845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46
Classification: Malicious
845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46 is a malicious file sample. Linked to Remcos malware. Detected by 35 antivirus engines.
Detection summary
- 35 antivirus detections
- 0 IDS alerts
- 11 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-06-20 13:30:07 |
2026-09-02 21:45:08 |
malicious-activity
|
|
| Remcos |
ThreatFox Abuse.ch |
2024-06-20 15:44:56 |
2024-06-22 15:30:46 |
|
S0332 Remcos
|
Tags
windows-server-utility
win.remcos
remcosrat
remvio
socmer
infostealer
Sample information
- Filenames
- 845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46, 845c3. Backdoor.exe, Challan copy.pdf.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 560640 bytes
- MD5
086ad86cc1560ecd86555678342047fb
- SHA-1
0d17bc82703565596221e818b1fb35fa1eea1c99
- SHA-256
845c3ba76768948ab3df490599f02d060cd464c6251e16e7847d53707254ee46
- First indexed
- 2024-06-20 13:02:04
- Last updated
- 2026-09-02 21:45:08
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| AVG | FileRepMalware [Trj] |
| AhnLab-V3 | Malware/Win.Generic.R357253 |
| Avast | FileRepMalware [Trj] |
| Avira | TR/Kryptik.kbioe |
| BitDefenderTheta | Gen:NN.ZemsilF.36806.Im0@aqZrSYi |
| Bkav | W32.AIDetectMalware.CS |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.PackedNET.2926 |
| ESET-NOD32 | a variant of MSIL/Kryptik.ALUK |
| Elastic | malicious (high confidence) |
| F-Secure | Trojan.TR/Kryptik.kbioe |
| FireEye | Generic.mg.086ad86cc1560ecd |
| Fortinet | MSIL/Kryptik.ALUK!tr |
| Google | Detected |
| Ikarus | Win32.Outbreak |
| Kaspersky | HEUR:Trojan.MSIL.Taskun.gen |
| Kingsoft | malware.kb.c.1000 |
| Malwarebytes | Trojan.MalPack.VRS.Generic |
| MaxSecure | Win.MxResIcn.Heur.Gen |
| McAfeeD | Real Protect-LS!086AD86CC156 |
| Microsoft | Trojan:Win32/Leonem |
| Paloalto | generic.ml |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:p7Yi/s+LnOJ+C8vKvew2LA) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Sophos | ML/PE-A |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | malicious.high.ml.score |
| TrendMicro-HouseCall | TROJ_GEN.F0D1C00FK24 |
| Varist | W32/MSIL_Kryptik.KTU.gen!Eldorado |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| ZoneAlarm | UDS:DangerousObject.Multi.Generic |
Process list
| Name | Command line |
| 845c3.Backdoor.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "C:\845c3.Backdoor.exe" |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\jBAjnj.exe" |
| schtasks.exe | /Create /TN "Updates\jBAjnj" /XML "%TEMP%\tmp2899.tmp" |
| 845c3.Backdoor.exe | |
| Challancopy.pdf.exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "C:\Challancopy.pdf.exe" |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\jBAjnj.exe" |
| schtasks.exe | /Create /TN "Updates\jBAjnj" /XML "%TEMP%\tmpD326.tmp" |
| Challancopy.pdf.exe | |
| Challancopy.pdf.exe | |