8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109

Classification: Malicious

8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109 is a malicious file sample. Linked to Jhuhugit malware. Detected by 52 antivirus engines.

Detection summary

  • 52 antivirus detections (75% detection ratio)
  • 0 IDS alerts
  • 1 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: JHUHUGIT (S0044)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2026-08-13 10:07:06 2026-08-13 10:07:06 malicious-activity
Trojan.Sofacy Hybrid-Analysis 2020-04-14 13:00:19 2020-04-14 13:00:19 S0044 JHUHUGIT

Tags

apt apt29 cozer cozybear cozycar cozyduke downloader dukes euroapt exploit group100 hammertoss infostealer minidionis officemonkeys qakbot seaduke thedukes x-agent xagent zemot

Sample information

Filenames
8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
Size
99328 bytes
MD5
07c8a0a792a5447daf08ac32d1e283e8
SHA-1
99f927f97838eb47c1d59500ee9155adb55b806a
SHA-256
8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109
First indexed
2020-04-14 13:00:19
Last updated
2025-10-12 10:55:57

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.Agent.BNQN
FireEyeGeneric.mg.07c8a0a792a5447d
McAfeeArtemis!07C8A0A792A5
ZillyaTrojan.Sednit.Win32.14
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Sofacy.a60d1539
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Agent.BNQN
Invinceaheuristic
SymantecTrojan.Sofacy
APEXMalicious
ClamAVWin.Malware.Sofacy-7
KasperskyTrojan.Win32.Sofacy.bq
BitDefenderTrojan.Agent.BNQN
NANO-AntivirusTrojan.Win32.Sofacy.dyjvhj
Paloaltogeneric.ml
AegisLabTrojan.Win32.Sofacy.4!c
Ad-AwareTrojan.Agent.BNQN
SophosTroj/Foosace-C
ComodoMalware@#g0nsxqo660vu
DrWebTrojan.Coreshell.23
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SEDNIT.WWP
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FortinetW32/Sofacy.BQ!tr
Trapminesuspicious.low.ml.score
EmsisoftTrojan.Agent.BNQN (B)
SentinelOneDFI - Malicious PE
JiangminTrojan.Sofacy.d
WebrootW32.Trojan.Agent.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Sofacy
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Foosace!dha
ViRobotTrojan.Win32.S.Sofacy.99328
ZoneAlarmTrojan.Win32.Sofacy.bq
AhnLab-V3Trojan/Win32.Sofacy.C1121436
Acronissuspicious
VBA32Trojan.Sofacy
ALYacTrojan.Agent.BNQN
CylanceUnsafe
ESET-NOD32Win32/Sednit.AB
TrendMicro-HouseCallTROJ_SEDNIT.WWP
RisingTrojan.Sednit!8.632 (TFE:5:Adv4aLApL4V)
YandexTrojan.Sofacy!
IkarusTrojan.Win32.Sofacy
eGambitTrojan.Generic
GDataTrojan.Agent.BNQN
AVGFileRepMetagen [Malware]
PandaGeneric Suspicious
Qihoo-360HEUR/QVM30.1.Malware.Gen

Process list

NameCommand line
rundll32.exe"C:\8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109.dll",#1