🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 9fa80577b8b3cb9c3062e5e1986cc9fe0c26eed023f7d430dfa5c60169c15c45.

Database Entry


IOC ID:1892725
IOC: 9fa80577b8b3cb9c3062e5e1986cc9fe0c26eed023f7d430dfa5c60169c15c45
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown RAT
Confidence Level : Confidence level is high (90%)
Is compromised? : False
First seen:2026-09-02 05:49:45 UTC
Last seen:never
UUID:1fb29844-a661-11f1-b569-42010aa4000a
Reporter Justice_Hammer
Reward 5 credits from ThreatFox
Tags:ComponentTask33 dotNET NodeJS-RAT
Reference: https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md

Avatar
Justice_Hammer
Two unsigned .NET helpers dropped by the ComponentTask33 MSI: ProfileQuickHost.exe (launcher, internal name WinAgent.exe) and SearchTrustedRuntimeSvc.exe (screenshot capture, internal name CaptureScreen.exe). Both are prebuilt and reused across builds, so their MVIDs are a stronger cross-build pivot than either file hash.