Classification: Malicious
tasklistw.exe is a malicious file sample. Linked to Turla, Oilrig activity. Reported by 2 threat sources, last seen 2023-03-04.
Detection summary
- 17 antivirus detections (24% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Turla |
Maltiverse |
2023-03-03 04:26:37 |
2023-03-04 19:42:14 |
malicious-activity
|
G0010 Turla
|
| OilRig |
Maltiverse |
2023-03-03 04:26:38 |
2023-03-04 19:41:59 |
malicious-activity
|
G0049 OilRig
|
| Trojan.Generic |
Hybrid-Analysis |
2019-11-14 20:30:07 |
2019-11-14 20:30:07 |
|
|
Sample information
- Filenames
- tasklistw.exe
- File type
- PE32+ executable (GUI) x86-64, for MS Windows
- Size
- 96256 bytes
- MD5
921bff2475a58c9044ca3be8eb29482a
- SHA-1
52a1d49b06a51e7ed722a5d2ffe121dfce477cf4
- SHA-256
c4a6db706c59a5a0a29368f80731904cc98a26e081088e5793764a381708b1ea
- First indexed
- 2019-11-14 20:30:07
- Last updated
- 2023-03-04 19:42:14
Antivirus detections
| Engine | Detection |
| MicroWorld-eScan | Trojan.GenericKD.32695145 |
| McAfee | Artemis!921BFF2475A5 |
| Cylance | Unsafe |
| BitDefender | Trojan.GenericKD.32695145 |
| Cyren | W64/Trojan.QEQH-4336 |
| Ad-Aware | Trojan.GenericKD.32695145 |
| Sophos | Generic PUA FC (PUA) |
| McAfee-GW-Edition | Artemis |
| FireEye | Trojan.GenericKD.32695145 |
| Microsoft | PUA:Win32/Presenoker |
| Endgame | malicious (moderate confidence) |
| Arcabit | Trojan.Generic.D1F2E369 |
| GData | Trojan.GenericKD.32695145 |
| ALYac | Trojan.GenericKD.32695145 |
| MAX | malware (ai score=82) |
| TrendMicro-HouseCall | TROJ_GEN.R020H05JT19 |
| Fortinet | W64/Agent.482A!tr |
Process list
| Name | Command line |
| tasklistw.exe | |