855f8c478918d0202a467a90a5ead1be7a4e87e08485106a6a545938979204ac

Classification: Malicious

855f8c478918d0202a467a90a5ead1be7a4e87e08485106a6a545938979204ac is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 34 antivirus detections
  • 3 IDS alerts
  • 0 processes observed
  • 3 contacted hosts
  • 5 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2026-09-02 22:45:03 2026-09-02 22:45:03 malicious-activity
SnakeKeylogger MalwareBazaar Abuse.ch 2023-11-30 06:53:55 2023-11-30 06:53:55 malicious-activity

Sample information

Filenames
855f8c478918d0202a467a90a5ead1be7a4e87e08485106a6a545938979204ac, Invoice YA 2023.exe
File type
application/x-dosexec
MD5
2fdd47b3a729217cdd1848ce1d832bd2
SHA-1
80b1f475e7c906927b87b76bea1d72a0ae0ce2c7
SHA-256
855f8c478918d0202a467a90a5ead1be7a4e87e08485106a6a545938979204ac
First indexed
2023-11-30 07:18:41
Last updated
2026-09-02 22:45:03

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware.CS
MicroWorld-eScanGen:Variant.Ser.Lazy.5637
FireEyeGen:Variant.Ser.Lazy.5637
SkyhighBehavesLike.Win32.Generic.hc
McAfeeGenericRXWL-XN!2FDD47B3A729
MalwarebytesTrojan.MalPack.PNG.Generic
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Ser.Lazy.D1605
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn33
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AKGP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderGen:Variant.Ser.Lazy.5637
AvastWin32:PWSX-gen [Trj]
EmsisoftGen:Variant.Ser.Lazy.5637 (B)
DrWebTrojan.Inject4.59820
SophosTroj/Krypt-ABH
SentinelOneStatic AI - Malicious PE
GoogleDetected
MAXmalware (ai score=82)
MicrosoftTrojan:MSIL/AgentTesla.DL!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataGen:Variant.Ser.Lazy.5637
VaristW32/MSIL_Kryptik.KFC.gen!Eldorado
AhnLab-V3Trojan/Win.PWSX-gen.C5556353
RisingMalware.Obfus/[email protected] (RDM.MSIL2:ecFe8vEhxTyXJEPt+2NYgQ)
IkarusTrojan.MSIL.Inject
FortinetMSIL/Kryptik.HDZY!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

Network contacts

132.226.247.73 104.21.67.152 192.169.69.26

DNS requests

aborters.duckdns.org anotherarmy.dns.army checkip.dyndns.org reallyfreegeoip.org varders.kozow.com