85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3

Classification: Malicious

85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 22 antivirus detections
  • 0 IDS alerts
  • 5 processes observed
  • 1 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-02-20 01:45:03 2026-09-02 23:45:10 malicious-activity
zgRAT MalwareBazaar Abuse.ch 2024-02-20 01:21:31 2024-02-20 01:21:31 malicious-activity

Sample information

Filenames
85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3, 53eac6a1efcdd851ac025fb7bf7e9ec1
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
6874408 bytes
MD5
53eac6a1efcdd851ac025fb7bf7e9ec1
SHA-1
9e945fc8fa397dc13c993b2ea7bde07648d2fbc7
SHA-256
85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3
First indexed
2024-02-20 01:23:26
Last updated
2026-09-02 23:45:10

Antivirus detections

EngineDetection
AVGTrojanX-gen [Trj]
AhnLab-V3Suspicious/Win.MalPe.X2205
AlibabaTrojan:MSIL/Kryptik.d630ac3a
AvastTrojanX-gen [Trj]
BkavW32.AIDetectMalware.CS
CrowdStrikewin/grayware_confidence_60% (D)
Cylanceunsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/Kryptik.AKYD
Elasticmalicious (moderate confidence)
KasperskyVHO:Trojan.MSIL.Agent.gen
MalwarebytesGeneric.Malware/Suspicious
McAfeeArtemis!53EAC6A1EFCD
MicrosoftTrojan:Win32/Wacatac.B!ml
RisingTrojan.Kryptik!8.8 (CLOUD)
SangforTrojan.Msil.Agent.Vxq4
SkyhighArtemis!Trojan
SophosMal/Generic-S
SymantecML.Attribute.HighConfidence
TencentWin32.Trojan.FalseSign.Jajl
VBA32Trojan.MSIL.zgRAT.Heur
ZoneAlarmVHO:Trojan.MSIL.Agent.gen

Network contacts

45.15.156.43

Process list

NameCommand line
53eac6a1efcdd851ac025fb7bf7e9ec1.exe
RegSvcs.exe
RegSvcs.exe
powershell.exeRemove -ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'kwweifjdskdv';New-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'kwweifjdskdv' -Value '"%LOCALAPPDATA%\kwweifjdskdv\kwweifjdskdv.exe"' -PropertyType 'String'
WerFault.exe-k -lc win32kbase.sys win32kbase.sys-20240220-0126.dm