious of 73 engines.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_md5
938ea0d64bd83bd4e70a1eaa32620846
VT 50 / 73
IOC database
- Type
- hash_md5
- Value
938ea0d64bd83bd4e70a1eaa32620846- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Recovered from a VirusTotal threat record.
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 73 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Ad-Aware | malicious | Trojan.GenericKD.43109573 |
| Alibaba | malicious | Trojan:Win32/Starter.ali2000005 |
| ALYac | malicious | Trojan.GenericKD.43109573 |
| Antiy-AVL | malicious | Trojan/Win32.AGeneric |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D291CCC5 |
| Avast | malicious | Win32:DropperX-gen [Drp] |
| AVG | malicious | Win32:DropperX-gen [Drp] |
| Avira | malicious | HEUR/AGEN.1122385 |
| BitDefender | malicious | Trojan.GenericKD.43109573 |
| BitDefenderTheta | malicious | Gen:NN.ZemsilF.34254.am0@a8lBVfe |
| CAT-QuickHeal | malicious | TrojanDownloader.Lorozoad.A3 |
| ClamAV | malicious | Win.Trojan.Lorozoad-1 |
| Comodo | malicious | TrojWare.MSIL.TrojanDownloader.Tiny.MXA@6ezw8o |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 85) |
| Cyren | malicious | W32/MSIL_Lorozoad.A.gen!Eldorado |
| DrWeb | malicious | Trojan.DownLoader23.11404 |
| eGambit | malicious | Unsafe.AI_Score_94% |
| Emsisoft | malicious | Trojan.GenericKD.43109573 (B) |
| ESET-NOD32 | malicious | a variant of MSIL/TrojanDownloader.Tiny.MX |
| F-Secure | malicious | Heuristic.HEUR/AGEN.1122385 |
| FireEye | malicious | Generic.mg.938ea0d64bd83bd4 |
| Fortinet | malicious | MSIL/Tiny.MX!tr.dldr |
| GData | malicious | Trojan.GenericKD.43109573 |
| Ikarus | malicious | Trojan-Downloader.MSIL.Tiny |
| Invincea | malicious | Mal/Generic-S |
| Jiangmin | malicious | Trojan.Generic.alrwt |
| K7AntiVirus | malicious | Trojan ( 0053f1e91 ) |
| K7GW | malicious | Trojan ( 0053f1e91 ) |
| Kaspersky | malicious | HEUR:Worm.MSIL.AutoRun.gen |
| Lionic | malicious | Trojan.Win32.Generic.4!c |
| MAX | malicious | malware (ai score=100) |
| McAfee | malicious | Artemis!938EA0D64BD8 |
| McAfee-GW-Edition | malicious | Artemis!Trojan |
| Microsoft | malicious | TrojanDownloader:MSIL/Lorozoad.A |
| MicroWorld-eScan | malicious | Trojan.GenericKD.43109573 |
| NANO-Antivirus | malicious | Trojan.Win32.Tiny.ebrklr |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Qihoo-360 | malicious | Win32/Trojan.170 |
| Sangfor | malicious | Malware |
| SentinelOne | malicious | DFI - Malicious PE |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Win32.Trojan.Generic.Hssk |
| VIPRE | malicious | Trojan.Win32.Generic!BT |
| Yandex | malicious | Trojan.Agent!2o7PFLHQduE |
| Zillya | malicious | Downloader.Tiny.Win32.15435 |
| ZoneAlarm | malicious | HEUR:Worm.MSIL.AutoRun.gen |
Details From VirusTotal
Basic Properties
| MD5 | 938ea0d64bd83bd4e70a1eaa32620846 |
| SHA-1 | 5c0cd0be6e32bf38136d48478fcdb99c4eed2a35 |
| SHA-256 | 03a3ea9a13078f83fa080e0cd67ff5d7dd2b0d4333ddc67f9a51e0cba7242014 |
| VHash | 243036551518003310010 |
| SSDEEP | 48:6gfWQRXxmbIj6yKvBZ0PcFjCPgZZK2HcvoV+TVh+neya9am5eHKuuli+hAq:6QRhmlxpWaCPgZZK2HxVMh+3aIBHUEk |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly |
| File size | 4.5 KB |
History
| Creation date | 2016-11-07 10:17 UTC |
| First seen on VirusTotal | 2016-11-08 18:39 UTC |
| Last submission | 2016-12-08 06:40 UTC |
| Last analysis | 2020-09-30 18:27 UTC |
| Last modified on VirusTotal | 2022-07-01 02:41 UTC |
Known Names
111111.exeoutput.104213763.txtsample.exemis.exeoutput.104213762.txt208edf48e1615de677fd4167aecff6dc2d867168Zyq1ZVhbMalware (80).exe
References (1)
-
VirusTotal report
VirusTotal verdict: 50 malicious / 0 suspicious of 73 engines.
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:blog.virustotal.com
The VirusTotal dataset, the backbone of the platform, structures artifact-related information into objects and represents relevant relationships between them, providing contextual links between various artifacts. This makes VirusTotal a valuable resource for threat research, enabling users to perform activities such as clustering artifacts related to specific threat actors or campaigns ...
-
web:docs.virustotal.com
How it works VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a myriad of tools to extract signals from the studied content. Any user can select a file from their computer using their browser and send it to VirusTotal .
-
web:docs.virustotal.com
Here are the key elements of VirusTotal reports. We'll look at a typical URL report first, then a typical report for files. The last two sections will focus on domain and IP address reports. URL Report Summary URL Report Details File Report Summary File Report Details Domain and IP address reports U…
-
web:docs.virustotal.com
Searching for IP address information VirusTotal runs its own passive DNS replication service, built by storing the DNS resolutions performed as we visit URLs and execute malware samples submitted by users. To retrieve the information we have on a given IP address, just type it into the search box.
-
web:gtidocs.virustotal.com
How to perform file searches Google Threat Intelligence allows you to search through our dataset in order to identify files that match certain criteria (hash, antivirus detections, metadata, submission file names, file format structural properties, file size, etc.). We could say that it is pretty m…
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.com
VirusTotal is a free online tool for scanning files and URLs for viruses and malware using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a platform offering malware detection, cyber threat intelligence, and data sharing for enhanced digital security.
-
web:www.virustotal.com
VirusTotal is a free online service for scanning files and URLs for viruses, malware, and other malicious content using multiple antivirus solutions.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.