381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin
Classification: Malicious
381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin is a malicious file sample. Linked to Apt29 activity. Detected by 39 antivirus engines.
Detection summary
- 39 antivirus detections (73% detection ratio)
- 1 IDS alerts
- 2 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-06-03 01:15:03 |
2023-06-03 01:15:03 |
|
|
| Unknown malware |
ThreatFox Abuse.ch |
2023-04-13 14:20:08 |
2023-04-13 15:17:45 |
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2023-03-06 10:56:28 |
2023-03-06 10:56:28 |
|
|
| Apt 29 |
Maltiverse |
2023-02-02 09:39:01 |
2023-02-03 08:32:01 |
malicious-activity
|
G0016 APT29
|
Sample information
- Filenames
- 381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin, 381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c
- File type
- PE32+ executable (DLL) (GUI) x86-64 (stripped to e ...
- Size
- 270336 bytes
- MD5
d0efe94196b4923eb644ec0b53d226cc
- SHA-1
c938934c0f5304541087313382aee163e0c5239c
- SHA-256
381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c
- First indexed
- 2023-02-03 08:32:01
- Last updated
- 2026-04-13 10:23:00
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.Win32.Agent.Y!c |
| Elastic | malicious (high confidence) |
| DrWeb | Trojan.DownLoader45.39488 |
| MicroWorld-eScan | Trojan.Generic.33168950 |
| McAfee | Artemis!D0EFE94196B4 |
| Cylance | Unsafe |
| VIPRE | Trojan.Generic.33168950 |
| K7AntiVirus | Trojan-Downloader ( 0059e5bb1 ) |
| K7GW | Trojan-Downloader ( 0059e5bb1 ) |
| Cyren | W64/ABRisk.YGIE-6692 |
| Symantec | Trojan Horse |
| ESET-NOD32 | a variant of Win64/TrojanDownloader.Dukes.A |
| Cynet | Malicious (score: 100) |
| Kaspersky | Trojan.Win64.Agent.qwidkb |
| BitDefender | Trojan.Generic.33168950 |
| Avast | Win64:DropperX-gen [Drp] |
| Tencent | Win64.Trojan.Agent.Gdhl |
| Emsisoft | Trojan.Generic.33168950 (B) |
| F-Secure | Trojan.TR/Agent.dbmru |
| TrendMicro | TROJ_FRS.VSNTAU23 |
| McAfee-GW-Edition | Artemis |
| FireEye | Trojan.Generic.33168950 |
| Sophos | Mal/Generic-S |
| GData | Trojan.Generic.33168950 |
| Avira | TR/Agent.dbmru |
| Antiy-AVL | Trojan/Win64.Agent |
| Arcabit | Trojan.Generic.D1FA1E36 |
| ZoneAlarm | Trojan.Win64.Agent.qwidkb |
| Microsoft | Trojan:Win64/Malagent!MSR |
| Google | Detected |
| AhnLab-V3 | Trojan/Win.DropperX-gen.C5371404 |
| ALYac | Trojan.Generic.33168950 |
| MAX | malware (ai score=86) |
| Malwarebytes | Trojan.Downloader |
| TrendMicro-HouseCall | TROJ_FRS.VSNTAU23 |
| Rising | Downloader.Dukes!8.172C6 (CLOUD) |
| Fortinet | W64/Dukes.A!tr.dldr |
| AVG | Win64:DropperX-gen [Drp] |
| Panda | Trj/Chgt.AD |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.dll",#1 |