7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761
Classification: Malicious
7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.
Detection summary
- 56 antivirus detections (81% detection ratio)
- 2 IDS alerts
- 52 processes observed
- 1 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-01-07 23:45:04 |
2026-09-02 11:45:05 |
malicious-activity
|
|
Tags
evasive
windows-server-utility
rat
Sample information
- Filenames
- 7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761, ymna.exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 1601024 bytes
- MD5
25da06e98e14b2a8cbd39e8e7aba3fad
- SHA-1
1900dd1a88cf634e70df31ca8ba55e98169a1961
- SHA-256
7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761
- First indexed
- 2024-01-07 23:13:23
- Last updated
- 2026-09-02 11:45:05
Antivirus detections
| Engine | Detection |
| Bkav | W32.AIDetectMalware.CS |
| Lionic | Trojan.Win32.DCRat.m!c |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Variant.Ransom.Prometheus.1 |
| CAT-QuickHeal | Trojan.DCRat.S29707587 |
| Skyhigh | BehavesLike.Win32.Generic.tc |
| McAfee | Trojan-FUJL!25DA06E98E14 |
| Malwarebytes | Generic.Spyware.Stealer.DDS |
| VIPRE | Gen:Variant.Ransom.Prometheus.1 |
| Sangfor | Suspicious.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | Backdoor:MSIL/DCRat.60ba5510 |
| K7GW | Spyware ( 0058ec321 ) |
| K7AntiVirus | Spyware ( 0058ec321 ) |
| Arcabit | Trojan.Ransom.Prometheus.1 |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Symantec | ML.Attribute.HighConfidence |
| tehtris | Generic.Malware |
| ESET-NOD32 | a variant of MSIL/Spy.Agent.DTP |
| Cynet | Malicious (score: 100) |
| APEX | Malicious |
| ClamAV | Win.Packed.Msilmamut-9950860-0 |
| Kaspersky | HEUR:Backdoor.MSIL.DCRat.gen |
| BitDefender | Gen:Variant.Ransom.Prometheus.1 |
| Avast | Win32:RATX-gen [Trj] |
| Tencent | Backdoor.MSIL.Stealer.11025419 |
| Emsisoft | Gen:Variant.Ransom.Prometheus.1 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1323984 |
| DrWeb | Trojan.PWS.StealerNET.124 |
| Zillya | Trojan.BasicGen.Win32.4 |
| TrendMicro | TROJ_GEN.R002C0DA524 |
| Sophos | Troj/DCRat-N |
| Ikarus | Trojan-Spy.Agent |
| Varist | W32/MSIL_Agent.LQ.gen!Eldorado |
| Avira | HEUR/AGEN.1323984 |
| Antiy-AVL | Trojan[Backdoor]/MSIL.DCRat |
| Kingsoft | malware.kb.c.997 |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Microsoft | Backdoor:MSIL/DCRat!MTB |
| ZoneAlarm | HEUR:Backdoor.MSIL.DCRat.gen |
| GData | Gen:Variant.Ransom.Prometheus.1 |
| Google | Detected |
| AhnLab-V3 | Trojan/Win.FUJL.C5130705 |
| Acronis | suspicious |
| BitDefenderTheta | Gen:NN.ZemsilF.36680.Hr0@aWQnk5bi |
| MAX | malware (ai score=86) |
| Cylance | unsafe |
| Panda | Trj/GdSda.A |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DA524 |
| Rising | Backdoor.DcRat!8.129D9 (CLOUD) |
| Yandex | TrojanSpy.Agent!zPLo0s1Nilk |
| SentinelOne | Static AI - Malicious PE |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | MSIL/Agent.DVA!tr |
| AVG | Win32:RATX-gen [Trj] |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| 7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761.exe | |
| cmd.exe | /C "%TEMP%\35gbisF1f8.bat" |
| w32tm.exe | w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 |
| System.exe | |
| schtasks.exe | /create /tn "Memory CompressionM" /sc MINUTE /mo 13 /tr "'C:\Recovery\Memory Compression.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "RuntimeBroker" /sc ONLOGON /tr "'%USERPROFILE%\Saved Games\RuntimeBroker.exe'" /rl HIGHEST /f |
| lsass.exe | |
| ymna.exe | |
| cmd.exe | /C "%TEMP%\rLL4imMUDV.bat" |
| w32tm.exe | w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 |
| AutoIt3.exe | |
| schtasks.exe | /create /tn "AutoIt3A" /sc MINUTE /mo 7 /tr "'%PROGRAMFILES%\AutoIt3\SciTE\api\AutoIt3.exe'" /f |
| schtasks.exe | /create /tn "AutoIt3" /sc ONLOGON /tr "'%PROGRAMFILES%\AutoIt3\SciTE\api\AutoIt3.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "AutoIt3A" /sc MINUTE /mo 7 /tr "'%PROGRAMFILES%\AutoIt3\SciTE\api\AutoIt3.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "taskhostt" /sc MINUTE /mo 11 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\taskhost.exe'" /f |
| schtasks.exe | /create /tn "taskhost" /sc ONLOGON /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\taskhost.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "taskhostt" /sc MINUTE /mo 10 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\taskhost.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "conhostc" /sc MINUTE /mo 7 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\conhost.exe'" /f |
| schtasks.exe | /create /tn "conhost" /sc ONLOGON /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\conhost.exe'" /rl HIGHEST /f |
| AutoIt3.exe | |
| schtasks.exe | /create /tn "conhostc" /sc MINUTE /mo 9 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\conhost.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "AutoIt3A" /sc MINUTE /mo 14 /tr "'%USERPROFILE%\AutoIt3.exe'" /f |
| schtasks.exe | /create /tn "AutoIt3" /sc ONLOGON /tr "'%USERPROFILE%\AutoIt3.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "AutoIt3A" /sc MINUTE /mo 13 /tr "'%USERPROFILE%\AutoIt3.exe'" /rl HIGHEST /f |
| taskhost.exe | |
| schtasks.exe | /create /tn "mobsyncm" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\mobsync.exe'" /f |
| schtasks.exe | /create /tn "mobsync" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\mobsync.exe'" /rl HIGHEST /f |
| conhost.exe | |
| schtasks.exe | /create /tn "mobsyncm" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\mobsync.exe'" /rl HIGHEST /f |
| schtasks.exe | /create /tn "lsassl" /sc MINUTE /mo 13 /tr "'C:\Temp\lsass.exe'" /f |