85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3
Classification: Malicious
85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.
Detection summary
- 22 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-02-20 01:45:03 |
2026-09-02 23:45:10 |
malicious-activity
|
|
| zgRAT |
MalwareBazaar Abuse.ch |
2024-02-20 01:21:31 |
2024-02-20 01:21:31 |
malicious-activity
|
|
Sample information
- Filenames
- 85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3, 53eac6a1efcdd851ac025fb7bf7e9ec1
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 6874408 bytes
- MD5
53eac6a1efcdd851ac025fb7bf7e9ec1
- SHA-1
9e945fc8fa397dc13c993b2ea7bde07648d2fbc7
- SHA-256
85678c213dc5d11411070297d3e899c3c052dee7a2ff1a0ccc26990c7c5f9aa3
- First indexed
- 2024-02-20 01:23:26
- Last updated
- 2026-09-02 23:45:10
Antivirus detections
| Engine | Detection |
| AVG | TrojanX-gen [Trj] |
| AhnLab-V3 | Suspicious/Win.MalPe.X2205 |
| Alibaba | Trojan:MSIL/Kryptik.d630ac3a |
| Avast | TrojanX-gen [Trj] |
| Bkav | W32.AIDetectMalware.CS |
| CrowdStrike | win/grayware_confidence_60% (D) |
| Cylance | unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | a variant of MSIL/Kryptik.AKYD |
| Elastic | malicious (moderate confidence) |
| Kaspersky | VHO:Trojan.MSIL.Agent.gen |
| Malwarebytes | Generic.Malware/Suspicious |
| McAfee | Artemis!53EAC6A1EFCD |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Rising | Trojan.Kryptik!8.8 (CLOUD) |
| Sangfor | Trojan.Msil.Agent.Vxq4 |
| Skyhigh | Artemis!Trojan |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Win32.Trojan.FalseSign.Jajl |
| VBA32 | Trojan.MSIL.zgRAT.Heur |
| ZoneAlarm | VHO:Trojan.MSIL.Agent.gen |
Process list
| Name | Command line |
| 53eac6a1efcdd851ac025fb7bf7e9ec1.exe | |
| RegSvcs.exe | |
| RegSvcs.exe | |
| powershell.exe | Remove -ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'kwweifjdskdv';New-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'kwweifjdskdv' -Value '"%LOCALAPPDATA%\kwweifjdskdv\kwweifjdskdv.exe"' -PropertyType 'String' |
| WerFault.exe | -k -lc win32kbase.sys win32kbase.sys-20240220-0126.dm |