81c1043490096d6c818bf0eae1bfe8248d7f9b3b1217d4c769de6f29e321e635

Classification: Malicious

81c1043490096d6c818bf0eae1bfe8248d7f9b3b1217d4c769de6f29e321e635 is a malicious file sample. Linked to Agent Tesla malware. Detected by 41 antivirus engines.

Detection summary

  • 41 antivirus detections
  • 4 IDS alerts
  • 4 processes observed
  • 3 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-08-16 01:30:04 2026-09-02 17:45:05 malicious-activity
AgentTesla MalwareBazaar Abuse.ch 2024-08-09 00:56:10 2024-08-09 00:56:10 malicious-activity S0331 Agent Tesla

Tags

evasive

Sample information

Filenames
81c1043490096d6c818bf0eae1bfe8248d7f9b3b1217d4c769de6f29e321e635, RFQ# 10925.pdf.exe
File type
application/x-dosexec
Size
1309696 bytes
MD5
51db45892803b947277b04005594f3aa
SHA-1
0491c1300641db70661d790439b54a9d0276afd2
SHA-256
81c1043490096d6c818bf0eae1bfe8248d7f9b3b1217d4c769de6f29e321e635
First indexed
2024-08-09 02:18:15
Last updated
2026-09-02 17:45:05

Antivirus detections

EngineDetection
APEXMalicious
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
AviraTR/AD.ShellcodeCrypter.udtvm
BitDefenderThetaGen:NN.ZexaE.36810.pvW@amGmccji
BkavW32.AIDetectMalware
ClamAVWin.Malware.Silentall-10034109-0
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 99)
DeepInstinctMALICIOUS
DrWebTrojan.AutoIt.1430
ESET-NOD32a variant of Win32/Injector.Autoit.GFR
Elasticmalicious (high confidence)
F-SecureTrojan.TR/AD.ShellcodeCrypter.udtvm
FireEyeGeneric.mg.51db45892803b947
FortinetAutoIt/Agent.APO!tr
GDataMSIL.Trojan-Spy.Snake.J7EWKE
GoogleDetected
GridinsoftTrojan.Win32.Downloader.sa
IkarusWin32.SuspectCrc
KasperskyUDS:DangerousObject.Multi.Generic
LionicTrojan.Win64.Injects.ts93
MalwarebytesTrojan.Injector.AutoIt
MaxSecureTrojan.Malware.300983.susgen
McAfeeArtemis!51DB45892803
McAfeeDReal Protect-LS!51DB45892803
MicrosoftTrojan:Win32/Strab.GP!MTB
Paloaltogeneric.ml
RisingTrojan.Injector/Autoit!1.100B5 (CLASSIC)
SangforTrojan.Win32.Autoit.Vfyf
SkyhighBehavesLike.Win32.Injector.tc
SophosTroj/AutoIt-DGJ
TrendMicroTrojanSpy.Win32.SNAKEKEYLOGGER.YXEHIZ
TrendMicro-HouseCallTrojanSpy.Win32.SNAKEKEYLOGGER.YXEHIZ
VBA32Trojan.Autoit.F
VaristW32/Autoit.THVB-3408
VirITTrojan.Win32.AutoIt_Heur.A
WebrootW32.Injector.Gen
ZoneAlarmUDS:DangerousObject.Multi.Generic
alibabacloudSoftware:Multi/Strab.GX8PHU

Network contacts

193.122.6.168 172.67.177.134 132.226.247.73

DNS requests

checkip.dyndns.org reallyfreegeoip.org

Process list

NameCommand line
RFQ#10925.pdf.exe
RegSvcs.exe"C:\RFQ#10925.pdf.exe"
RFQ#10925.pdf.exe
RegSvcs.exe"C:\RFQ#10925.pdf.exe"