Classification: Malicious
Win32.Turla.v1.bin is a malicious file sample. Linked to Turla, Oilrig activity. Reported by 3 threat sources, last seen 2026-08-26.
Detection summary
- 4 antivirus detections (5% detection ratio)
- 0 IDS alerts
- 7 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-09 10:14:29 |
2026-08-26 10:09:12 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2024-09-11 17:15:04 |
2024-09-11 18:00:06 |
|
|
| Turla |
Maltiverse |
2023-03-03 04:26:37 |
2023-03-04 19:42:06 |
malicious-activity
|
G0010 Turla
|
| OilRig |
Maltiverse |
2023-03-03 04:26:38 |
2023-03-04 19:41:51 |
malicious-activity
|
G0049 OilRig
|
| Backdoor.Agent |
Hybrid-Analysis |
2019-04-13 14:45:03 |
2019-04-13 14:45:03 |
|
|
Tags
apt
apt34
backdoor
empire
hacktool
metasploit
meterpreter
Sample information
- Filenames
- Win32.Turla.v1.bin, download.dat
- File type
- PE32+ executable (DLL) (GUI) x86-64, for MS Windows
- Size
- 206848 bytes
- MD5
38abeb8a68e9207da3e6ead88a9682ec
- SHA-1
52c8cbd0545caab7596c1382c7fc5a479209851d
- SHA-256
454e6c3d8c1c982cd301b4dd82ec3431935c28adea78ed8160d731ab0bed6cb7
- First indexed
- 2019-04-13 14:45:03
- Last updated
- 2024-09-11 18:00:06
Antivirus detections
| Engine | Detection |
| ESET-NOD32 | a variant of Win64/Turla.CB |
| Paloalto | generic.ml |
| Rising | Backdoor.Agent!8.C5D (TFE:6:zhtPnHI3bIK) |
| eGambit | Trojan.Generic |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\Win32.Turla.v1.bin.dll",#1 |
| rundll32.exe | "C:\Win32.Turla.v1.bin.dll",#2 |
| rundll32.exe | %WINDIR%\System32\rundll32.exe "C:\download.dat.dll",#1 |
| rundll32.exe | "C:\download.dat.dll",#1 |
| rundll32.exe | %WINDIR%\System32\rundll32.exe "C:\download.dat.dll",#2 |
| rundll32.exe | "C:\download.dat.dll",#2 |