Classification: Malicious
atiagentCozyBear.bin is a malicious file sample. Linked to Apt29 activity. Reported by 2 threat sources, last seen 2026-05-14.
Detection summary
- 21 antivirus detections (31% detection ratio)
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2024-10-22 02:00:04 |
2026-05-14 18:45:03 |
|
|
| Apt 29 |
Maltiverse |
2023-08-19 05:15:31 |
2023-08-20 21:20:24 |
malicious-activity
|
G0016 APT29
|
| Gen:Variant.Zusy |
Hybrid-Analysis |
2018-05-22 13:30:26 |
2018-05-22 13:30:26 |
|
|
Sample information
- Filenames
- atiagentCozyBear.bin, 43cd9ef6904c35c6854bf59d99731a05048af9e870261064a255db0181930fad
- File type
- PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
- Size
- 53768 bytes
- MD5
452ee2968ec82c7e30c21c828b330c17
- SHA-1
00384c359e2931fb922b034fca2707e1b2a25396
- SHA-256
43cd9ef6904c35c6854bf59d99731a05048af9e870261064a255db0181930fad
- SHA-512
bef788d69d8d75579cbf6499b4c2aec7c413cc56fea2a51efc4dc7742f52648fff3b64b78b3d8544d81ee473472521d352f931b56564a88031c5116444b65926
- First indexed
- 2018-05-22 13:30:26
- Last updated
- 2026-05-14 18:45:04
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Gen:Variant.Zusy.284644 |
| ALYac | Gen:Variant.Zusy.284644 |
| Arcabit | Trojan.Zusy.D457E4 |
| Symantec | Trojan.Cozer!gen3 |
| BitDefender | Gen:Variant.Zusy.284644 |
| Avast | Win32:CozyDuke-D [Trj] |
| Ad-Aware | Gen:Variant.Zusy.284644 |
| Emsisoft | Gen:Variant.Zusy.284644 (B) |
| F-Secure | Gen:Variant.Zusy.284644 |
| McAfee-GW-Edition | Trojan-FFPR!452EE2968EC8 |
| Sophos | Troj/Cozer-B |
| Microsoft | Trojan:Win32/Cozer.gen.A!dha |
| Endgame | malicious (moderate confidence) |
| GData | Gen:Variant.Zusy.284644 |
| AhnLab-V3 | Trojan/Win32.HDC.C804097 |
| McAfee | Trojan-FFPR!452EE2968EC8 |
| MAX | malware (ai score=88) |
| ESET-NOD32 | a variant of Win32/Cozer.E |
| AVG | Win32:CozyDuke-D [Trj] |
| Panda | Trj/Genetic.gen |
| Qihoo-360 | HEUR/QVM30.1.54A4.Malware.Gen |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\atiagentCozyBear.bin.dll",#1 |
| regsvr32.exe | /s "C:\atiagentCozyBear.bin.dll" |
| rundll32.exe | "C:\atiagentCozyBear.bin.dll",#3 |
| rundll32.exe | "C:\atiagentCozyBear.bin.dll",#4 |