Classification: Malicious
audio is a malicious file sample. Linked to Daggerfly activity. Reported by 3 threat sources, last seen 2026-08-08. Detected by 52 antivirus engines.
Detection summary
- 52 antivirus detections (64% detection ratio)
- 0 IDS alerts
- 3 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-08 10:17:51 |
2026-08-08 10:17:51 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2023-05-22 08:00:03 |
2023-05-22 08:00:03 |
|
|
| Bronze Highland |
Maltiverse |
2023-04-21 04:32:47 |
2023-04-22 14:55:19 |
malicious-activity
|
G1034 Daggerfly
|
Tags
backdoor
keylogger
panda
plugx
apt
Sample information
- Filenames
- audio
- File type
- PE32 executable (DLL) (console) Intel 80386, for M ...
- Size
- 124416 bytes
- MD5
07df8d223f8a370cd703d177d7e93a36
- SHA-1
9d1ecbbe8637fed0d89fca1af35ea821277ad2e8
- SHA-256
2c0cfe2f4f1e7539b4700e1205411ec084cbc574f9e4710ecd4733fbf0f8a7dc
- First indexed
- 2023-04-22 14:55:19
- Last updated
- 2025-10-21 00:13:06
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Agent.MgBot |
| AVG | Win32:Trojan-gen |
| AhnLab-V3 | Trojan/Win.Agent.C5418978 |
| Alibaba | Trojan:Win32/MgBot.edb0b31a |
| Arcabit | Trojan.Fragtor.D407F9 |
| Avast | Win32:Trojan-gen |
| Avira | TR/Agent.hgdbj |
| BitDefender | Gen:Variant.Fragtor.264185 |
| Bkav | W32.Common.69C1B03A |
| CAT-QuickHeal | Trojan.Ghanarava.1733891334e93a36 |
| CTX | dll.trojan.generic |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen20.43765 |
| ESET-NOD32 | Win32/Agent.VFT |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Gen:Variant.Fragtor.264185 (B) |
| F-Secure | Trojan.TR/Agent.hgdbj |
| Fortinet | W32/Agent.VFT!tr |
| GData | Gen:Variant.Fragtor.264185 |
| Google | Detected |
| Gridinsoft | Trojan.Win32.Agent.oa!s1 |
| Ikarus | Trojan.Win32.Agent |
| K7AntiVirus | Trojan ( 004986881 ) |
| K7GW | Trojan ( 004986881 ) |
| Kaspersky | Trojan.Win32.MgBot.a |
| Lionic | Trojan.Win32.MgBot.4!c |
| Malwarebytes | Malware.AI.4270901185 |
| MaxSecure | Trojan.Malware.206623782.susgen |
| McAfeeD | ti!2C0CFE2F4F1E |
| MicroWorld-eScan | Gen:Variant.Fragtor.264185 |
| Microsoft | Trojan:Win32/Agent.VFT |
| NANO-Antivirus | Trojan.Win32.MgBot.jwielw |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Trojan.Agent!8.B1E (KTSE) |
| Sangfor | Trojan.Win32.Mgbot.Vm98 |
| Skyhigh | BehavesLike.Win32.Injector.ch |
| Sophos | Mal/Generic-S |
| Symantec | Trojan Horse |
| Tencent | Malware.Win32.Gencirc.13ae87ca |
| TrellixENS | Artemis!07DF8D223F8A |
| TrendMicro | Trojan.Win32.MGBOT.USBLBS24 |
| TrendMicro-HouseCall | Trojan.Win32.MGBOT.USBLBS24 |
| VIPRE | Gen:Variant.Fragtor.264185 |
| Varist | W32/Agent.NOMD-3990 |
| Yandex | Trojan.MgBot!/xDD8FWKQcw |
| Zillya | Trojan.MgBot.Win32.1 |
| alibabacloud | Trojan:Win/Agent.V#B |
| huorong | Trojan/Generic!29120668FDFF0EB1 |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\audio.dll",#1 |
| rundll32.exe | "C:\audio.dll",#2 |