8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109
Classification: Malicious
8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109 is a malicious file sample. Linked to Jhuhugit malware. Detected by 52 antivirus engines.
Detection summary
- 52 antivirus detections (75% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-13 10:07:06 |
2026-08-13 10:07:06 |
malicious-activity
|
|
| Trojan.Sofacy |
Hybrid-Analysis |
2020-04-14 13:00:19 |
2020-04-14 13:00:19 |
|
S0044 JHUHUGIT
|
Tags
apt
apt29
cozer
cozybear
cozycar
cozyduke
downloader
dukes
euroapt
exploit
group100
hammertoss
infostealer
minidionis
officemonkeys
qakbot
seaduke
thedukes
x-agent
xagent
zemot
Sample information
- Filenames
- 8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109
- File type
- PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
- Size
- 99328 bytes
- MD5
07c8a0a792a5447daf08ac32d1e283e8
- SHA-1
99f927f97838eb47c1d59500ee9155adb55b806a
- SHA-256
8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109
- First indexed
- 2020-04-14 13:00:19
- Last updated
- 2025-10-12 10:55:57
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Trojan.Agent.BNQN |
| FireEye | Generic.mg.07c8a0a792a5447d |
| McAfee | Artemis!07C8A0A792A5 |
| Zillya | Trojan.Sednit.Win32.14 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | Trojan:Win32/Sofacy.a60d1539 |
| K7GW | Riskware ( 0040eff71 ) |
| K7AntiVirus | Riskware ( 0040eff71 ) |
| Arcabit | Trojan.Agent.BNQN |
| Invincea | heuristic |
| Symantec | Trojan.Sofacy |
| APEX | Malicious |
| ClamAV | Win.Malware.Sofacy-7 |
| Kaspersky | Trojan.Win32.Sofacy.bq |
| BitDefender | Trojan.Agent.BNQN |
| NANO-Antivirus | Trojan.Win32.Sofacy.dyjvhj |
| Paloalto | generic.ml |
| AegisLab | Trojan.Win32.Sofacy.4!c |
| Ad-Aware | Trojan.Agent.BNQN |
| Sophos | Troj/Foosace-C |
| Comodo | Malware@#g0nsxqo660vu |
| DrWeb | Trojan.Coreshell.23 |
| VIPRE | Trojan.Win32.Generic!BT |
| TrendMicro | TROJ_SEDNIT.WWP |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.nh |
| Fortinet | W32/Sofacy.BQ!tr |
| Trapmine | suspicious.low.ml.score |
| Emsisoft | Trojan.Agent.BNQN (B) |
| SentinelOne | DFI - Malicious PE |
| Jiangmin | Trojan.Sofacy.d |
| Webroot | W32.Trojan.Agent.Gen |
| MAX | malware (ai score=100) |
| Antiy-AVL | Trojan/Win32.Sofacy |
| Endgame | malicious (high confidence) |
| Microsoft | Trojan:Win32/Foosace!dha |
| ViRobot | Trojan.Win32.S.Sofacy.99328 |
| ZoneAlarm | Trojan.Win32.Sofacy.bq |
| AhnLab-V3 | Trojan/Win32.Sofacy.C1121436 |
| Acronis | suspicious |
| VBA32 | Trojan.Sofacy |
| ALYac | Trojan.Agent.BNQN |
| Cylance | Unsafe |
| ESET-NOD32 | Win32/Sednit.AB |
| TrendMicro-HouseCall | TROJ_SEDNIT.WWP |
| Rising | Trojan.Sednit!8.632 (TFE:5:Adv4aLApL4V) |
| Yandex | Trojan.Sofacy! |
| Ikarus | Trojan.Win32.Sofacy |
| eGambit | Trojan.Generic |
| GData | Trojan.Agent.BNQN |
| AVG | FileRepMetagen [Malware] |
| Panda | Generic Suspicious |
| Qihoo-360 | HEUR/QVM30.1.Malware.Gen |
Process list
| Name | Command line |
| rundll32.exe | "C:\8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109.dll",#1 |