tasklistw.exe

Classification: Malicious

tasklistw.exe is a malicious file sample. Linked to Turla, Oilrig activity. Reported by 2 threat sources, last seen 2023-03-04.

Detection summary

  • 17 antivirus detections (24% detection ratio)
  • 0 IDS alerts
  • 1 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: TURLA (G0010) OILRIG (G0049)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Turla Maltiverse 2023-03-03 04:26:37 2023-03-04 19:42:14 malicious-activity G0010 Turla
OilRig Maltiverse 2023-03-03 04:26:38 2023-03-04 19:41:59 malicious-activity G0049 OilRig
Trojan.Generic Hybrid-Analysis 2019-11-14 20:30:07 2019-11-14 20:30:07

Tags

apt apt34

Sample information

Filenames
tasklistw.exe
File type
PE32+ executable (GUI) x86-64, for MS Windows
Size
96256 bytes
MD5
921bff2475a58c9044ca3be8eb29482a
SHA-1
52a1d49b06a51e7ed722a5d2ffe121dfce477cf4
SHA-256
c4a6db706c59a5a0a29368f80731904cc98a26e081088e5793764a381708b1ea
First indexed
2019-11-14 20:30:07
Last updated
2023-03-04 19:42:14

Antivirus detections

EngineDetection
MicroWorld-eScanTrojan.GenericKD.32695145
McAfeeArtemis!921BFF2475A5
CylanceUnsafe
BitDefenderTrojan.GenericKD.32695145
CyrenW64/Trojan.QEQH-4336
Ad-AwareTrojan.GenericKD.32695145
SophosGeneric PUA FC (PUA)
McAfee-GW-EditionArtemis
FireEyeTrojan.GenericKD.32695145
MicrosoftPUA:Win32/Presenoker
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D1F2E369
GDataTrojan.GenericKD.32695145
ALYacTrojan.GenericKD.32695145
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R020H05JT19
FortinetW64/Agent.482A!tr

Process list

NameCommand line
tasklistw.exe