854d267aea33e8dc80021ac043b003ab7c6f99061e56e36572cba3548e6882c9
Classification: Malicious
854d267aea33e8dc80021ac043b003ab7c6f99061e56e36572cba3548e6882c9 is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02.
Detection summary
- 57 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 7 contacted hosts
- 8 DNS requests
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 22:45:04 | 2026-09-02 22:45:04 | malicious-activity | |
| DCRat | ThreatFox Abuse.ch | 2024-06-23 16:56:43 | 2024-06-25 16:22:02 | ||
| DCRat | MalwareBazaar Abuse.ch | 2024-06-23 04:52:55 | 2024-06-23 04:52:55 | malicious-activity |
Tags
win.dcrat darkcrystal rat evasive maliciousSample information
- Filenames
- 854d267aea33e8dc80021ac043b003ab7c6f99061e56e36572cba3548e6882c9, 289f27e7a02f8e76ebf39d2c0c3f09e4.bin
- File type
- application/x-dosexec
- MD5
289f27e7a02f8e76ebf39d2c0c3f09e4- SHA-1
fb404a7a85d5fb617436f73832e4716556756d6a- SHA-256
854d267aea33e8dc80021ac043b003ab7c6f99061e56e36572cba3548e6882c9- First indexed
- 2024-06-23 06:21:12
- Last updated
- 2026-09-02 22:45:04
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.MSIL.Basic.8.Gen |
| APEX | Malicious |
| AVG | Win32:PWSX-gen [Trj] |
| Alibaba | Worm:MSIL/Dinihou.f7362e31 |
| Antiy-AVL | Trojan/Win32.Kryptik |
| Arcabit | Trojan.Fragtor.D8E51D [many] |
| Avast | Win32:PWSX-gen [Trj] |
| Avira | TR/Crypt.Agent.sqeqh |
| Baidu | VBS.Trojan.Kryptik.kh |
| BitDefender | Gen:Variant.Fragtor.582941 |
| BitDefenderTheta | Gen:NN.ZexaF.36808.LuY@a0LXn0l |
| Bkav | W64.AIDetectMalware |
| ClamAV | Win.Packed.Bladabindi-10017056-0 |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Cybereason | malicious.7a02f8 |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.DarkCrystalNET.18 |
| ESET-NOD32 | multiple detections |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Fragtor.582941 (B) |
| F-Secure | Trojan.TR/Crypt.Agent.sqeqh |
| FireEye | Generic.mg.289f27e7a02f8e76 |
| Fortinet | W32/Kryptik.HXIV!tr |
| GData | MSIL.Trojan.PSE.1AV6B6O |
| Detected | |
| Gridinsoft | Trojan.Win64.DCRat.tr |
| Ikarus | Trojan-Spy.LummaStealer |
| Jiangmin | Worm.MSIL.vpw |
| Kaspersky | Worm.VBS.Dinihou.au |
| Kingsoft | Win32.Troj.Unknown.a |
| Lionic | Trojan.BAT.Starter.tsAs |
| MAX | malware (ai score=86) |
| Malwarebytes | Malware.AI.4221297215 |
| MaxSecure | Win.MxResIcn.Heur.Gen |
| McAfee | Artemis!289F27E7A02F |
| McAfeeD | ti!854D267AEA33 |
| MicroWorld-eScan | Gen:Variant.Fragtor.582941 |
| Microsoft | Backdoor:MSIL/DCRat!pz |
| NANO-Antivirus | Trojan.Script.Vbs-heuristic.druvzi |
| Paloalto | generic.ml |
| Rising | Backdoor.DCRat!1.E0D3 (CLASSIC) |
| Sangfor | Trojan.Vbs.Agent.Vi87 |
| SentinelOne | Static AI - Malicious SFX |
| Skyhigh | BehavesLike.Win64.Remcos.tc |
| Sophos | Mal/Generic-R |
| Symantec | Trojan.Gen.MBT |
| Tencent | Vbs.Worm.Dinihou.Jajl |
| TrendMicro | TrojanSpy.Win64.LUMMASTEALER.YXEFVZ |
| TrendMicro-HouseCall | TrojanSpy.Win64.LUMMASTEALER.YXEFVZ |
| VIPRE | Gen:Variant.Jaik.231799 |
| Varist | W32/ABRisk.MFJY-8268 |
| VirIT | Trojan.Win32.GenusT.DQCZ |
| Zillya | Exploit.UAC.Win32.999 |
| ZoneAlarm | HEUR:Trojan-Spy.Win32.Stealer.gen |
| alibabacloud | Backdoor:Win/Obfuscated.A |
Network contacts
150.171.109.74 3.250.92.156 44.244.22.128 52.27.79.221 50.16.27.236 52.16.171.153 44.192.95.127
DNS requests
bargainnygroandjwk.shop ck66916.tw1.ru disappointcredisotw.shop doughtdrillyksow.shop injurypiggyoewirog.shop leafcalfconflcitw.shop publicitycharetew.shop www.noticeofpleadings.net