Classification: Malicious
bounty-68090320269009011 is a malicious file sample. Linked to Zirconium activity. Reported by 3 threat sources, last seen 2026-08-16.
Detection summary
- 59 antivirus detections
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-13 10:18:37 |
2026-08-16 10:20:39 |
malicious-activity
|
|
| APT31 |
MalwarePatrol |
2026-03-03 17:55:03 |
2026-03-03 18:09:30 |
malicious-activity
|
G0128 ZIRCONIUM
|
| Generic Malware |
Hybrid-Analysis |
2024-09-13 05:45:04 |
2024-09-13 07:00:07 |
|
|
Tags
apt31
judgment panda
red keres
bronze vinewood
zirconium
Sample information
- Filenames
- bounty-68090320269009011
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 458480 bytes
- MD5
d954af3b6c229a0b1e4cd6f3a4a24a3f
- SHA-1
8d0a0d715b47470fe42c39b8ee92dea831fffdf7
- SHA-256
74f7a3b2a5df81eb7b5e0c5c4af8548e61dc37c608dda458b75b58852f2f2cfd
- First indexed
- 2024-09-13 05:30:42
- Last updated
- 2026-07-17 00:14:22
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Trojan.Heur2.RP.BqX@bKa3!Xhb |
| AVG | Win32:Malware-gen |
| Alibaba | Backdoor:Win32/PcClient.ab23d738 |
| Arcabit | Trojan.Heur2.RP.E32C63 |
| Avast | Win32:Malware-gen |
| Avira | TR/Spy.Agent.dneku |
| BitDefender | Gen:Trojan.Heur2.RP.BqX@bKa3!Xhb |
| BitDefenderTheta | AI:Packer.D0323B1E20 |
| Bkav | W32.AIDetectMalware |
| ClamAV | Win.Trojan.Pcclient-4244 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cybereason | malicious.b6c229 |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop5.56461 |
| ESET-NOD32 | multiple detections |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Trojan.Heur2.RP.BqX@bKa3!Xhb (B) |
| F-Secure | Backdoor.BDS/PcClient.45056.1 |
| FireEye | Generic.mg.d954af3b6c229a0b |
| Fortinet | W32/Agent.OQNN!tr |
| GData | Gen:Trojan.Heur2.RP.BqX@bKa3!Xhb |
| Google | Detected |
| Ikarus | Backdoor.Win32.SuspectCRC |
| Jiangmin | TrojanDropper.Agent.bvif |
| K7AntiVirus | Spyware ( 004c501b1 ) |
| K7GW | Spyware ( 004c501b1 ) |
| Kaspersky | Exploit.Win32.BypassUAC.mj |
| Kingsoft | malware.kb.a.977 |
| Lionic | Trojan.Win32.PcClient.3!c |
| MAX | malware (ai score=86) |
| Malwarebytes | Malware.AI.1886707202 |
| MaxSecure | Trojan.Malware.10212380.susgen |
| McAfee | Dropper-FOK!D954AF3B6C22 |
| McAfeeD | ti!74F7A3B2A5DF |
| MicroWorld-eScan | Gen:Trojan.Heur2.RP.BqX@bKa3!Xhb |
| Microsoft | TrojanDropper:Win32/Warood.A |
| NANO-Antivirus | Trojan.Win32.Agent.dstgaz |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Dropper.Warood!8.538A (TFE:5:uLqMVihzRLR) |
| Sangfor | Dropper.Win32.Warood.Vh7d |
| Skyhigh | Dropper-FOK!D954AF3B6C22 |
| Sophos | Mal/Generic-R |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.11521e07 |
| Trapmine | malicious.moderate.ml.score |
| TrendMicro | TROJ_GEN.R002C0CDH24 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0CDH24 |
| VBA32 | Backdoor.PcClient |
| VIPRE | Gen:Trojan.Heur2.RP.BqX@bKa3!Xhb |
| Varist | W32/ABRisk.OAGJ-6638 |
| Webroot | W32.Trojan.Rawdoor |
| Xcitium | Malware@#dsaq756fw1kp |
| Yandex | TrojanSpy.Agent!6f88JtGwOW8 |
| Zillya | Trojan.AgentCRTD.Win32.7787 |
| ZoneAlarm | Exploit.Win32.BypassUAC.mj |
| alibabacloud | Exploit:Win/Warood.A |
Process list
| Name | Command line |
| bounty-68090320269009011.exe | |
| bounty-68090320269009011.exe | |
| bounty-68090320269009011.exe | |
| bounty-68090320269009011.exe | |
| bounty-68090320269009011.exe | |