855d0048eb544614d057f025c49145f599a41219e57dc4c415a854b4dbd633a1

Classification: Malicious

855d0048eb544614d057f025c49145f599a41219e57dc4c415a854b4dbd633a1 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 30 antivirus detections
  • 0 IDS alerts
  • 5 processes observed
  • 7 contacted hosts
  • 6 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-03-08 15:15:03 2026-09-02 22:45:03 malicious-activity
Generic.Malware MalwareBazaar Abuse.ch 2024-03-08 14:47:14 2024-03-08 14:47:14 malicious-activity

Tags

evasive infostealer

Sample information

Filenames
855d0048eb544614d057f025c49145f599a41219e57dc4c415a854b4dbd633a1, Re Remittance Advice.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
804360 bytes
MD5
beb75d678dead227ec7a733a6dc5e705
SHA-1
9ec898e0effd6edb10b3063a600bd3c412ad3d49
SHA-256
855d0048eb544614d057f025c49145f599a41219e57dc4c415a854b4dbd633a1
First indexed
2024-03-08 14:47:59
Last updated
2026-09-02 22:45:03

Antivirus detections

EngineDetection
APEXMalicious
AVGFileRepMalware [Pws]
AvastFileRepMalware [Pws]
BitDefenderThetaGen:NN.ZemsilF.36802.Xm2@a4!FDUj
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (W)
Cylanceunsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/Kryptik.ALCL
Elasticmalicious (high confidence)
FortinetMSIL/GenericKDS.61009645!tr
GoogleDetected
GridinsoftTrojan.Win32.Packed.sa
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
LionicTrojan.Win32.Taskun.4!c
MalwarebytesTrojan.MalPack.PNG.Generic
MaxSecureTrojan.Malware.300983.susgen
McAfeeArtemis!BEB75D678DEA
MicrosoftTrojan:MSIL/Formbook.KAI!MTB
RisingTrojan.Formbook!8.F858 (CLOUD)
SangforTrojan.Msil.Agent.Vgav
SentinelOneStatic AI - Malicious PE
SkyhighArtemis!Trojan
SophosMal/Generic-S
SymantecScr.Malcode!gdn33
TrendMicro-HouseCallTROJ_GEN.F0D1C00C824
VaristW32/MSIL_Agent.HQX.gen!Eldorado
VirITTrojan.Win32.MSIL_Heur.A

Network contacts

142.251.218.99 142.250.141.94 142.250.80.35 142.251.40.99 142.250.80.67 142.251.40.195 172.217.165.132

DNS requests

ocsp.pki.goog www.google.de fonts.gstatic.com maps.gstatic.com www.google.com www.gstatic.com

Process list

NameCommand line
ReRemittanceAdvice.exe
powershell.exeAdd-MpPreference -ExclusionPath "C:\ReRemittanceAdvice.exe"
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\cEzTqNDUrJzL.exe"
schtasks.exe/Create /TN "Updates\cEzTqNDUrJzL" /XML "%TEMP%\tmpA23.tmp"
RegSvcs.exe