ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70.exe

Classification: Malicious

ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70.exe is a malicious file sample. Linked to Apt29 activity. Detected by 13 antivirus engines.

Detection summary

  • 13 antivirus detections (18% detection ratio)
  • 1 IDS alerts
  • 2 processes observed
  • 5 contacted hosts
  • 5 DNS requests

MITRE ATT&CK associations

Intrusion sets: APT29 (G0016)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Apt 29 Maltiverse 2023-08-18 04:15:27 2023-08-19 20:21:54 malicious-activity G0016 APT29
Generic Malware Hybrid-Analysis 2023-07-21 18:45:03 2023-07-21 18:45:03

Tags

apt

Sample information

Filenames
ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70.exe
File type
PE32+ executable (DLL) (GUI) x86-64 (stripped to e ...
Size
33280 bytes
MD5
0be11b4f34ede748892ea49e473d82db
SHA-1
15d9b5a0d442e9dccf1e0f0ded34f7b6014c47b6
SHA-256
ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70
First indexed
2023-07-21 18:34:01
Last updated
2026-01-05 00:29:08

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKD.68275714
FireEyeTrojan.GenericKD.68275714
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Dukes.N
BitDefenderTrojan.GenericKD.68275714
DrWebBackDoor.Siggen2.4528
EmsisoftTrojan.GenericKD.68275714 (B)
GDataTrojan.GenericKD.68275714
ArcabitTrojan.Generic.D411CE02
MAXmalware (ai score=84)
RisingTrojan.Dukes!8.181FA (CLOUD)
DeepInstinctMALICIOUS

Network contacts

34.206.34.177 18.239.196.201 18.155.188.31 18.155.188.195 108.139.4.116

DNS requests

o.ss2.us ocsp.e2m02.amazontrust.com ocsp.rootca3.amazontrust.com ocsp.rootg2.amazontrust.com toyy.zulipchat.com

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\ae79aa17e6f3cc8e816e32335738b61b343e78c20abb8ae044adfeac5d97bf70.exe.dll",#1777