7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761

Classification: Malicious

7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761 is a malicious file sample. Reported by 1 threat source, last seen 2026-09-02.

Detection summary

  • 56 antivirus detections (81% detection ratio)
  • 2 IDS alerts
  • 52 processes observed
  • 1 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-01-07 23:45:04 2026-09-02 11:45:05 malicious-activity

Tags

evasive windows-server-utility rat

Sample information

Filenames
7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761, ymna.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
1601024 bytes
MD5
25da06e98e14b2a8cbd39e8e7aba3fad
SHA-1
1900dd1a88cf634e70df31ca8ba55e98169a1961
SHA-256
7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761
First indexed
2024-01-07 23:13:23
Last updated
2026-09-02 11:45:05

Antivirus detections

EngineDetection
BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.DCRat.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Prometheus.1
CAT-QuickHealTrojan.DCRat.S29707587
SkyhighBehavesLike.Win32.Generic.tc
McAfeeTrojan-FUJL!25DA06E98E14
MalwarebytesGeneric.Spyware.Stealer.DDS
VIPREGen:Variant.Ransom.Prometheus.1
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/DCRat.60ba5510
K7GWSpyware ( 0058ec321 )
K7AntiVirusSpyware ( 0058ec321 )
ArcabitTrojan.Ransom.Prometheus.1
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Spy.Agent.DTP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Msilmamut-9950860-0
KasperskyHEUR:Backdoor.MSIL.DCRat.gen
BitDefenderGen:Variant.Ransom.Prometheus.1
AvastWin32:RATX-gen [Trj]
TencentBackdoor.MSIL.Stealer.11025419
EmsisoftGen:Variant.Ransom.Prometheus.1 (B)
F-SecureHeuristic.HEUR/AGEN.1323984
DrWebTrojan.PWS.StealerNET.124
ZillyaTrojan.BasicGen.Win32.4
TrendMicroTROJ_GEN.R002C0DA524
SophosTroj/DCRat-N
IkarusTrojan-Spy.Agent
VaristW32/MSIL_Agent.LQ.gen!Eldorado
AviraHEUR/AGEN.1323984
Antiy-AVLTrojan[Backdoor]/MSIL.DCRat
Kingsoftmalware.kb.c.997
GridinsoftTrojan.Win32.Agent.oa!s1
MicrosoftBackdoor:MSIL/DCRat!MTB
ZoneAlarmHEUR:Backdoor.MSIL.DCRat.gen
GDataGen:Variant.Ransom.Prometheus.1
GoogleDetected
AhnLab-V3Trojan/Win.FUJL.C5130705
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.36680.Hr0@aWQnk5bi
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DA524
RisingBackdoor.DcRat!8.129D9 (CLOUD)
YandexTrojanSpy.Agent!zPLo0s1Nilk
SentinelOneStatic AI - Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DVA!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS

Network contacts

5.42.85.163

Process list

NameCommand line
7d9ec2e09c8559b1d695569da5f16b9a6edd54c38526b91d458ca5c43c401761.exe
cmd.exe/C "%TEMP%\35gbisF1f8.bat"
w32tm.exew32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
System.exe
schtasks.exe/create /tn "Memory CompressionM" /sc MINUTE /mo 13 /tr "'C:\Recovery\Memory Compression.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "RuntimeBroker" /sc ONLOGON /tr "'%USERPROFILE%\Saved Games\RuntimeBroker.exe'" /rl HIGHEST /f
lsass.exe
ymna.exe
cmd.exe/C "%TEMP%\rLL4imMUDV.bat"
w32tm.exew32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
AutoIt3.exe
schtasks.exe/create /tn "AutoIt3A" /sc MINUTE /mo 7 /tr "'%PROGRAMFILES%\AutoIt3\SciTE\api\AutoIt3.exe'" /f
schtasks.exe/create /tn "AutoIt3" /sc ONLOGON /tr "'%PROGRAMFILES%\AutoIt3\SciTE\api\AutoIt3.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "AutoIt3A" /sc MINUTE /mo 7 /tr "'%PROGRAMFILES%\AutoIt3\SciTE\api\AutoIt3.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "taskhostt" /sc MINUTE /mo 11 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\taskhost.exe'" /f
schtasks.exe/create /tn "taskhost" /sc ONLOGON /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\taskhost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "taskhostt" /sc MINUTE /mo 10 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\taskhost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "conhostc" /sc MINUTE /mo 7 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\conhost.exe'" /f
schtasks.exe/create /tn "conhost" /sc ONLOGON /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\conhost.exe'" /rl HIGHEST /f
AutoIt3.exe
schtasks.exe/create /tn "conhostc" /sc MINUTE /mo 9 /tr "'C:\Recovery\cf812052-d863-11e7-ae2b-a9d1a6f40333\conhost.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "AutoIt3A" /sc MINUTE /mo 14 /tr "'%USERPROFILE%\AutoIt3.exe'" /f
schtasks.exe/create /tn "AutoIt3" /sc ONLOGON /tr "'%USERPROFILE%\AutoIt3.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "AutoIt3A" /sc MINUTE /mo 13 /tr "'%USERPROFILE%\AutoIt3.exe'" /rl HIGHEST /f
taskhost.exe
schtasks.exe/create /tn "mobsyncm" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\mobsync.exe'" /f
schtasks.exe/create /tn "mobsync" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\mobsync.exe'" /rl HIGHEST /f
conhost.exe
schtasks.exe/create /tn "mobsyncm" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\mobsync.exe'" /rl HIGHEST /f
schtasks.exe/create /tn "lsassl" /sc MINUTE /mo 13 /tr "'C:\Temp\lsass.exe'" /f