53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce

Classification: Malicious

53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce is a malicious file sample. Linked to Empire malware. Detected by 41 antivirus engines.

Detection summary

  • 41 antivirus detections
  • 1 IDS alerts
  • 1 processes observed
  • 1 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Malware families: EMPIRE (S0363)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Empire Triage 2026-05-21 06:48:24 2026-05-21 06:48:24 malicious-activity S0363 Empire
PowerShellRunner ThreatFox Abuse.ch 2024-03-26 07:14:18 2024-03-28 06:23:29
Generic Malware Hybrid-Analysis 2024-03-26 01:15:04 2024-03-26 02:45:11

Tags

evasive win.powershellrunner empire downloader

Sample information

Filenames
53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce, 53b55.Hack.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
56832 bytes
MD5
85458e5e0809da89721cf8f78907adba
SHA-1
ae817d295f0aa7a91c4dc059561c3c629f908a96
SHA-256
53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce
First indexed
2024-03-26 00:59:11
Last updated
2026-07-11 07:38:32

Antivirus detections

EngineDetection
ALYacGeneric.Trojan.Empire.A.406A974F
AVGWin32:Sharpire-A [Hack]
AhnLab-V3Trojan/Win.RealProtect-LS.C5168497
ArcabitGeneric.Trojan.Empire.A.406A974F
AvastWin32:Sharpire-A [Hack]
AviraHEUR/AGEN.1371741
BitDefenderGeneric.Trojan.Empire.A.406A974F
BitDefenderThetaGen:NN.ZemsilF.36802.diW@augeni
BkavW32.AIDetectMalware.CS
ClamAVWin.Packed.Empire-10010538-0
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.e0809d
Cylanceunsafe
DeepInstinctMALICIOUS
DrWebBackDoor.GruntNET.1
ESET-NOD32a variant of MSIL/Agent.DLY
Elasticmalicious (high confidence)
EmsisoftGeneric.Trojan.Empire.A.406A974F (B)
F-SecureHeuristic.HEUR/AGEN.1371741
FireEyeGeneric.mg.85458e5e0809da89
FortinetMSIL/Agent.DLY!tr
GDataGeneric.Trojan.Empire.A.406A974F
IkarusTrojan.MSIL.Agent
KasperskyHEUR:Trojan.MSIL.Empire.b
Kingsoftmalware.kb.c.963
LionicTrojan.Win32.PowershellEmpire.4!c
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.300983.susgen
McAfeeArtemis!85458E5E0809
MicroWorld-eScanGeneric.Trojan.Empire.A.406A974F
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.qm
SymantecML.Attribute.HighConfidence
TencentMsil.Trojan.Empire.Twhl
Trapminesuspicious.low.ml.score
VIPREGeneric.Trojan.Empire.A.406A974F
VaristW32/MSIL_Agent.FJE.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A
ZillyaTrojan.Injector.Win32.414974
ZoneAlarmHEUR:Trojan.MSIL.Empire.b

Network contacts

86.123.95.152

DNS requests

sabinflorin.ddns.net sabinflorin.ddns.net:4444

Process list

NameCommand line
53b55.Hack.exe