53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce
Classification: Malicious
53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce is a malicious file sample. Linked to Empire malware. Detected by 41 antivirus engines.
Detection summary
- 41 antivirus detections
- 1 IDS alerts
- 1 processes observed
- 1 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Empire |
Triage |
2026-05-21 06:48:24 |
2026-05-21 06:48:24 |
malicious-activity
|
S0363 Empire
|
| PowerShellRunner |
ThreatFox Abuse.ch |
2024-03-26 07:14:18 |
2024-03-28 06:23:29 |
|
|
| Generic Malware |
Hybrid-Analysis |
2024-03-26 01:15:04 |
2024-03-26 02:45:11 |
|
|
Tags
evasive
win.powershellrunner
empire
downloader
Sample information
- Filenames
- 53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce, 53b55.Hack.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 56832 bytes
- MD5
85458e5e0809da89721cf8f78907adba
- SHA-1
ae817d295f0aa7a91c4dc059561c3c629f908a96
- SHA-256
53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce
- First indexed
- 2024-03-26 00:59:11
- Last updated
- 2026-07-11 07:38:32
Antivirus detections
| Engine | Detection |
| ALYac | Generic.Trojan.Empire.A.406A974F |
| AVG | Win32:Sharpire-A [Hack] |
| AhnLab-V3 | Trojan/Win.RealProtect-LS.C5168497 |
| Arcabit | Generic.Trojan.Empire.A.406A974F |
| Avast | Win32:Sharpire-A [Hack] |
| Avira | HEUR/AGEN.1371741 |
| BitDefender | Generic.Trojan.Empire.A.406A974F |
| BitDefenderTheta | Gen:NN.ZemsilF.36802.diW@augeni |
| Bkav | W32.AIDetectMalware.CS |
| ClamAV | Win.Packed.Empire-10010538-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cybereason | malicious.e0809d |
| Cylance | unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.GruntNET.1 |
| ESET-NOD32 | a variant of MSIL/Agent.DLY |
| Elastic | malicious (high confidence) |
| Emsisoft | Generic.Trojan.Empire.A.406A974F (B) |
| F-Secure | Heuristic.HEUR/AGEN.1371741 |
| FireEye | Generic.mg.85458e5e0809da89 |
| Fortinet | MSIL/Agent.DLY!tr |
| GData | Generic.Trojan.Empire.A.406A974F |
| Ikarus | Trojan.MSIL.Agent |
| Kaspersky | HEUR:Trojan.MSIL.Empire.b |
| Kingsoft | malware.kb.c.963 |
| Lionic | Trojan.Win32.PowershellEmpire.4!c |
| MAX | malware (ai score=82) |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | Artemis!85458E5E0809 |
| MicroWorld-eScan | Generic.Trojan.Empire.A.406A974F |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.qm |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Msil.Trojan.Empire.Twhl |
| Trapmine | suspicious.low.ml.score |
| VIPRE | Generic.Trojan.Empire.A.406A974F |
| Varist | W32/MSIL_Agent.FJE.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Zillya | Trojan.Injector.Win32.414974 |
| ZoneAlarm | HEUR:Trojan.MSIL.Empire.b |
Process list
| Name | Command line |
| 53b55.Hack.exe | |