7d78076dac303316f0329e628df256a55b07bbea46ed03097e7bd33a6e52085d

Classification: Malicious

7d78076dac303316f0329e628df256a55b07bbea46ed03097e7bd33a6e52085d is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 33 antivirus detections
  • 1 IDS alerts
  • 34 processes observed
  • 1 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-03-12 08:25:42 2026-09-02 11:45:06 malicious-activity

Tags

windows-server-utility evasive

Sample information

Filenames
7d78076dac303316f0329e628df256a55b07bbea46ed03097e7bd33a6e52085d, 7d78076dac303316f0329e628df256a55b07bbea46ed03097e7bd33a6e52085d.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
1228017 bytes
MD5
74582deec90e9e6cbb177747f118c643
SHA-1
c3bdfe4c86c51e3f0b31e299b44811607e9c6486
SHA-256
7d78076dac303316f0329e628df256a55b07bbea46ed03097e7bd33a6e52085d
First indexed
2024-03-12 08:03:06
Last updated
2026-09-02 11:45:07

Antivirus detections

EngineDetection
ALYacTrojan.MSIL.Basic.8.Gen
APEXMalicious
AVGWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.MSIL.Basic.8.Gen
AhnLab-V3Trojan/Win.DC.R444179
ArcabitTrojan.MSIL.Basic.8.Gen
AvastWin32:TrojanX-gen [Trj]
AviraHEUR/AGEN.1144842
BitDefenderTrojan.Uztuby.17
BitDefenderThetaGen:NN.ZemsilF.34218.5q0@aGSO5xhi
ClamAVWin.Malware.Uztuby-9848412-0
CynetMalicious (score: 100)
DrWebBackDoor.QuasarNET.5
ESET-NOD32a variant of MSIL/Spy.Agent.DEK
Elasticmalicious (high confidence)
EmsisoftTrojan.Uztuby.17 (B)
F-SecureHeuristic.HEUR/AGEN.1144842
FireEyeGeneric.mg.74582deec90e9e6c
GDataWin32.Trojan.BSE.1CL7UZW
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
MAXmalware (ai score=88)
MalwarebytesTrojan.Injector
McAfeeArtemis!74582DEEC90E
McAfee-GW-EditionBehavesLike.Win32.Generic.th
MicroWorld-eScanTrojan.Uztuby.17
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
SangforTrojan.Win32.Save.a
SentinelOneStatic AI - Malicious SFX
SophosMal/SpyNoon-A
YandexTrojanSpy.Agent!E1F/YYS2Hnk
ZoneAlarmHEUR:Trojan-Ransom.Win32.Instructions.vho

Network contacts

185.246.67.26

Process list

NameCommand line
7d78076dac303316f0329e628df256a55b07bbea46ed03097e7bd33a6e52085d.exe
WScript.exe"C:\runtimePerfMonitorDll\6MFELPbNOX5vr9aXwzdCc1GKV.vbe"
cmd.exe%WINDIR%\system32\cmd.exe /c ""C:\runtimePerfMonitorDll\zANuZEHewnILsTM8VeuW7MLoj4xN1.bat" "
runtimePerfMonitorDllRuntimeMonitor.exe
cmd.exe/C "%TEMP%\eci4aV6yqf.bat"
w32tm.exew32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
AutoIt3_x64.exe
schtasks.exe/create /tn "AutoIt3_x64" /sc ONLOGON /tr "'%PROGRAMFILES%\(x86)\AutoIt3\Au3Check\AutoIt3_x64.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "fontdrvhost" /sc ONLOGON /tr "'%WINDIR%\System32\mfsvr\fontdrvhost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "sihost" /sc ONLOGON /tr "'C:\tempdir\sihost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "TrustedInstaller" /sc ONLOGON /tr "'C:\tempdir\TrustedInstaller.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "AutoIt3_x64" /sc ONLOGON /tr "'%PUBLIC%\Pictures\AutoIt3_x64.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "conhost" /sc ONLOGON /tr "'%WINDIR%\System32\Windows.Globalization.Fontgroups\conhost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "RuntimeBroker" /sc ONLOGON /tr "'%WINDIR%\System32\twinui\RuntimeBroker.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "fontdrvhost" /sc ONLOGON /tr "'%WINDIR%\System32\KBDYCC\fontdrvhost.exe'" /rl HIGHEST /f
WScript.exe"C:\extra_enc_0.vbe"
cmd.exe/c ""C:\runtimePerfMonitorDll\zANuZEHewnILsTM8VeuW7MLoj4xN1.bat" "
runtimePerfMonitorDllRuntimeMonitor.exe
cmd.exe/C "%TEMP%\73Ty7MZ348.bat"
w32tm.exew32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
runtimePerfMonitorDllRuntimeMonitor.exe
AutoIt3_x64.exe
schtasks.exe/create /tn "ShellExperienceHost" /sc ONLOGON /tr "'C:\PerfLogs\Admin\ShellExperienceHost.exe'" /rl HIGHEST /f
<Ignored Process>
schtasks.exe/create /tn "ctfmon" /sc ONLOGON /tr "'%WINDIR%\System32\WinOpcIrmProtector\ctfmon.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "conhost" /sc ONLOGON /tr "'%WINDIR%\System32\ActivationManager\conhost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "mitmdump" /sc ONLOGON /tr "'%PROGRAMFILES%\mitmproxy\bin\api-ms-win-core-processthreads-l1-1-0\mitmdump.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "taskhostw" /sc ONLOGON /tr "'%USERPROFILE%\Recent\taskhostw.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "winlogon" /sc ONLOGON /tr "'%WINDIR%\System32\taskschd\winlogon.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "fontdrvhost" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\fontdrvhost.exe'" /rl HIGHEST /f