bd7d85741a3801d8fe7a725061249337.exe

Classification: Malicious

bd7d85741a3801d8fe7a725061249337.exe is a malicious file sample. Linked to Kazuar malware. Reported by 3 threat sources, last seen 2026-05-14.

Detection summary

  • 45 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 8 contacted hosts
  • 9 DNS requests

MITRE ATT&CK associations

Malware families: KAZUAR (S0265)

Intrusion sets: TURLA (G0010)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2026-05-14 11:45:04 2026-05-14 11:45:04
Kazuar MalwareBazaar Abuse.ch 2026-05-14 10:39:08 2026-05-14 10:39:08 malicious-activity S0265 Kazuar
Turla MalwarePatrol 2026-03-03 18:13:59 2026-03-03 18:13:59 malicious-activity G0010 Turla

Tags

turla pfinet tag_0530 snake pacifier apt makersmark uroburos venomous bear waterbug iron hunter itg12 krypton group 88 g0010 blue python sig23 atk13 hippo team popeye

Sample information

Filenames
bd7d85741a3801d8fe7a725061249337.exe, 6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d.bin
File type
PE32 executable for MS Windows 4.00 (GUI), Intel i ...
MD5
bd7d85741a3801d8fe7a725061249337
SHA-1
fb5eb1cad3444d7a1647bb906fff3200d8a707f3
SHA-256
6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d
First indexed
2026-03-03 18:13:59
Last updated
2026-05-19 14:56:59

Antivirus detections

EngineDetection
ALYacBackdoor.MSIL.Kazuar
APEXMalicious
AhnLab-V3Trojan/Win.Generic.C5884131
AlibabaBackdoor:MSIL/KazuarModule.32fb5bde
Antiy-AVLTrojan/MSIL.Turla
ArcabitTrojan.Turla.1
AviraTR/W32.Agent
CAT-QuickHealTrojan.MSIL
CTXexe.trojan.msil
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
ESET-NOD32MSIL/Turla.Y trojan
Elasticmalicious (moderate confidence)
EmsisoftTrojan.Turla.1 (B)
F-SecureTrojan.TR/W32.Agent
GDataTrojan.Turla.1
GoogleDetected
IkarusTrojan.MSIL.Turla
K7AntiVirusBackdoor ( 006dfced1 )
K7GWBackdoor ( 006dfced1 )
KingsoftMSIL.Trojan.Kazuar.gen
LionicTrojan.Win32.Turla.4!c
MalwarebytesMalware.AI.4291917544
MaxSecureTrojan.Malware.684672969.susgen
McAfeeDti!6EB31006CA31
MicroWorld-eScanTrojan.Turla.1
MicrosoftBackdoor:MSIL/KazuarModule.A!dha
Paloaltogeneric.ml
PandaTrj/CI.A
RisingTrojan.Turla!8.1C8 (CLOUD)
SentinelOneStatic AI - Suspicious PE
SophosMal/Generic-S
SymantecTrojan.Gen.MBT
TencentMsil.Trojan.Kazuar.Fkjl
Trapminemalicious.moderate.ml.score
TrellixENSArtemis!BD7D85741A38
TrendMicroTROJ_GEN.R023C0DEE26
TrendMicro-HouseCallTrojan.MSIL.KAZUARLOADER.A
VBA32Trojan.MSIL.Agent
VIPRETrojan.Turla.1
VaristW32/ABTrojan.XKCX-7530
VirITTrojan.Win32.MSIL.JQO
ZoneAlarmTroj/MSIL-TKO
alibabacloudBackdoor:MSIL/Turla.Y

Network contacts

184.25.113.153 151.101.1.44 150.171.22.12 104.254.148.252 142.251.218.234 150.171.109.185 142.251.218.193 99.84.160.78

DNS requests

clients2.googleusercontent.com edge-consumer-static.azureedge.net ib.adnxs.com m.adnxs.com px.ads.linkedin.com r.msftstatic.com sb.scorecardresearch.com trc.taboola.com www.googleapis.com