85ba99319f22cde0abd25e839a7a230a730f1d52e546754873e479be88e65da1

Classification: Malicious

85ba99319f22cde0abd25e839a7a230a730f1d52e546754873e479be88e65da1 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02.

Detection summary

  • 29 antivirus detections (40% detection ratio)
  • 0 IDS alerts
  • 6 processes observed
  • 0 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-10-22 18:15:03 2026-09-02 23:45:08 malicious-activity
Generic.Malware MalwareBazaar Abuse.ch 2023-10-22 16:39:50 2023-10-22 16:39:50 malicious-activity
HEUR:Trojan.MSIL.Disfa Hybrid-Analysis 2019-11-11 00:45:08 2019-11-11 00:45:08

Tags

rat

Sample information

Filenames
85ba99319f22cde0abd25e839a7a230a730f1d52e546754873e479be88e65da1, 85ba99319f22cde0abd25e839a7a230a730f1d52e546754873e479be88e65da1.exe, SecuriteInfo.com.Trojan.KillProc2.6649.17545.4126, download.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
4227072 bytes
MD5
5577c8755bee3b80e17e42e80eadde86
SHA-1
79ebbc3f9d175669ee090f53b93a925b42281b73
SHA-256
85ba99319f22cde0abd25e839a7a230a730f1d52e546754873e479be88e65da1
First indexed
2019-11-11 00:45:08
Last updated
2026-09-02 23:45:08

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKDZ.59568
FireEyeGeneric.mg.5577c8755bee3b80
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
Invinceaheuristic
ESET-NOD32a variant of MSIL/Kryptik.QME
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Disfa.gen
BitDefenderTrojan.GenericKDZ.59568
Endgamemalicious (high confidence)
DrWebTrojan.KillProc2.6649
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminemalicious.moderate.ml.score
SentinelOneDFI - Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.QME!tr
MicrosoftTrojan:Win32/Fuerboos.A!cl
ZoneAlarmHEUR:Trojan.MSIL.Disfa.gen
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.32245.@p0@aCS@XMl
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKDZ.59568
CylanceUnsafe
RisingTrojan.Kryptik!8.8 (TFE:C:kbwZGU7nfnP)
IkarusTrojan.MSIL.Crypt
AVGFileRepMalware
Cybereasonmalicious.f9d175
Qihoo-360HEUR/QVM03.0.1E5F.Malware.Gen

Process list

NameCommand line
85ba99319f22cde0abd25e839a7a230a730f1d52e546754873e479be88e65da1.exe
5PuUgwpIyLd2AH2K.exe
cmd.exe/c pause
download.exe
kz5gyyL0weMQKHAO.exe
cmd.exe/c pause