Win32.Turla.v1.bin

Classification: Malicious

Win32.Turla.v1.bin is a malicious file sample. Linked to Turla, Oilrig activity. Reported by 3 threat sources, last seen 2026-08-26.

Detection summary

  • 4 antivirus detections (5% detection ratio)
  • 0 IDS alerts
  • 7 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: TURLA (G0010) OILRIG (G0049)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2026-08-09 10:14:29 2026-08-26 10:09:12 malicious-activity
Generic Malware Hybrid-Analysis 2024-09-11 17:15:04 2024-09-11 18:00:06
Turla Maltiverse 2023-03-03 04:26:37 2023-03-04 19:42:06 malicious-activity G0010 Turla
OilRig Maltiverse 2023-03-03 04:26:38 2023-03-04 19:41:51 malicious-activity G0049 OilRig
Backdoor.Agent Hybrid-Analysis 2019-04-13 14:45:03 2019-04-13 14:45:03

Tags

apt apt34 backdoor empire hacktool metasploit meterpreter

Sample information

Filenames
Win32.Turla.v1.bin, download.dat
File type
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Size
206848 bytes
MD5
38abeb8a68e9207da3e6ead88a9682ec
SHA-1
52c8cbd0545caab7596c1382c7fc5a479209851d
SHA-256
454e6c3d8c1c982cd301b4dd82ec3431935c28adea78ed8160d731ab0bed6cb7
First indexed
2019-04-13 14:45:03
Last updated
2024-09-11 18:00:06

Antivirus detections

EngineDetection
ESET-NOD32a variant of Win64/Turla.CB
Paloaltogeneric.ml
RisingBackdoor.Agent!8.C5D (TFE:6:zhtPnHI3bIK)
eGambitTrojan.Generic

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\Win32.Turla.v1.bin.dll",#1
rundll32.exe"C:\Win32.Turla.v1.bin.dll",#2
rundll32.exe%WINDIR%\System32\rundll32.exe "C:\download.dat.dll",#1
rundll32.exe"C:\download.dat.dll",#1
rundll32.exe%WINDIR%\System32\rundll32.exe "C:\download.dat.dll",#2
rundll32.exe"C:\download.dat.dll",#2