436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85
Classification: Malicious
436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85 is a malicious file sample. Linked to Kazuar malware. Detected by 49 antivirus engines.
Detection summary
- 49 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: KAZUAR (S0265)
Intrusion sets: TURLA (G0010)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-06-03 07:45:04 | 2026-06-03 07:45:04 | ||
| Kazuar | MalwareBazaar Abuse.ch | 2026-05-19 10:49:02 | 2026-05-19 10:49:02 | malicious-activity | S0265 Kazuar |
| Turla | MalwarePatrol | 2026-03-03 18:13:57 | 2026-03-03 18:13:57 | malicious-activity | G0010 Turla |
Tags
turla pfinet tag_0530 snake pacifier apt makersmark uroburos venomous bear waterbug iron hunter itg12 krypton group 88 g0010 blue python sig23 atk13 hippo team popeye evasiveSample information
- Filenames
- 436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85, 436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85.bin
- File type
- PE32 executable for MS Windows 4.00 (GUI), Intel i ...
- MD5
035e952a9504894fb311aef75ab64aec- SHA-1
78db2202722f8c5afd7ee135e620908d99bc3d55- SHA-256
436cfce71290c2fc2f2c362541db68ced6847c66a73b55487e5e5c73b0636c85- First indexed
- 2026-03-03 18:13:57
- Last updated
- 2026-06-03 07:45:04
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Backdoor.MSIL.Kazuar |
| APEX | Malicious |
| AVG | Win32:MalwareX-gen [Misc] |
| AhnLab-V3 | Trojan/Win.Generic.C5882680 |
| Alibaba | Backdoor:MSIL/KazuarModule.f317b5af |
| Antiy-AVL | Trojan/MSIL.Kazuar |
| Arcabit | Trojan.Turla.4 |
| Avast | Win32:MalwareX-gen [Misc] |
| Avira | TR/W32.Agent |
| BitDefender | Trojan.Turla.4 |
| Bkav | W32.Malware.7B36146E |
| CAT-QuickHeal | Backdoor.Kazuarmodule |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | MSIL/Turla.Y trojan |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Trojan.Turla.4 (B) |
| F-Secure | Trojan.TR/W32.Agent |
| Fortinet | MSIL/Turla.Y!tr |
| GData | Trojan.Turla.4 |
| Detected | |
| Ikarus | Trojan.MSIL.Turla |
| K7AntiVirus | Backdoor ( 006dfced1 ) |
| K7GW | Backdoor ( 006dfced1 ) |
| Kaspersky | HEUR:Trojan.MSIL.Kazuar.gen |
| Kingsoft | MSIL.Backdoor.KazuarModule.v |
| Lionic | Trojan.Win32.Turla.4!c |
| Malwarebytes | Malware.AI.1621830304 |
| MaxSecure | Trojan.Malware.684672969.susgen |
| McAfeeD | ti!436CFCE71290 |
| MicroWorld-eScan | Trojan.Turla.4 |
| Microsoft | Backdoor:MSIL/KazuarModule.A!dha |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Rising | Trojan.Turla!8.1C8 (CLOUD) |
| Sangfor | Backdoor.Msil.Turla.Vm0a |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Gen.MBT |
| Tencent | Msil.Trojan.Kazuar.Xmhl |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | Artemis!035E952A9504 |
| TrendMicro | Trojan.Win32.ZYX.USBLEC26 |
| TrendMicro-HouseCall | Trojan.Win32.ZYX.USBLEC26 |
| VIPRE | Trojan.Turla.4 |
| Varist | W32/ABTrojan.AKUN-4990 |
| ZoneAlarm | Troj/MSIL-TKO |
| alibabacloud | Backdoor:MSIL/Turla.Y |