Please ensure you understand and agree with our data protection policy before using this site. Review Policy
Online Virus Checker | v.1.0.170.174 |
DB Version: | 2024-03-27 18:00:23 |
AgentTesla is a Remote Access Trojan (RAT) built on the .Net framework, primarily utilized to acquire initial access to systems. It's frequently employed within the framework of Malware-As-A-Service (MaaS). Within this illicit business model, individuals referred to as "initial access brokers" (IAB) offer their specialized expertise to criminal groups seeking to exploit corporate networks. As an initial-stage malware, AgentTesla facilitates remote access to a compromised system, subsequently permitting the downloading of more advanced secondary tools, including ransomware.
File | 58fce91551ddbdd915ed2cc71a2d7f2a5f354ea137365cba589affb21bfb5301.exe |
Checked | 2024-03-27 16:28:35 |
MD5 | d555c9f03a1666ab0c162b497b495301 |
SHA1 | bb9c497dbb935a0ee7ea369937a1a9939fda8a57 |
SHA256 | 58fce91551ddbdd915ed2cc71a2d7f2a5f354ea137365cba589affb21bfb5301 |
SHA512 | 0a21d6ffdc383d62c5b36df8c020a9ea4ec505a4c1e3d11f62d673a3fe746b114a2816d62d6a89ac0decb3ff140ba2c2b27bc37cf57ed6b9cdd4551e96ea6448 |
Imphash | b34f154ec913d2d2c435cbd644e91687 |
File Size | 738592 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Win32.AgentTesla.tr without requiring further user intervention.
edf03d8a90a67b8c580f5a616e7a0811 96320491b7a4d512eb60af783fd21052 4fb06cecdccc7117 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00403359 |
Compilation: | 2018-12-15 22:24:27 |
Checksum: | 0x00000000 (Actual: 0x000bdf99) |
OS Version: | 4.0 |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
Sign: | The PE file does not contain a certificate table. |
Sections: | 5 |
Imports: | KERNEL32, USER32, GDI32, SHELL32, ADVAPI32, COMCTL32, ole32, |
Exports: | 0 |
Resources: | 12 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000062a5 | 0x00006400 | 5814efda24a547f46f687d77de540309 | 6.43 |
.rdata | 0x00008000 | 0x00001396 | 0x00001400 | ef1be07ca8b096915258569fb3718a3c | 5.16 |
.data | 0x0000a000 | 0x00020318 | 0x00000600 | 7d0d44c89e64b001096d8f9c60b1ac1b | 3.90 |
.ndata | 0x0002b000 | 0x00023000 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rsrc | 0x0004e000 | 0x0005aec8 | 0x0005b000 | 96ef424146e3112d1b5e3fec561d15b0 | 3.05 |