bounty-68090320269009011

Classification: Malicious

bounty-68090320269009011 is a malicious file sample. Linked to Zirconium activity. Reported by 3 threat sources, last seen 2026-08-16.

Detection summary

  • 59 antivirus detections
  • 0 IDS alerts
  • 5 processes observed
  • 0 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Intrusion sets: ZIRCONIUM (G0128)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Cyber Threat Alliance 2026-08-13 10:18:37 2026-08-16 10:20:39 malicious-activity
APT31 MalwarePatrol 2026-03-03 17:55:03 2026-03-03 18:09:30 malicious-activity G0128 ZIRCONIUM
Generic Malware Hybrid-Analysis 2024-09-13 05:45:04 2024-09-13 07:00:07

Tags

apt31 judgment panda red keres bronze vinewood zirconium

Sample information

Filenames
bounty-68090320269009011
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
458480 bytes
MD5
d954af3b6c229a0b1e4cd6f3a4a24a3f
SHA-1
8d0a0d715b47470fe42c39b8ee92dea831fffdf7
SHA-256
74f7a3b2a5df81eb7b5e0c5c4af8548e61dc37c608dda458b75b58852f2f2cfd
First indexed
2024-09-13 05:30:42
Last updated
2026-07-17 00:14:22

Antivirus detections

EngineDetection
ALYacGen:Trojan.Heur2.RP.BqX@bKa3!Xhb
AVGWin32:Malware-gen
AlibabaBackdoor:Win32/PcClient.ab23d738
ArcabitTrojan.Heur2.RP.E32C63
AvastWin32:Malware-gen
AviraTR/Spy.Agent.dneku
BitDefenderGen:Trojan.Heur2.RP.BqX@bKa3!Xhb
BitDefenderThetaAI:Packer.D0323B1E20
BkavW32.AIDetectMalware
ClamAVWin.Trojan.Pcclient-4244
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.b6c229
CylanceUnsafe
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebTrojan.MulDrop5.56461
ESET-NOD32multiple detections
Elasticmalicious (high confidence)
EmsisoftGen:Trojan.Heur2.RP.BqX@bKa3!Xhb (B)
F-SecureBackdoor.BDS/PcClient.45056.1
FireEyeGeneric.mg.d954af3b6c229a0b
FortinetW32/Agent.OQNN!tr
GDataGen:Trojan.Heur2.RP.BqX@bKa3!Xhb
GoogleDetected
IkarusBackdoor.Win32.SuspectCRC
JiangminTrojanDropper.Agent.bvif
K7AntiVirusSpyware ( 004c501b1 )
K7GWSpyware ( 004c501b1 )
KasperskyExploit.Win32.BypassUAC.mj
Kingsoftmalware.kb.a.977
LionicTrojan.Win32.PcClient.3!c
MAXmalware (ai score=86)
MalwarebytesMalware.AI.1886707202
MaxSecureTrojan.Malware.10212380.susgen
McAfeeDropper-FOK!D954AF3B6C22
McAfeeDti!74F7A3B2A5DF
MicroWorld-eScanGen:Trojan.Heur2.RP.BqX@bKa3!Xhb
MicrosoftTrojanDropper:Win32/Warood.A
NANO-AntivirusTrojan.Win32.Agent.dstgaz
Paloaltogeneric.ml
PandaTrj/CI.A
RisingDropper.Warood!8.538A (TFE:5:uLqMVihzRLR)
SangforDropper.Win32.Warood.Vh7d
SkyhighDropper-FOK!D954AF3B6C22
SophosMal/Generic-R
SymantecML.Attribute.HighConfidence
TencentMalware.Win32.Gencirc.11521e07
Trapminemalicious.moderate.ml.score
TrendMicroTROJ_GEN.R002C0CDH24
TrendMicro-HouseCallTROJ_GEN.R002C0CDH24
VBA32Backdoor.PcClient
VIPREGen:Trojan.Heur2.RP.BqX@bKa3!Xhb
VaristW32/ABRisk.OAGJ-6638
WebrootW32.Trojan.Rawdoor
XcitiumMalware@#dsaq756fw1kp
YandexTrojanSpy.Agent!6f88JtGwOW8
ZillyaTrojan.AgentCRTD.Win32.7787
ZoneAlarmExploit.Win32.BypassUAC.mj
alibabacloudExploit:Win/Warood.A

DNS requests

post.discherry.com

Process list

NameCommand line
bounty-68090320269009011.exe
bounty-68090320269009011.exe
bounty-68090320269009011.exe
bounty-68090320269009011.exe
bounty-68090320269009011.exe