6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa
Classification: Malicious
6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa is a malicious file sample. Linked to Backdoordiplomacy, Ke3Chang activity.
Detection summary
- 0 antivirus detections
- 0 IDS alerts
- 14 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: BACKDOORDIPLOMACY (G0135) KE3CHANG (G0004)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Cyber Threat Alliance | 2026-08-14 10:19:44 | 2026-08-14 10:19:44 | malicious-activity | |
| Generic Malware | Hybrid-Analysis | 2025-09-30 07:22:33 | 2025-09-30 08:15:30 | ||
| Mirage | Maltiverse | 2023-01-20 04:14:49 | 2023-01-21 18:46:08 | malicious-activity | G0004 Ke3chang |
| Backdoordiplomacy | Maltiverse | 2023-01-20 04:14:49 | 2023-01-21 18:46:06 | malicious-activity | G0135 BackdoorDiplomacy |
Tags
aptSample information
- Filenames
- 6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa
- File type
- PE32+ executable for MS Windows 6.00 (DLL), x86-64 ...
- Size
- 121856 bytes
- MD5
008a71c9a5167985ae6fedd63a50a902- SHA-1
540e50b57b648df5e91f7e09df4c2e0e0177c668- SHA-256
6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa- First indexed
- 2023-01-21 18:46:06
- Last updated
- 2025-09-30 08:15:30
Process list
| Name | Command line |
|---|---|
| <Ignored Process> | |
| rundll32.exe | "C:\6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa.dll",#1 |
| rundll32.exe | "C:\6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa.dll",#2 |
| cmd.exe | /c ""C:\tmp.bat" " |
| reg.exe | ReG aDd hKEy_LOcAl_MaChiNE\SYsTEm\CuRRenTCoNTRolSeT\SeRViCeS\AppMgmt\pARamEteRs /v ServiceDll /t REG_EXPAND_SZ /d "C:\6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa.dll" /f |
| reg.exe | ReG aDd hKEy_LOcAl_MaChiNE\SYsTEm\CuRRenTCoNTRolSeT\SeRViCeS\AppMgmt /v Start /t REG_DWORD /d 2 /f |
| reg.exe | ReG dELete hKEy_LOcAl_MaChiNE\SYsTEm\CuRRenTCoNTRolSeT\SeRViCeS\AppMgmt\pARamEteRs /v ServiceDllUnloadOnStop /f |
| net.exe | net start AppMgmt |
| net1.exe | %WINDIR%\system32\net1 start AppMgmt |
| rundll32.exe | "C:\6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa.dll",#3 |
| cmd.exe | /c ""C:\tmp.bat" " |
| reg.exe | ReG aDd hKEy_LOcAl_MaChiNE\SYsTEm\CuRRenTCoNTRolSeT\SeRViCeS\AppMgmt\pARamEteRs /v ServiceDll /t REG_EXPAND_SZ /d "C:\6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa.dll" /f |
| reg.exe | ReG aDd hKEy_LOcAl_MaChiNE\SYsTEm\CuRRenTCoNTRolSeT\SeRViCeS\AppMgmt /v Start /t REG_DWORD /d 2 /f |
| reg.exe | ReG dELete hKEy_LOcAl_MaChiNE\SYsTEm\CuRRenTCoNTRolSeT\SeRViCeS\AppMgmt\pARamEteRs /v ServiceDllUnloadOnStop /f |