7dca5662fe7621ffd890ac202dd50e9d22b8f2ca186490ad62d8813cc0727cdb
Classification: Malicious
7dca5662fe7621ffd890ac202dd50e9d22b8f2ca186490ad62d8813cc0727cdb is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 48 antivirus detections (69% detection ratio)
- 4 IDS alerts
- 2 processes observed
- 5 contacted hosts
- 5 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2024-01-08 18:15:04 | 2026-09-02 11:45:03 | malicious-activity | |
| SnakeKeylogger | MalwareBazaar Abuse.ch | 2024-01-08 16:36:05 | 2024-01-08 16:36:05 | malicious-activity |
Sample information
- Filenames
- 7dca5662fe7621ffd890ac202dd50e9d22b8f2ca186490ad62d8813cc0727cdb, 7dca5.Trojan.exe, Vessel details.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 1150464 bytes
- MD5
dedf47709ccc73cc599b1be48d34b70f- SHA-1
6dd596495fc521e9d690f0e3d2c79c08e4a439c2- SHA-256
7dca5662fe7621ffd890ac202dd50e9d22b8f2ca186490ad62d8813cc0727cdb- First indexed
- 2024-01-08 18:03:12
- Last updated
- 2026-09-02 11:45:03
Antivirus detections
| Engine | Detection |
|---|---|
| APEX | Malicious |
| AVG | Win32:TrojanX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.C5564571 |
| Alibaba | Trojan:MSIL/Kryptik.3b1eecdf |
| Antiy-AVL | Trojan/MSIL.Kryptik |
| Arcabit | Trojan.Generic.D43D500F |
| Avast | Win32:TrojanX-gen [Trj] |
| Avira | TR/AD.SnakeStealer.axzbq |
| BitDefender | Trojan.GenericKD.71127055 |
| Bkav | W32.AIDetectMalware.CS |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of MSIL/Kryptik.AKKQ |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.GenericKD.71127055 (B) |
| F-Secure | Trojan.TR/AD.SnakeStealer.axzbq |
| Fortinet | MSIL/GenKryptik.GPIK!tr |
| GData | Win32.Trojan.Agent.RAZ0SQ |
| Detected | |
| Gridinsoft | Trojan.Win32.Kryptik.sa |
| Ikarus | Trojan.MSIL.Inject |
| K7AntiVirus | Trojan ( 005ae1ad1 ) |
| K7GW | Trojan ( 005ae1ad1 ) |
| Kaspersky | HEUR:Trojan.Win32.Generic |
| Lionic | Trojan.Win32.Generic.4!c |
| MAX | malware (ai score=85) |
| Malwarebytes | Trojan.Crypt.MSIL.Generic |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfee | Artemis!DEDF47709CCC |
| MicroWorld-eScan | Trojan.GenericKD.71127055 |
| Microsoft | Trojan:Win32/Leonem |
| Panda | Trj/Chgt.AD |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:tv/hckvdeSV9qwXIpR+r1g) |
| Sangfor | Trojan.Win32.Kryptik.V211 |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.th |
| Sophos | Troj/Krypt-ADF |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.Generic.Aujl |
| TrendMicro-HouseCall | TROJ_GEN.F0D1C00A724 |
| VIPRE | Trojan.GenericKD.71127055 |
| Varist | W32/MSIL_Agent.GXH.gen!Eldorado |
| ViRobot | Trojan.Win.Z.Kryptik.1150464 |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| ZoneAlarm | HEUR:Trojan.Win32.Generic |
| tehtris | Generic.Malware |
Network contacts
132.226.247.73 172.67.177.134 158.101.44.242 104.21.67.152 51.38.247.67
DNS requests
checkip.dyndns.org reallyfreegeoip.org aborters.duckdns.org anotherarmy.dns.army varders.kozow.com
Process list
| Name | Command line |
|---|---|
| 7dca5.Trojan.exe | |
| RegAsm.exe | |