845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46

Classification: Malicious

845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46 is a malicious file sample. Linked to Remcos malware. Detected by 35 antivirus engines.

Detection summary

  • 35 antivirus detections
  • 0 IDS alerts
  • 11 processes observed
  • 1 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: REMCOS (S0332)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-06-20 13:30:07 2026-09-02 21:45:08 malicious-activity
Remcos ThreatFox Abuse.ch 2024-06-20 15:44:56 2024-06-22 15:30:46 S0332 Remcos

Tags

windows-server-utility win.remcos remcosrat remvio socmer infostealer

Sample information

Filenames
845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46, 845c3. Backdoor.exe, Challan copy.pdf.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
560640 bytes
MD5
086ad86cc1560ecd86555678342047fb
SHA-1
0d17bc82703565596221e818b1fb35fa1eea1c99
SHA-256
845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46
First indexed
2024-06-20 13:02:04
Last updated
2026-09-02 21:45:08

Antivirus detections

EngineDetection
APEXMalicious
AVGFileRepMalware [Trj]
AhnLab-V3Malware/Win.Generic.R357253
AvastFileRepMalware [Trj]
AviraTR/Kryptik.kbioe
BitDefenderThetaGen:NN.ZemsilF.36806.Im0@aqZrSYi
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebTrojan.PackedNET.2926
ESET-NOD32a variant of MSIL/Kryptik.ALUK
Elasticmalicious (high confidence)
F-SecureTrojan.TR/Kryptik.kbioe
FireEyeGeneric.mg.086ad86cc1560ecd
FortinetMSIL/Kryptik.ALUK!tr
GoogleDetected
IkarusWin32.Outbreak
KasperskyHEUR:Trojan.MSIL.Taskun.gen
Kingsoftmalware.kb.c.1000
MalwarebytesTrojan.MalPack.VRS.Generic
MaxSecureWin.MxResIcn.Heur.Gen
McAfeeDReal Protect-LS!086AD86CC156
MicrosoftTrojan:Win32/Leonem
Paloaltogeneric.ml
RisingMalware.Obfus/[email protected] (RDM.MSIL2:p7Yi/s+LnOJ+C8vKvew2LA)
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SophosML/PE-A
SymantecML.Attribute.HighConfidence
Trapminemalicious.high.ml.score
TrendMicro-HouseCallTROJ_GEN.F0D1C00FK24
VaristW32/MSIL_Kryptik.KTU.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A
ZoneAlarmUDS:DangerousObject.Multi.Generic

Network contacts

62.102.148.166

Process list

NameCommand line
845c3.Backdoor.exe
powershell.exeAdd-MpPreference -ExclusionPath "C:\845c3.Backdoor.exe"
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\jBAjnj.exe"
schtasks.exe/Create /TN "Updates\jBAjnj" /XML "%TEMP%\tmp2899.tmp"
845c3.Backdoor.exe
Challancopy.pdf.exe
powershell.exeAdd-MpPreference -ExclusionPath "C:\Challancopy.pdf.exe"
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\jBAjnj.exe"
schtasks.exe/Create /TN "Updates\jBAjnj" /XML "%TEMP%\tmpD326.tmp"
Challancopy.pdf.exe
Challancopy.pdf.exe