Classification: Malicious
bounty-65309813155761065 is a malicious file sample. Linked to Apt29, Darkhotel activity. Reported by 2 threat sources, last seen 2023-02-24.
Detection summary
- 27 antivirus detections (11% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-02-24 12:30:03 |
2023-02-24 12:30:03 |
|
|
| Apt 29 |
Maltiverse |
2023-02-17 04:22:59 |
2023-02-18 06:58:19 |
malicious-activity
|
G0016 APT29
|
| Darkhotel |
Maltiverse |
2023-02-17 04:22:59 |
2023-02-18 06:58:19 |
malicious-activity
|
G0012 Darkhotel
|
| Stone Panda |
Maltiverse |
2023-02-17 04:22:59 |
2023-02-18 06:58:19 |
malicious-activity
|
|
Tags
apt
apt29
cozer
cozybear
cozycar
cozyduke
darkhotel
dubnium
dukes
euroapt
falloutteam
group100
hammertoss
karba
luder
minidionis
nemim
officemonkeys
seaduke
spyware
tapaoux
thedukes
trojan
Sample information
- Filenames
- bounty-65309813155761065
- File type
- PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
- Size
- 166864 bytes
- MD5
e819b36e92bf84ead50e481cfa1d517d
- SHA-1
c1a2799d4f3e4caf62a6e9aa58ea4b8592493221
- SHA-256
bdc15b09b78093a1a5503a1a7bfb487f7ef4ca2cb8b4d1d1bdf9a54cdc87fae4
- First indexed
- 2023-02-18 06:58:19
- Last updated
- 2025-07-30 02:33:20
Antivirus detections
| Engine | Detection |
| Cyren | W32/ABRisk.SIJV-4650 |
| TrendMicro | TrojanSpy.Win32.TRANSBOX.ZJJH.enc |
| Sophos | Mal/Generic-S |
| Google | Detected |
| TrendMicro-HouseCall | TrojanSpy.Win32.TRANSBOX.ZJJH.enc |
| Fortinet | W32/TrojanSpy_Win32_TRANSBOX_ZJJH.ENC |
| ALYac | Trojan.Spy.TransBox |
| Antiy-AVL | Trojan/Win32.Agent |
| Arcabit | Trojan.GenericFCA.Agent.D1286B |
| BitDefender | Trojan.GenericFCA.Agent.75883 |
| Bkav | W32.AIDetectMalware |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | Win32/Agent.AFFD |
| Emsisoft | Trojan.GenericFCA.Agent.75883 (B) |
| FireEye | Trojan.GenericFCA.Agent.75883 |
| GData | Trojan.GenericFCA.Agent.75883 |
| K7AntiVirus | Trojan ( 005ac56c1 ) |
| K7GW | Trojan ( 005ac56c1 ) |
| Lionic | Trojan.Win32.GenericFCA.4!c |
| MAX | malware (ai score=85) |
| MicroWorld-eScan | Trojan.GenericFCA.Agent.75883 |
| Microsoft | Trojan:Win32/Tnega!MSR |
| Symantec | Trojan.Gen.MBT |
| VIPRE | Trojan.GenericFCA.Agent.75883 |
| Varist | W32/ABRisk.SIJV-4650 |
| alibabacloud | Backdoor |
Process list
| Name | Command line |
| <Ignored Process> | |
| regsvr32.exe | /s "C:\bounty-65309813155761065.dll" |