86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1

Classification: Malicious

86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-03.

Detection summary

  • 57 antivirus detections
  • 2 IDS alerts
  • 5 processes observed
  • 2 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-07-27 13:30:05 2026-09-03 00:45:03 malicious-activity

Tags

infostealer

Sample information

Filenames
86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
733696 bytes
MD5
84cde485c63b081e3c753525de5ca7c7
SHA-1
e75196d8eca2f65d2912618938c2211d31da4c8f
SHA-256
86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1
First indexed
2025-07-27 13:16:10
Last updated
2026-09-03 00:45:04

Antivirus detections

EngineDetection
ALYacTrojan.GenericKDZ.105698
APEXMalicious
AVGWin32:MalwareX-gen [Pws]
AhnLab-V3Trojan/Win.Generic.C5603797
AlibabaTrojan:MSIL/Formbook.d1b367b4
ArcabitTrojan.Generic.D19CE2
AvastWin32:MalwareX-gen [Pws]
AviraTR/AD.Nekark.hmlda
BitDefenderTrojan.GenericKDZ.105698
BkavW32.AIDetectMalware.CS
CAT-QuickHealTrojan.MsilFC.S33348356
CTXexe.trojan.msil
ClamAVWin.Packed.Taskun-10024493-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
DrWebTrojan.PackedNET.2755
ESET-NOD32a variant of MSIL/Kryptik.ALFL
Elasticmalicious (high confidence)
EmsisoftTrojan.GenericKDZ.105698 (B)
F-SecureTrojan.TR/AD.Nekark.hmlda
FortinetMSIL/Remcos.GWMJE!tr
GDataTrojan.GenericKDZ.105698
GoogleDetected
IkarusTrojan.MSIL.Inject
K7AntiVirusTrojan ( 700000201 )
K7GWTrojan ( 700000201 )
KasperskyHEUR:Trojan.MSIL.Taskun.gen
KingsoftMSIL.Trojan.Taskun.gen
LionicTrojan.Win32.Taskun.4!c
MalwarebytesMalware.AI.4033545436
MaxSecureTrojan.Malware.74644571.susgen
McAfeeDti!86CC6304F561
MicroWorld-eScanTrojan.GenericKDZ.105698
MicrosoftTrojan:MSIL/Formbook.RDZ!MTB
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingMalware.Obfus/[email protected] (RDM.MSIL2:X9N4u+rF+DGx2cHCC5Po2g)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.bc
SophosTroj/Krypt-ABH
SymantecScr.Malcode!gdn33
TencentMalware.Win32.Gencirc.11be8b9d
TrellixENSAgentTesla!84CDE485C63B
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9h
VBA32TrojanLoader.MSIL.DaVinci.Heur
VIPRETrojan.GenericKDZ.105698
VaristW32/MSIL_Troj.DDH.gen!Eldorado
VirITTrojan.Win32.GenusT.DVND
WebrootW32.Malware.gen
XcitiumMalware@#335bhx00zupi0
YandexTrojan.Taskun!vu/8TeMQW8c
ZillyaTrojan.Kryptik.Win32.4690374
ZoneAlarmTroj/Krypt-ABH
alibabacloudTrojan:MSIL/Formbook.RDZ!MTB
huorongTrojanSpy/MSIL.AgentTesla.mq

Network contacts

104.26.13.205 172.67.74.152

DNS requests

api.ipify.org

Process list

NameCommand line
86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1.exe
powershell.exeAdd-MpPreference -ExclusionPath "C:\86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1.exe"
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\VTROzEh.exe"
schtasks.exe/Create /TN "Updates\VTROzEh" /XML "%TEMP%\tmpF3CD.tmp"
RegSvcs.exe