bd7d85741a3801d8fe7a725061249337.exe
Classification: Malicious
bd7d85741a3801d8fe7a725061249337.exe is a malicious file sample. Linked to Kazuar malware. Reported by 3 threat sources, last seen 2026-05-14.
Detection summary
- 45 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 8 contacted hosts
- 9 DNS requests
MITRE ATT&CK associations
Malware families: KAZUAR (S0265)
Intrusion sets: TURLA (G0010)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-05-14 11:45:04 | 2026-05-14 11:45:04 | ||
| Kazuar | MalwareBazaar Abuse.ch | 2026-05-14 10:39:08 | 2026-05-14 10:39:08 | malicious-activity | S0265 Kazuar |
| Turla | MalwarePatrol | 2026-03-03 18:13:59 | 2026-03-03 18:13:59 | malicious-activity | G0010 Turla |
Tags
turla pfinet tag_0530 snake pacifier apt makersmark uroburos venomous bear waterbug iron hunter itg12 krypton group 88 g0010 blue python sig23 atk13 hippo team popeyeSample information
- Filenames
- bd7d85741a3801d8fe7a725061249337.exe, 6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d.bin
- File type
- PE32 executable for MS Windows 4.00 (GUI), Intel i ...
- MD5
bd7d85741a3801d8fe7a725061249337- SHA-1
fb5eb1cad3444d7a1647bb906fff3200d8a707f3- SHA-256
6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d- First indexed
- 2026-03-03 18:13:59
- Last updated
- 2026-05-19 14:56:59
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Backdoor.MSIL.Kazuar |
| APEX | Malicious |
| AhnLab-V3 | Trojan/Win.Generic.C5884131 |
| Alibaba | Backdoor:MSIL/KazuarModule.32fb5bde |
| Antiy-AVL | Trojan/MSIL.Turla |
| Arcabit | Trojan.Turla.1 |
| Avira | TR/W32.Agent |
| CAT-QuickHeal | Trojan.MSIL |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | MSIL/Turla.Y trojan |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Trojan.Turla.1 (B) |
| F-Secure | Trojan.TR/W32.Agent |
| GData | Trojan.Turla.1 |
| Detected | |
| Ikarus | Trojan.MSIL.Turla |
| K7AntiVirus | Backdoor ( 006dfced1 ) |
| K7GW | Backdoor ( 006dfced1 ) |
| Kingsoft | MSIL.Trojan.Kazuar.gen |
| Lionic | Trojan.Win32.Turla.4!c |
| Malwarebytes | Malware.AI.4291917544 |
| MaxSecure | Trojan.Malware.684672969.susgen |
| McAfeeD | ti!6EB31006CA31 |
| MicroWorld-eScan | Trojan.Turla.1 |
| Microsoft | Backdoor:MSIL/KazuarModule.A!dha |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Trojan.Turla!8.1C8 (CLOUD) |
| SentinelOne | Static AI - Suspicious PE |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Gen.MBT |
| Tencent | Msil.Trojan.Kazuar.Fkjl |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | Artemis!BD7D85741A38 |
| TrendMicro | TROJ_GEN.R023C0DEE26 |
| TrendMicro-HouseCall | Trojan.MSIL.KAZUARLOADER.A |
| VBA32 | Trojan.MSIL.Agent |
| VIPRE | Trojan.Turla.1 |
| Varist | W32/ABTrojan.XKCX-7530 |
| VirIT | Trojan.Win32.MSIL.JQO |
| ZoneAlarm | Troj/MSIL-TKO |
| alibabacloud | Backdoor:MSIL/Turla.Y |
Network contacts
184.25.113.153 151.101.1.44 150.171.22.12 104.254.148.252 142.251.218.234 150.171.109.185 142.251.218.193 99.84.160.78
DNS requests
clients2.googleusercontent.com edge-consumer-static.azureedge.net ib.adnxs.com m.adnxs.com px.ads.linkedin.com r.msftstatic.com sb.scorecardresearch.com trc.taboola.com www.googleapis.com