8644c17c6ff405458abb450ea224aefe37e27bad68a01bbf9d5512dc73bc1a3c

Classification: Malicious

8644c17c6ff405458abb450ea224aefe37e27bad68a01bbf9d5512dc73bc1a3c is a malicious file sample. Reported by 1 threat source, last seen 2026-09-03.

Detection summary

  • 55 antivirus detections
  • 1 IDS alerts
  • 8 processes observed
  • 3 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-08-06 22:30:04 2026-09-03 00:45:09 malicious-activity

Tags

evasive malicious

Sample information

Filenames
8644c17c6ff405458abb450ea224aefe37e27bad68a01bbf9d5512dc73bc1a3c, 66522f42ad8fb771d604ceba4341f5cf.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
2298591 bytes
MD5
66522f42ad8fb771d604ceba4341f5cf
SHA-1
9f2b5c8402e012a9025e12e5e99a4a4f0d478f17
SHA-256
8644c17c6ff405458abb450ea224aefe37e27bad68a01bbf9d5512dc73bc1a3c
First indexed
2024-08-06 22:12:15
Last updated
2026-09-03 00:45:09

Antivirus detections

EngineDetection
ALYacGen:Variant.Application.FCA.3561
APEXMalicious
AVGWin32:MalwareX-gen [Misc]
AlibabaTrojanPSW:MSIL/DCRat.77e5024c
ArcabitTrojan.Uztuby.17 [many]
AvastWin32:MalwareX-gen [Misc]
AviraHEUR/AGEN.1380145
BitDefenderTrojan.Uztuby.17
BkavW32.AIDetectMalware
CAT-QuickHealTrojan.Ghanarava.173097538041f5cf
CTXexe.trojan.msil
ClamAVWin.Trojan.Uztuby-9855059-0
CrowdStrikewin/malicious_confidence_100% (D)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebTrojan.Siggen29.20260
ESET-NOD32RAR/Agent.ER trojan
Elasticmalicious (high confidence)
EmsisoftTrojan.Uztuby.17 (B)
F-SecureHeuristic.HEUR/AGEN.1380145
FortinetMSIL/Crypt.SS!tr.spy
GDataTrojan.Uztuby.17
GoogleDetected
IkarusTrojan.MSIL.Crypt
K7AntiVirusTrojan ( 005ac5cb1 )
K7GWTrojan ( 005ac5cb1 )
KasperskyUDS:Trojan-PSW.MSIL.Disco.gen
KingsoftMSIL.Trojan-PSW.Disco.gen
LionicTrojan.Win32.Uztuby.i!c
MalwarebytesMalware.AI.3424282684
MaxSecureTrojan.Malware.115904540.susgen
McAfeeDTrojan:Win/DCRat.GA
MicroWorld-eScanTrojan.Uztuby.17
MicrosoftTrojan:Win32/DCRat.MQ!MTB
NANO-AntivirusTrojan.Win32.Disco.kqoonv
Paloaltogeneric.ml
PandaTrj/CI.A
RisingTrojan.Dnoper!8.10CB3 (CLOUD)
SangforSuspicious.Win32.Save.ins
SentinelOneStatic AI - Malicious SFX
SkyhighBehavesLike.Win32.Dropper.vc
SophosTroj/Krypt-AEV
SymantecTrojan Horse
TencentTrojan.Msil.Kryptik.ce
TrellixENSArtemis!66522F42AD8F
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9z
VBA32TrojanPSW.MSIL.Disco
VIPRETrojan.Uztuby.17
VaristW32/MSIL_Kryptik.KIJ.gen!Eldorado
VirITTrojan.Win32.Genus.WFX
XcitiumMalware@#crd3u5nhhjk7
ZoneAlarmTroj/Krypt-AEV
alibabacloudTrojan[stealer]:MSIL/DCRat.MR8PHU
huorongBackdoor/MSIL.DCRat.l

Network contacts

104.21.46.178 23.37.17.215 172.67.168.209

DNS requests

673304cm.nyashka.top

Process list

NameCommand line
66522f42ad8fb771d604ceba4341f5cf.exe
WScript.exe"C:\msfontintobroker\VkNCYEUC1upHrhgwQf7JvasJjeEXTbsD23UGUXhAftNKdI7488oFOIY2lO0x.vbe"
cmd.exe%WINDIR%\system32\cmd.exe /c ""C:\msfontintobroker\NGVJ44.bat" "
Intodhcp.exe
cmd.exe/C "%TEMP%\IASIrEL6Vt.bat"
chcp.comchcp 65001
w32tm.exew32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
conhost.exe