78aaeff421355a794a6248c84871eef7.exe
Classification: Malicious
78aaeff421355a794a6248c84871eef7.exe is a malicious file sample. Linked to Kazuar malware. Reported by 3 threat sources, last seen 2026-05-19.
Detection summary
- 47 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: KAZUAR (S0265)
Intrusion sets: TURLA (G0010)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-05-19 11:45:05 | 2026-05-19 11:45:05 | ||
| Kazuar | MalwareBazaar Abuse.ch | 2026-05-19 10:36:13 | 2026-05-19 10:36:13 | malicious-activity | S0265 Kazuar |
| Turla | MalwarePatrol | 2026-03-03 18:14:01 | 2026-03-03 18:14:01 | malicious-activity | G0010 Turla |
Tags
turla pfinet tag_0530 snake pacifier apt makersmark uroburos venomous bear waterbug iron hunter itg12 krypton group 88 g0010 blue python sig23 atk13 hippo team popeyeSample information
- Filenames
- 78aaeff421355a794a6248c84871eef7.exe, c1f278f88275e07cc03bd390fe1cbeedd55933110c6fd16de4187f4c4aaf42b9.bin
- File type
- PE32 executable for MS Windows 4.00 (console), Int ...
- MD5
78aaeff421355a794a6248c84871eef7- SHA-1
ac6957ce5b1d361561d1836a6c026ab9a3279227- SHA-256
c1f278f88275e07cc03bd390fe1cbeedd55933110c6fd16de4187f4c4aaf42b9- First indexed
- 2026-03-03 18:14:01
- Last updated
- 2026-05-19 14:57:21
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Backdoor.MSIL.Kazuar |
| AVG | Win32:MalwareX-gen [Misc] |
| AhnLab-V3 | Trojan/Win.Generic.C5882680 |
| Alibaba | Backdoor:MSIL/KazuarModule.d68afffa |
| Antiy-AVL | Trojan/MSIL.Turla |
| Arcabit | Trojan.Turla.7 |
| Avast | Win32:MalwareX-gen [Misc] |
| Avira | TR/W32.Agent |
| BitDefender | Trojan.Turla.7 |
| CAT-QuickHeal | Trojan.MSIL |
| CTX | exe.trojan.msil |
| CrowdStrike | win/malicious_confidence_100% (W) |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | MSIL/Turla.Y trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Trojan.Turla.7 (B) |
| F-Secure | Trojan.TR/W32.Agent |
| Fortinet | MSIL/Turla.Y!tr |
| GData | Trojan.Turla.7 |
| Detected | |
| Gridinsoft | Trojan.Win32.Agent.sa |
| Ikarus | Trojan.MSIL.Turla |
| K7AntiVirus | Backdoor ( 006dfced1 ) |
| K7GW | Backdoor ( 006dfced1 ) |
| Kaspersky | HEUR:Trojan.MSIL.Kazuar.gen |
| Kingsoft | MSIL.Backdoor.KazuarModule.v |
| Lionic | Trojan.Win32.Turla.4!c |
| Malwarebytes | Malware.AI.1621830304 |
| MaxSecure | Trojan.Malware.684786758.susgen |
| McAfeeD | ti!C1F278F88275 |
| MicroWorld-eScan | Trojan.Turla.7 |
| Microsoft | Backdoor:MSIL/KazuarModule.A!dha |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Trojan.Turla!8.1C8 (CLOUD) |
| Sangfor | Backdoor.Msil.Turla.Vcds |
| Sophos | Mal/Generic-S |
| Symantec | Trojan Horse |
| Tencent | Msil.Trojan.Kazuar.Vylw |
| Trapmine | malicious.moderate.ml.score |
| TrellixENS | Artemis!78AAEFF42135 |
| TrendMicro | Backdoor.MSIL.TURLA.TL0101EE26ZZ |
| TrendMicro-HouseCall | Backdoor.MSIL.TURLA.TL0101EE26ZZ |
| VIPRE | Trojan.Turla.7 |
| Varist | W32/ABRisk.PMUV-2553 |
| ZoneAlarm | Troj/MSIL-TKO |
| alibabacloud | Backdoor:MSIL/Turla.Y |