48e3add1881d60e0f6a036cfdb24426266f23f624a4cd57b8ea945e9ca98e6fd
Classification: Malicious
48e3add1881d60e0f6a036cfdb24426266f23f624a4cd57b8ea945e9ca98e6fd is a malicious file sample. Linked to Fin7, Fin8 activity. Detected by 76 antivirus engines.
Detection summary
- 76 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Intrusion sets: FIN7 (G0046) FIN8 (G0061)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Fin8 | Maltiverse | 2023-08-18 04:16:05 | 2023-08-19 20:21:51 | malicious-activity | G0061 FIN8 |
| Fin7 | Maltiverse | 2023-08-18 04:16:05 | 2023-08-19 20:21:49 | malicious-activity | G0046 FIN7 |
Tags
aptSample information
- SHA-256
48e3add1881d60e0f6a036cfdb24426266f23f624a4cd57b8ea945e9ca98e6fd- First indexed
- 2023-08-19 20:21:49
- Last updated
- 2026-03-26 01:33:05
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.Common.5EC1A832 |
| Lionic | Trojan.Win32.Convagent.4!c |
| Elastic | malicious (high confidence) |
| Cynet | Malicious (score: 100) |
| CAT-QuickHeal | Trojan.Malagent.S30640132 |
| ALYac | Trojan.MSIL.Agent |
| Cylance | unsafe |
| Zillya | Trojan.Agent.Win32.3596709 |
| Sangfor | Suspicious.Win32.Save.a |
| K7AntiVirus | Trojan ( 005a8dde1 ) |
| K7GW | Trojan ( 005a8dde1 ) |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cyren | W64/Agent.NEDJ |
| Symantec | Trojan Horse |
| ESET-NOD32 | a variant of MSIL/Agent.WIH |
| APEX | Malicious |
| Kaspersky | HEUR:Trojan.MSIL.Agentb.gen |
| BitDefender | Trojan.Generic.34038133 |
| ViRobot | Trojan.Win.Z.Agent.364547 |
| MicroWorld-eScan | Trojan.Generic.34038133 |
| Avast | Win64:MalwareX-gen [Trj] |
| Emsisoft | Trojan.Generic.34038133 (B) |
| F-Secure | Trojan.TR/Agent.kpmip |
| VIPRE | Trojan.Generic.34038133 |
| TrendMicro | TROJ_FRS.0NA104GK23 |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.fc |
| FireEye | Generic.mg.bd265f2d3e827e2f |
| Sophos | Troj/MSILAg-AB |
| SentinelOne | Static AI - Malicious PE |
| Webroot | W32.Trojan.Agent.Gen |
| Avira | TR/Agent.kpmip |
| Antiy-AVL | Trojan/Win32.PossibleThreat |
| Microsoft | Trojan:MSIL/AgentTesla!MSR |
| Gridinsoft | Trojan.Heur!.03012280 |
| Arcabit | Trojan.Generic.D2076175 |
| ZoneAlarm | HEUR:Trojan.MSIL.Agentb.gen |
| GData | Trojan.Generic.34038133 |
| Detected | |
| AhnLab-V3 | Trojan/Win.Agentb.C5458082 |
| McAfee | Artemis!BD265F2D3E82 |
| MAX | malware (ai score=84) |
| Malwarebytes | Malware.AI.4199379524 |
| Panda | Trj/Chgt.AD |
| TrendMicro-HouseCall | TROJ_FRS.0NA104GK23 |
| Tencent | Msil.Trojan.Agentb.Cnhl |
| MaxSecure | Trojan.Malware.73701643.susgen |
| Fortinet | W32/PossibleThreat |
| AVG | Win64:MalwareX-gen [Trj] |
| DeepInstinct | MALICIOUS |
| Antiy-AVL | Trojan/Win32.Agent |
| Arcabit | Trojan.Agent.GFRR |
| BitDefender | Trojan.Agent.GFRR |
| Bkav | W32.AIDetectMalware.CS |
| CTX | dll.trojan.msil |
| Cylance | Unsafe |
| ESET-NOD32 | MSIL/Agent.WIH trojan |
| Emsisoft | Trojan.Agent.GFRR (B) |
| GData | Trojan.Agent.GFRR |
| Ikarus | Trojan.MSIL.Agent |
| Jiangmin | Trojan.MSIL.apaxd |
| K7AntiVirus | Trojan ( 005f37861 ) |
| K7GW | Trojan ( 005f37861 ) |
| Kingsoft | malware.kb.c.954 |
| Lionic | Trojan.Win32.Agentb.X!c |
| Malwarebytes | Trojan.Agent.MSIL |
| McAfeeD | ti!48E3ADD1881D |
| MicroWorld-eScan | Trojan.Agent.GFRR |
| Paloalto | generic.ml |
| Rising | Trojan.Convagent!8.12323 (CLOUD) |
| Tencent | Malware.Win32.Gencirc.1495ffff |
| TrellixENS | Artemis!BD265F2D3E82 |
| VIPRE | Trojan.Agent.GFRR |
| Varist | W64/Agent.NEDJ |
| Yandex | Trojan.Agentb!XyqiWQLRcVo |
| ZoneAlarm | Troj/MSILAg-AB |
| alibabacloud | Trojan:MSIL/AgentTesla.Gen |