Please ensure you understand and agree with our data protection policy before using this site. Review Policy
Online Virus Checker | v.1.0.170.174 |
DB Version: | 2024-03-27 18:00:23 |
AgentTesla is a Remote Access Trojan (RAT) built on the .Net framework, primarily utilized to acquire initial access to systems. It's frequently employed within the framework of Malware-As-A-Service (MaaS). Within this illicit business model, individuals referred to as "initial access brokers" (IAB) offer their specialized expertise to criminal groups seeking to exploit corporate networks. As an initial-stage malware, AgentTesla facilitates remote access to a compromised system, subsequently permitting the downloading of more advanced secondary tools, including ransomware.
File | 417fb1a8808fd3e3071f68990eb63fee002ed084182e58d8a4eccf9f1a44f75e.exe |
Checked | 2024-03-27 16:32:22 |
MD5 | b5e11e2073a1f74806b2b56e7bda8903 |
SHA1 | c9ea07e16a7975064c2e732af4b1522604aee4fd |
SHA256 | 417fb1a8808fd3e3071f68990eb63fee002ed084182e58d8a4eccf9f1a44f75e |
SHA512 | 9622297b640871db540dd7a1bea5c65814b607b4b79cc83560093516ff0f4181971218b31d3853794b7d058e626c477f227692b46b61606cfeac6ff874116228 |
Imphash | b34f154ec913d2d2c435cbd644e91687 |
File Size | 755433 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Win32.AgentTesla.tr without requiring further user intervention.
edf03d8a90a67b8c580f5a616e7a0811 96320491b7a4d512eb60af783fd21052 4fb06cecdccc7117 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00403359 |
Compilation: | 2018-12-15 22:24:27 |
Checksum: | 0x00000000 (Actual: 0x000c12c9) |
OS Version: | 4.0 |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
Sign: | The PE file does not contain a certificate table. |
Sections: | 5 |
Imports: | KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, |
Exports: | 0 |
Resources: | 12 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000062a5 | 0x00006400 | 5814efda24a547f46f687d77de540309 | 6.43 |
.rdata | 0x00008000 | 0x00001396 | 0x00001400 | ef1be07ca8b096915258569fb3718a3c | 5.16 |
.data | 0x0000a000 | 0x00020318 | 0x00000600 | 7d0d44c89e64b001096d8f9c60b1ac1b | 3.90 |
.ndata | 0x0002b000 | 0x00023000 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rsrc | 0x0004e000 | 0x0005aec8 | 0x0005b000 | 96ef424146e3112d1b5e3fec561d15b0 | 3.05 |