869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca
Classification: Malicious
869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca is a malicious file sample. Reported by 1 threat source, last seen 2026-09-03.
Detection summary
- 66 antivirus detections
- 0 IDS alerts
- 24 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2025-01-27 08:43:24 |
2026-09-03 00:45:05 |
malicious-activity
|
|
Tags
evasive
malicious
windows-server-utility
Sample information
- Filenames
- 869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca, jhn1u7ntf6.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 2210583 bytes
- MD5
09b7a6fd3683f653ea233a547c082671
- SHA-1
07f919d59982c0670ea31d1f1f63b08f31eff676
- SHA-256
869f0e3329384069c1fad576588672e99686bd57eee2213f90f0c78ece45d7ca
- First indexed
- 2025-01-27 08:21:51
- Last updated
- 2026-09-03 00:45:05
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.MSIL.Basic.8.Gen |
| APEX | Malicious |
| AVG | Win32:Evo-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.R492805 |
| Alibaba | TrojanPSW:MSIL/DCRat.3954a2b1 |
| Arcabit | Trojan.Uztuby.17 [many] |
| Avast | Win32:Evo-gen [Trj] |
| Avira | TR/Spy.Agent.nutyk |
| BitDefender | Trojan.Uztuby.17 |
| Bkav | W32.Common.D072E1A9 |
| CAT-QuickHeal | Trojan.Ghanarava.1736270337082671 |
| CTX | exe.trojan.msil |
| ClamAV | Win.Trojan.Uztuby-9855059-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | VBS.Starter.321 |
| ESET-NOD32 | multiple detections |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Uztuby.17 (B) |
| F-Secure | Trojan.TR/Spy.Agent.nutyk |
| FireEye | Generic.mg.09b7a6fd3683f653 |
| Fortinet | MSIL/Crypt.SS!tr.spy |
| GData | Trojan.Zmutzy.Lscpt.1 |
| Google | Detected |
| Ikarus | Trojan.SuspectCRC |
| K7AntiVirus | Trojan ( 005ac5cb1 ) |
| K7GW | Trojan ( 005ac5cb1 ) |
| Kaspersky | UDS:Trojan-PSW.MSIL.Disco.gen |
| Kingsoft | MSIL.Trojan-PSW.Disco.gen |
| Lionic | Trojan.Win32.Uztuby.4!c |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.317375757.susgen |
| McAfee | Artemis!09B7A6FD3683 |
| McAfeeD | ti!869F0E332938 |
| MicroWorld-eScan | Trojan.Uztuby.17 |
| Microsoft | Trojan:Win32/DCRat!rfn |
| NANO-Antivirus | Trojan.Win32.Disco.kunpzi |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Trojan.Dnoper!8.10CB3 (CLOUD) |
| Sangfor | Suspicious.Win32.Save.ins |
| SentinelOne | Static AI - Malicious SFX |
| Skyhigh | BehavesLike.Win32.Generic.vc |
| Sophos | Troj/Krypt-AEV |
| Symantec | Trojan.Gen.MBT |
| Tencent | Win32.Script.Agent.Kajl |
| TrendMicro | TROJ_GEN.R002C0DLS24 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DLS24 |
| VBA32 | TrojanPSW.MSIL.Disco |
| VIPRE | Trojan.Uztuby.17 |
| Varist | W32/MSIL_Kryptik.KIJ.gen!Eldorado |
| ViRobot | Trojan.Win.Z.Uztuby.2210583 |
| VirIT | Trojan.Win32.GenusT.EGRK |
| Xcitium | Malware@#1xvdi54y05dp |
| alibabacloud | Trojan[spy]:MSIL/DCRat.LM8PHU |
| huorong | Backdoor/MSIL.DCRat.l |
| Avira | HEUR/AGEN.1380145 |
| Bkav | W32.AIDetectMalware |
| DrWeb | Trojan.Siggen31.48899 |
| F-Secure | Heuristic.HEUR/AGEN.1380145 |
| GData | Trojan.MSIL.Basic.8.Gen |
| Lionic | Trojan.Win32.Uztuby.i!c |
| TrellixENS | Artemis!09B7A6FD3683 |
| ZoneAlarm | Mal/RarMal-R |
Process list
| Name | Command line |
| jhn1u7ntf6.exe | |
| WScript.exe | "C:\webFontsession\ygBm0L4dnhMtPJ5zo9k2Iwhn4.vbe" |
| cmd.exe | %WINDIR%\system32\cmd.exe /c ""C:\webFontsession\7uhC6Mx3YQJtIYicktXEMaD7UeOIzINRTf.bat" " |
| SurrogatesessionRuntimeBrokerDhcp.exe | |
| cmd.exe | /C "%TEMP%\xHAQPcqSYM.bat" |
| chcp.com | chcp 65001 |
| w32tm.exe | w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 |
| conhost.exe | |
| Idle.exe | |
| TrustedInstaller.exe | |
| RuntimeBroker.exe | |
| SurrogatesessionRuntimeBrokerDhcp.exe | |
| SurrogatesessionRuntimeBrokerDhcp.exe | |
| SurrogatesessionRuntimeBrokerDhcp.exe | |
| RuntimeBroker.exe | |
| conhost.exe | |
| SurrogatesessionRuntimeBrokerDhcp.exe | |
| Idle.exe | |
| TrustedInstaller.exe | |
| RuntimeBroker.exe | |
| conhost.exe | |
| TrustedInstaller.exe | |
| Idle.exe | |
| SurrogatesessionRuntimeBrokerDhcp.exe | |