86c5161f5f85545822b070a1062971091fc638b8a8ea6bd5472e5208656279b2

Classification: Malicious

86c5161f5f85545822b070a1062971091fc638b8a8ea6bd5472e5208656279b2 is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-03.

Detection summary

  • 53 antivirus detections (74% detection ratio)
  • 11 IDS alerts
  • 26 processes observed
  • 3 contacted hosts
  • 3 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-29 15:21:01 2026-09-03 00:45:04 malicious-activity
RedLineStealer MalwareBazaar Abuse.ch 2023-11-29 15:05:40 2023-11-29 15:05:40 malicious-activity

Sample information

Filenames
86c5161f5f85545822b070a1062971091fc638b8a8ea6bd5472e5208656279b2, 96666E098BA9BD84EE3B85E85097B7C7.exe
File type
application/x-dosexec
Size
418332 bytes
MD5
96666e098ba9bd84ee3b85e85097b7c7
SHA-1
e92fc3b5c3fa9743f25880d2260035313742baab
SHA-256
86c5161f5f85545822b070a1062971091fc638b8a8ea6bd5472e5208656279b2
First indexed
2023-11-29 15:06:41
Last updated
2026-09-03 00:45:04

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.NGVCK.gh
McAfeeArtemis!96666E098BA9
Cylanceunsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanSpy:Win32/RedLine.951c82b3
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.GenusT.DTYF
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HVEE
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.70581269
NANO-AntivirusTrojan.Win32.Stealer.keiknd
MicroWorld-eScanTrojan.GenericKD.70581269
AvastWin32:PWSX-gen [Trj]
EmsisoftTrojan.GenericKD.70581269 (B)
F-SecureTrojan.TR/Crypt.Agent.yklrf
DrWebTrojan.PWS.RedLineNET.6
VIPRETrojan.GenericKD.70581269
TrendMicroTrojanSpy.Win32.REDLINE.YXDKZZ
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.96666e098ba9bd84
SophosMal/Generic-S
IkarusTrojan.Win32.Redline
GDataTrojan.GenericKD.70581269
JiangminTrojan.GenericML.dyk
GoogleDetected
AviraTR/Crypt.Agent.yklrf
Antiy-AVLTrojan/Win32.Kryptik.hsyn
Kingsoftmalware.kb.a.997
ArcabitTrojan.Generic.D434FC15
ViRobotTrojan.Win.Z.Kryptik.418332
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/RedLine.RDEB!MTB
VaristW32/ABRisk.ITKA-5972
AhnLab-V3Trojan/Win.Generic.R625145
BitDefenderThetaGen:NN.ZexaF.36608.zuW@aSEQk7p
ALYacTrojan.GenericKD.70581269
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack.PES
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDKZZ
Rising[email protected] (RDML:OPxohmJhsE3f/hSKzCk8Xw)
SentinelOneStatic AI - Suspicious PE
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Kryptik.HVGM!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.5c3fa9
DeepInstinctMALICIOUS

Network contacts

150.171.109.65 184.25.254.58 52.204.246.173

DNS requests

js.monitor.azure.com mscom.demdex.net www.bing.com

Process list

NameCommand line
96666E098BA9BD84EE3B85E85097B7C7.exe
msedge.exe--single-argument http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=96666E098BA9BD84EE3B85E85097B7C7.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0
msedge.exe--type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xcc,0xd0,0xd4,0xa8,0xdc,0x7ffea539b208,0x7ffea539b218,0x7ffea539b228
msedge.exe--type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1800 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:2
msedge.exe--type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1936 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:3
msedge.exe--type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2056 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=6 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1063619308 --mojo-platform-channel-handle=2836 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=5 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1063887649 --mojo-platform-channel-handle=2880 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3612 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=renderer --extension-process --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=7 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1064480310 --mojo-platform-channel-handle=3676 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --extension-process --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=13 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1064764697 --mojo-platform-channel-handle=3688 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --extension-process --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=9 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1065028271 --mojo-platform-channel-handle=3672 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --extension-process --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=10 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1065328425 --mojo-platform-channel-handle=3868 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --extension-process --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=11 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1065635048 --mojo-platform-channel-handle=3916 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=14 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1067152984 --mojo-platform-channel-handle=4596 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6220 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=6576 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=4440 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=18 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1072720464 --mojo-platform-channel-handle=6208 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=renderer --display-capture-permissions-policy-allowed --js-flags=--ms-user-locale= --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=1 --renderer-client-id=19 --time-ticks-at-unix-epoch=-1701298290785097 --launch-time-ticks=1073164044 --mojo-platform-channel-handle=7792 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:1
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2320 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=1776 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.16299.192 --gpu-preferences=UAAAAAAAAADoAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAACQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=5016 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:2
msedge.exe--type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2540 --field-trial-handle=2088,i,12388395720507336475,1742741055448191792,131072 /prefetch:8
msedge.exe--single-argument http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch2&plcid=0x409&o1=SHIM_NOVERSION_FOUND&version=(null)&processName=96666E098BA9BD84EE3B85E85097B7C7.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0
msedge.exe--type=crashpad-handler "--user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=%LOCALAPPDATA%\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=107.0.5304.110 "--annotation=exe=%PROGRAMFILES%\(x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=107.0.1418.56 --initial-client-data=0xd0,0xd4,0xd8,0xac,0x138,0x7ffea539b208,0x7ffea539b218,0x7ffea539b228