855f8d8748a0658e591d712268ed8bc4b2fe28cb6b621a561fc1fbdeb4d1ea44
Classification: Malicious
855f8d8748a0658e591d712268ed8bc4b2fe28cb6b621a561fc1fbdeb4d1ea44 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 25 antivirus detections
- 1 IDS alerts
- 6 processes observed
- 2 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-06-18 20:00:03 |
2026-09-02 22:45:03 |
malicious-activity
|
|
Sample information
- Filenames
- 855f8d8748a0658e591d712268ed8bc4b2fe28cb6b621a561fc1fbdeb4d1ea44, 855f8.Trojan.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 449536 bytes
- MD5
31552649278b061edf588dab96c93db4
- SHA-1
e5794fa6daf3f8ec497955285a1417ab8962cc0b
- SHA-256
855f8d8748a0658e591d712268ed8bc4b2fe28cb6b621a561fc1fbdeb4d1ea44
- First indexed
- 2024-06-18 19:55:07
- Last updated
- 2026-09-02 22:45:03
Antivirus detections
| Engine | Detection |
| APEX | Malicious |
| BitDefenderTheta | Gen:NN.ZexaF.36806.BqW@a0Qeiqp |
| Bkav | W32.AIDetectMalware |
| ClamAV | Win.Keylogger.Lazy-10031941-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| Elastic | malicious (high confidence) |
| FireEye | Generic.mg.31552649278b061e |
| Google | Detected |
| Ikarus | Trojan.Win32.Krypt |
| Kaspersky | VHO:Trojan-PSW.Win32.Stealerc.gen |
| Kingsoft | malware.kb.a.986 |
| Lionic | Virus.Generic.AI.1!c |
| MaxSecure | Trojan.Malware.300983.susgen |
| McAfeeD | Real Protect-LS!31552649278B |
| Paloalto | generic.ml |
| Rising | [email protected] (RDML:6Z3hgJ7+sBEBQdv98+Ijlg) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Generic.gc |
| Sophos | ML/PE-A |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | malicious.high.ml.score |
| ZoneAlarm | VHO:Trojan-PSW.Win32.Stealerc.gen |
Process list
| Name | Command line |
| 855f8.Trojan.exe | |
| RegAsm.exe | |
| cmd.exe | /c timeout /t 10 & del /f /q "%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" & rd /s /q "%ALLUSERSPROFILE%\DGDHJEGIEBFH" & exit |
| timeout.exe | timeout /t 10 |
| WerFault.exe | -u -p 3880 -s 412 |
| WerFault.exe | -pss -s 440 -p 3880 -ip 3880 |