Verdict
- MALWAREBAZAAR_MATCH MalwareBazaar has the sample.
- VT_HIGH_DETECTION_RATIO 30% or more of VirusTotal vendors flag the indicator.
- MULTIPLE_CORROBORATING_SOURCES Two or more independent source families agree.
Key indicators
- SHA256
- 99fd9e75e6241eff30e01c5b59df9e901fb24d12bee89c069cc6158f78b3cc98
- SHA1
- fc09dd898b6e7ff546e4a7517a715928fbafc297
- MD5
- 3f4f5a6cb95047fea6102bd7d2226aa9
- File name
- winserv.exe
- File type
- exe
- Signature
- Not signed
- Family
- RemoteManipulator
- First submitted
- 2019-07-17
- First seen
- 2019-07-17 (2631 days before · VirusTotal)
- Last seen
- 2026-09-28 (1 day before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Sample catalogued as RemoteManipulator, submitted 221 days ago. | — | 221 days old | Strong | |
| 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.jaik/remoteutilities. Win32 EXE file; vendors name it jaik, remoteutilities. Sandboxes: 4 of 5 sandboxes: malicious. | 58/75 | 1 day recent | Strong | |
| Referenced in 4 community pulses, which are unverified. | — | — | Neutral |
Coverage · checked, no record: ThreatFox, Code signature, CIRCL hashlookup · failed: none
Analyst summary
Consistent with engineMalicious, high confidence. 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.jaik/remoteutilities. Win32 EXE file; vendors name it jaik, remoteutilities. Sandboxes: 4 of 5 sandboxes: malicious. Independent sources corroborate it.
Why the evidence points to malicious
- [VirusTotal] 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.jaik/remoteutilities. Win32 EXE file; vendors name it jaik, remoteutilities. Sandboxes: 4 of 5 sandboxes: malicious.
- [MalwareBazaar] Sample catalogued as RemoteManipulator, submitted 221 days ago.
Attribution
Links the indicator to RemoteManipulator activity; this does not identify a specific threat actor or implicate the hosting provider.
All evidence
6 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Sample catalogued as RemoteManipulator, submitted 221 days ago. | — | 221 days old | Strong | |
| 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.jaik/remoteutilities. Win32 EXE file; vendors name it jaik, remoteutilities. Sandboxes: 4 of 5 sandboxes: malicious. | 58/75 | 1 day recent | Strong | |
| Referenced in 4 community pulses, which are unverified. | — | — | Neutral | |
| No record. | — | — | No record | |
| Code signature | No record. | — | — | No record |
| No record. | — | — | No record |
Engine rules applied
- HASH_NOT_TIME_DECAYEDFile-hash evidence does not decay: an old analysis date does not make a file benign.
- MALWAREBAZAAR_MATCHMalwareBazaar has the sample.
- VT_HIGH_DETECTION_RATIO30% or more of VirusTotal vendors flag the indicator.
- MULTIPLE_CORROBORATING_SOURCESTwo or more independent source families agree.
Analyst summary
Consistent with engineMalicious, high confidence. 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.jaik/remoteutilities. Win32 EXE file; vendors name it jaik, remoteutilities. Sandboxes: 4 of 5 sandboxes: malicious. Independent sources corroborate it.
Why the evidence points to malicious
- [VirusTotal] 58/75 vendors (77.3%) flag it: strong multi-vendor detection; label trojan.jaik/remoteutilities. Win32 EXE file; vendors name it jaik, remoteutilities. Sandboxes: 4 of 5 sandboxes: malicious.
- [MalwareBazaar] Sample catalogued as RemoteManipulator, submitted 221 days ago.
Attribution
Links the indicator to RemoteManipulator activity; this does not identify a specific threat actor or implicate the hosting provider.
Key indicators
- SHA256
- 99fd9e75e6241eff30e01c5b59df9e901fb24d12bee89c069cc6158f78b3cc98
- SHA1
- fc09dd898b6e7ff546e4a7517a715928fbafc297
- MD5
- 3f4f5a6cb95047fea6102bd7d2226aa9
- File name
- winserv.exe
- File type
- exe
- Signature
- Not signed
- Family
- RemoteManipulator
- First submitted
- 2019-07-17
- First seen
- 2019-07-17 (2631 days before · VirusTotal)
- Last seen
- 2026-09-28 (1 day before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
Attribution
Links the indicator to RemoteManipulator activity; this does not identify a specific threat actor or implicate the hosting provider.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
Evidence timeline
- 2026-02-20MalwareBazaar: Sample catalogued as RemoteManipulator, submitted 221 days ago
- 2026-09-28VirusTotal: 58/75 vendors (77.3%) flag it: strong multi-vendor detection
- 2026-09-29Investigated
Recommended next steps
- huntSearch EDR for 99fd9e75e624... across all endpoints.
- enrichPull RemoteManipulator C2 indicators from ThreatFox and check network logs for them.
- blockAdd the hash to the EDR blocklist.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

