🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for sha256_hash 7969ccaf1db750bc3b02d51626d6916ecbd0c0cf2f7de3c7bc0be240f5f2978d.

Database Entry


IOC ID:1892726
IOC: 7969ccaf1db750bc3b02d51626d6916ecbd0c0cf2f7de3c7bc0be240f5f2978d
IOC Type :sha256_hash
Threat Type :payload
Malware: Unknown RAT
Confidence Level : Confidence level is high (90%)
Is compromised? : False
First seen:2026-09-02 05:50:02 UTC
Last seen:never
UUID:1fbbbe83-a661-11f1-b569-42010aa4000a
Reporter Justice_Hammer
Reward 5 credits from ThreatFox
Tags:ComponentTask33 dotNET NodeJS-RAT
Reference: https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md

Avatar
Justice_Hammer
Two unsigned .NET helpers dropped by the ComponentTask33 MSI: ProfileQuickHost.exe (launcher, internal name WinAgent.exe) and SearchTrustedRuntimeSvc.exe (screenshot capture, internal name CaptureScreen.exe). Both are prebuilt and reused across builds, so their MVIDs are a stronger cross-build pivot than either file hash.