381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin

Classification: Malicious

381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin is a malicious file sample. Linked to Apt29 activity. Detected by 39 antivirus engines.

Detection summary

  • 39 antivirus detections (73% detection ratio)
  • 1 IDS alerts
  • 2 processes observed
  • 1 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Intrusion sets: APT29 (G0016)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-06-03 01:15:03 2023-06-03 01:15:03
Unknown malware ThreatFox Abuse.ch 2023-04-13 14:20:08 2023-04-13 15:17:45
Generic.Malware MalwareBazaar Abuse.ch 2023-03-06 10:56:28 2023-03-06 10:56:28
Apt 29 Maltiverse 2023-02-02 09:39:01 2023-02-03 08:32:01 malicious-activity G0016 APT29

Tags

unknown apt

Sample information

Filenames
381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.bin, 381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c
File type
PE32+ executable (DLL) (GUI) x86-64 (stripped to e ...
Size
270336 bytes
MD5
d0efe94196b4923eb644ec0b53d226cc
SHA-1
c938934c0f5304541087313382aee163e0c5239c
SHA-256
381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c
First indexed
2023-02-03 08:32:01
Last updated
2026-04-13 10:23:00

Antivirus detections

EngineDetection
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader45.39488
MicroWorld-eScanTrojan.Generic.33168950
McAfeeArtemis!D0EFE94196B4
CylanceUnsafe
VIPRETrojan.Generic.33168950
K7AntiVirusTrojan-Downloader ( 0059e5bb1 )
K7GWTrojan-Downloader ( 0059e5bb1 )
CyrenW64/ABRisk.YGIE-6692
SymantecTrojan Horse
ESET-NOD32a variant of Win64/TrojanDownloader.Dukes.A
CynetMalicious (score: 100)
KasperskyTrojan.Win64.Agent.qwidkb
BitDefenderTrojan.Generic.33168950
AvastWin64:DropperX-gen [Drp]
TencentWin64.Trojan.Agent.Gdhl
EmsisoftTrojan.Generic.33168950 (B)
F-SecureTrojan.TR/Agent.dbmru
TrendMicroTROJ_FRS.VSNTAU23
McAfee-GW-EditionArtemis
FireEyeTrojan.Generic.33168950
SophosMal/Generic-S
GDataTrojan.Generic.33168950
AviraTR/Agent.dbmru
Antiy-AVLTrojan/Win64.Agent
ArcabitTrojan.Generic.D1FA1E36
ZoneAlarmTrojan.Win64.Agent.qwidkb
MicrosoftTrojan:Win64/Malagent!MSR
GoogleDetected
AhnLab-V3Trojan/Win.DropperX-gen.C5371404
ALYacTrojan.Generic.33168950
MAXmalware (ai score=86)
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_FRS.VSNTAU23
RisingDownloader.Dukes!8.172C6 (CLOUD)
FortinetW64/Dukes.A!tr.dldr
AVGWin64:DropperX-gen [Drp]
PandaTrj/Chgt.AD

Network contacts

172.64.145.157

DNS requests

api.notion.com

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\381a3c6c7e119f58dfde6f03a9890353a20badfa1bfa7c38ede62c6b0692103c.dll",#1