869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca

Classification: Malicious

869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca is a malicious file sample. Reported by 1 threat source, last seen 2026-09-03.

Detection summary

  • 66 antivirus detections
  • 0 IDS alerts
  • 24 processes observed
  • 1 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-01-27 08:43:24 2026-09-03 00:45:05 malicious-activity

Tags

evasive malicious windows-server-utility

Sample information

Filenames
869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca, jhn1u7ntf6.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
2210583 bytes
MD5
09b7a6fd3683f653ea233a547c082671
SHA-1
07f919d59982c0670ea31d1f1f63b08f31eff676
SHA-256
869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca
First indexed
2025-01-27 08:21:51
Last updated
2026-09-03 00:45:05

Antivirus detections

EngineDetection
ALYacTrojan.MSIL.Basic.8.Gen
APEXMalicious
AVGWin32:Evo-gen [Trj]
AhnLab-V3Trojan/Win.Generic.R492805
AlibabaTrojanPSW:MSIL/DCRat.3954a2b1
ArcabitTrojan.Uztuby.17 [many]
AvastWin32:Evo-gen [Trj]
AviraTR/Spy.Agent.nutyk
BitDefenderTrojan.Uztuby.17
BkavW32.Common.D072E1A9
CAT-QuickHealTrojan.Ghanarava.1736270337082671
CTXexe.trojan.msil
ClamAVWin.Trojan.Uztuby-9855059-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
DrWebVBS.Starter.321
ESET-NOD32multiple detections
Elasticmalicious (high confidence)
EmsisoftTrojan.Uztuby.17 (B)
F-SecureTrojan.TR/Spy.Agent.nutyk
FireEyeGeneric.mg.09b7a6fd3683f653
FortinetMSIL/Crypt.SS!tr.spy
GDataTrojan.Zmutzy.Lscpt.1
GoogleDetected
IkarusTrojan.SuspectCRC
K7AntiVirusTrojan ( 005ac5cb1 )
K7GWTrojan ( 005ac5cb1 )
KasperskyUDS:Trojan-PSW.MSIL.Disco.gen
KingsoftMSIL.Trojan-PSW.Disco.gen
LionicTrojan.Win32.Uztuby.4!c
MalwarebytesGeneric.Malware.AI.DDS
MaxSecureTrojan.Malware.317375757.susgen
McAfeeArtemis!09B7A6FD3683
McAfeeDti!869F0E332938
MicroWorld-eScanTrojan.Uztuby.17
MicrosoftTrojan:Win32/DCRat!rfn
NANO-AntivirusTrojan.Win32.Disco.kunpzi
Paloaltogeneric.ml
PandaTrj/CI.A
RisingTrojan.Dnoper!8.10CB3 (CLOUD)
SangforSuspicious.Win32.Save.ins
SentinelOneStatic AI - Malicious SFX
SkyhighBehavesLike.Win32.Generic.vc
SophosTroj/Krypt-AEV
SymantecTrojan.Gen.MBT
TencentWin32.Script.Agent.Kajl
TrendMicroTROJ_GEN.R002C0DLS24
TrendMicro-HouseCallTROJ_GEN.R002C0DLS24
VBA32TrojanPSW.MSIL.Disco
VIPRETrojan.Uztuby.17
VaristW32/MSIL_Kryptik.KIJ.gen!Eldorado
ViRobotTrojan.Win.Z.Uztuby.2210583
VirITTrojan.Win32.GenusT.EGRK
XcitiumMalware@#1xvdi54y05dp
alibabacloudTrojan[spy]:MSIL/DCRat.LM8PHU
huorongBackdoor/MSIL.DCRat.l
AviraHEUR/AGEN.1380145
BkavW32.AIDetectMalware
DrWebTrojan.Siggen31.48899
F-SecureHeuristic.HEUR/AGEN.1380145
GDataTrojan.MSIL.Basic.8.Gen
LionicTrojan.Win32.Uztuby.i!c
TrellixENSArtemis!09B7A6FD3683
ZoneAlarmMal/RarMal-R

Network contacts

172.67.132.55

DNS requests

stethem.ru

Process list

NameCommand line
jhn1u7ntf6.exe
WScript.exe"C:\webFontsession\ygBm0L4dnhMtPJ5zo9k2Iwhn4.vbe"
cmd.exe%WINDIR%\system32\cmd.exe /c ""C:\webFontsession\7uhC6Mx3YQJtIYicktXEMaD7UeOIzINRTf.bat" "
SurrogatesessionRuntimeBrokerDhcp.exe
cmd.exe/C "%TEMP%\xHAQPcqSYM.bat"
chcp.comchcp 65001
w32tm.exew32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
conhost.exe
Idle.exe
TrustedInstaller.exe
RuntimeBroker.exe
SurrogatesessionRuntimeBrokerDhcp.exe
SurrogatesessionRuntimeBrokerDhcp.exe
SurrogatesessionRuntimeBrokerDhcp.exe
RuntimeBroker.exe
conhost.exe
SurrogatesessionRuntimeBrokerDhcp.exe
Idle.exe
TrustedInstaller.exe
RuntimeBroker.exe
conhost.exe
TrustedInstaller.exe
Idle.exe
SurrogatesessionRuntimeBrokerDhcp.exe