84dd2a034d3c9d53d216198cb05f2d5fc65ad7dac487915196eda622a997bb05

Classification: Malicious

84dd2a034d3c9d53d216198cb05f2d5fc65ad7dac487915196eda622a997bb05 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 74 antivirus detections (47% detection ratio)
  • 2 IDS alerts
  • 2 processes observed
  • 2 contacted hosts
  • 2 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-10-30 13:45:04 2026-09-02 22:45:08 malicious-activity

Tags

rat

Sample information

Filenames
84dd2a034d3c9d53d216198cb05f2d5fc65ad7dac487915196eda622a997bb05, INVOICE.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
376320 bytes
MD5
d414eca1e374dac20dff6822d0793f84
SHA-1
5f16530c1115f0422d152abc96974d04695a66f8
SHA-256
84dd2a034d3c9d53d216198cb05f2d5fc65ad7dac487915196eda622a997bb05
First indexed
2023-10-30 13:30:39
Last updated
2026-09-02 22:45:08

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKDZ.103827
MalwarebytesPony.Spyware.Stealer.DDS
VIPRETrojan.GenericKDZ.103827
BitDefenderTrojan.GenericKDZ.103827
Cybereasonmalicious.c1115f
BitDefenderThetaGen:NN.ZemsilF.36792.wm0@auquogd
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.GPIK
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
RisingMalware.Obfus/[email protected] (RDM.MSIL2:qoqWPk/76Mm8NzJqnyr45g)
SophosML/PE-A
DrWebTrojan.KeyloggerNET.54
FireEyeGeneric.mg.d414eca1e374dac2
EmsisoftTrojan.GenericKDZ.103827 (B)
VaristW32/MSIL_Kryptik.KAG.gen!Eldorado
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D19593
ZoneAlarmHEUR:Backdoor.MSIL.Remcos.gen
GDataTrojan.GenericKDZ.103827
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5531969
ALYacTrojan.GenericKDZ.103827
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
TrendMicro-HouseCallTROJ_GEN.F0D1C00JU23
SentinelOneStatic AI - Malicious PE
FortinetMSIL/GenKryptik.GPIK!tr
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)
ALYacIL:Trojan.MSILZilla.87214
AlibabaBackdoor:MSIL/SnakeKeylogger.0a9ad673
ArcabitIL:Trojan.MSILZilla.D154AE
AviraHEUR/AGEN.1371293
BitDefenderIL:Trojan.MSILZilla.87214
BitDefenderThetaGen:NN.ZemsilF.36802.wm0@auquogd
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.GenericFC.S32037935
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.1e374d
Cylanceunsafe
ESET-NOD32a variant of MSIL/GenKryptik.GPUX
EmsisoftIL:Trojan.MSILZilla.87214 (B)
F-SecureHeuristic.HEUR/AGEN.1371293
GDataIL:Trojan.MSILZilla.87214
IkarusTrojan.MSIL.Agent
JiangminBackdoor.MSIL.ggwo
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
KingsoftMSIL.Backdoor.Remcos.gen
LionicTrojan.Win32.Remcos.m!c
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.73696032.susgen
McAfeeGenericRXWL-GB!D414ECA1E374
MicroWorld-eScanIL:Trojan.MSILZilla.87214
MicrosoftTrojan:MSIL/SnakeKeylogger.SPQM!MTB
NANO-AntivirusTrojan.Win32.Remcos.kcxygi
PandaTrj/Chgt.AD
SangforBackdoor.Msil.Kryptik.Vb6e
SkyhighBehavesLike.Win32.Generic.fc
SophosMal/Generic-S
TencentMalware.Win32.Gencirc.13f3d175
TrendMicroBackdoor.MSIL.REMCOS.USPAXJU23
TrendMicro-HouseCallBackdoor.MSIL.REMCOS.USPAXJU23
VBA32TScope.Trojan.MSIL
VIPREIL:Trojan.MSILZilla.87214
XcitiumMalware@#3o2t8uqu02s09
YandexTrojan.Igent.b07ENZ.7
ZillyaTrojan.GenKryptik.Win32.328743
alibabacloudBackdoor:MSIL/Remcos.gen

Network contacts

158.101.44.242 101.0.117.102

DNS requests

checkip.dyndns.org mail.comxdesign.com

Process list

NameCommand line
INVOICE.exe
INVOICE.exe