bounty-65309813155761065

Classification: Malicious

bounty-65309813155761065 is a malicious file sample. Linked to Apt29, Darkhotel activity. Reported by 2 threat sources, last seen 2023-02-24.

Detection summary

  • 27 antivirus detections (11% detection ratio)
  • 0 IDS alerts
  • 2 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: APT29 (G0016) DARKHOTEL (G0012)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-02-24 12:30:03 2023-02-24 12:30:03
Apt 29 Maltiverse 2023-02-17 04:22:59 2023-02-18 06:58:19 malicious-activity G0016 APT29
Darkhotel Maltiverse 2023-02-17 04:22:59 2023-02-18 06:58:19 malicious-activity G0012 Darkhotel
Stone Panda Maltiverse 2023-02-17 04:22:59 2023-02-18 06:58:19 malicious-activity

Tags

apt apt29 cozer cozybear cozycar cozyduke darkhotel dubnium dukes euroapt falloutteam group100 hammertoss karba luder minidionis nemim officemonkeys seaduke spyware tapaoux thedukes trojan

Sample information

Filenames
bounty-65309813155761065
File type
PE32 executable (DLL) (GUI) Intel 80386, for MS Wi ...
Size
166864 bytes
MD5
e819b36e92bf84ead50e481cfa1d517d
SHA-1
c1a2799d4f3e4caf62a6e9aa58ea4b8592493221
SHA-256
bdc15b09b78093a1a5503a1a7bfb487f7ef4ca2cb8b4d1d1bdf9a54cdc87fae4
First indexed
2023-02-18 06:58:19
Last updated
2025-07-30 02:33:20

Antivirus detections

EngineDetection
CyrenW32/ABRisk.SIJV-4650
TrendMicroTrojanSpy.Win32.TRANSBOX.ZJJH.enc
SophosMal/Generic-S
GoogleDetected
TrendMicro-HouseCallTrojanSpy.Win32.TRANSBOX.ZJJH.enc
FortinetW32/TrojanSpy_Win32_TRANSBOX_ZJJH.ENC
ALYacTrojan.Spy.TransBox
Antiy-AVLTrojan/Win32.Agent
ArcabitTrojan.GenericFCA.Agent.D1286B
BitDefenderTrojan.GenericFCA.Agent.75883
BkavW32.AIDetectMalware
CylanceUnsafe
DeepInstinctMALICIOUS
ESET-NOD32Win32/Agent.AFFD
EmsisoftTrojan.GenericFCA.Agent.75883 (B)
FireEyeTrojan.GenericFCA.Agent.75883
GDataTrojan.GenericFCA.Agent.75883
K7AntiVirusTrojan ( 005ac56c1 )
K7GWTrojan ( 005ac56c1 )
LionicTrojan.Win32.GenericFCA.4!c
MAXmalware (ai score=85)
MicroWorld-eScanTrojan.GenericFCA.Agent.75883
MicrosoftTrojan:Win32/Tnega!MSR
SymantecTrojan.Gen.MBT
VIPRETrojan.GenericFCA.Agent.75883
VaristW32/ABRisk.SIJV-4650
alibabacloudBackdoor

Process list

NameCommand line
<Ignored Process>
regsvr32.exe/s "C:\bounty-65309813155761065.dll"