7e6b3d8f37991cef921fd8c8f0a0c48a76e437665ac60db3afe271d14de9bff5
Classification: Malicious
7e6b3d8f37991cef921fd8c8f0a0c48a76e437665ac60db3afe271d14de9bff5 is a malicious file sample. Linked to Agent Tesla malware. Detected by 29 antivirus engines.
Detection summary
- 29 antivirus detections (40% detection ratio)
- 21 IDS alerts
- 4 processes observed
- 2 contacted hosts
- 2 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-10-09 20:15:03 |
2026-09-02 12:45:05 |
malicious-activity
|
|
| AgentTesla |
MalwareBazaar Abuse.ch |
2023-10-09 14:16:47 |
2023-10-09 14:16:47 |
malicious-activity
|
S0331 Agent Tesla
|
Tags
windows-server-utility
evasive
infostealer
Sample information
- Filenames
- 7e6b3d8f37991cef921fd8c8f0a0c48a76e437665ac60db3afe271d14de9bff5, 7e6b3.Trojan.exe, Halkbank_Ekstre_20231009_073809_405251-PDF.exe
- File type
- application/x-dosexec
- Size
- 877056 bytes
- MD5
c05706e095169c745c5b32da5e8310ca
- SHA-1
cbf1e08bb2d37e2efbe93b9f1270a888b9e953d0
- SHA-256
7e6b3d8f37991cef921fd8c8f0a0c48a76e437665ac60db3afe271d14de9bff5
- First indexed
- 2023-10-09 15:18:29
- Last updated
- 2026-09-02 12:45:05
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.Win32.Taskun.4!c |
| Elastic | malicious (high confidence) |
| Skyhigh | BehavesLike.Win32.Generic.cc |
| McAfee | Artemis!C05706E09516 |
| Sangfor | Suspicious.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_100% (W) |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Symantec | Scr.Malcode!gdn34 |
| ESET-NOD32 | a variant of MSIL/GenKryptik.GORO |
| APEX | Malicious |
| Cynet | Malicious (score: 100) |
| Kaspersky | UDS:Trojan.MSIL.Taskun.gen |
| Avast | CrypterX-gen [Trj] |
| F-Secure | Trojan.TR/AD.GenSteal.pigws |
| Trapmine | suspicious.low.ml.score |
| Sophos | Troj/Krypt-ABH |
| SentinelOne | Static AI - Malicious PE |
| Google | Detected |
| ZoneAlarm | UDS:Trojan.MSIL.Taskun.gen |
| Microsoft | Trojan:Win32/Leonem |
| Varist | W32/MSIL_Agent.FPI.gen!Eldorado |
| Cylance | unsafe |
| Panda | Trj/Chgt.AD |
| TrendMicro-HouseCall | TROJ_GEN.F0D1C00J923 |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:4UBxEiEsEpDZ51kRmpdoeg) |
| Ikarus | Trojan.MSIL.Inject |
| MaxSecure | Trojan.Malware.300983.susgen |
| AVG | CrypterX-gen [Trj] |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| 7e6b3.Trojan.exe | |
| WerFault.exe | -u -p 4052 -s 1560 |
| WerFault.exe | -u -p 4052 -s 1560 |
| WerFault.exe | -pss -s 440 -p 4052 -ip 4052 |