846c3ade72d5ad1e20300c79208baa28d18114343c719856649406eef3b8d4e2

Classification: Malicious

846c3ade72d5ad1e20300c79208baa28d18114343c719856649406eef3b8d4e2 is a malicious file sample. Linked to Agent Tesla malware. Detected by 25 antivirus engines.

Detection summary

  • 25 antivirus detections
  • 1 IDS alerts
  • 2 processes observed
  • 1 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-06-07 00:15:09 2026-09-02 21:45:07 malicious-activity
Agent Tesla ThreatFox Abuse.ch 2024-06-05 15:50:59 2024-06-07 15:37:23 S0331 Agent Tesla
AgentTesla MalwareBazaar Abuse.ch 2024-06-05 07:52:20 2024-06-05 07:52:20 malicious-activity S0331 Agent Tesla

Tags

win.agent_tesla agentesla agenttesla negasteal evasive

Sample information

Filenames
846c3ade72d5ad1e20300c79208baa28d18114343c719856649406eef3b8d4e2, 846c3. Trojan.exe, Inv# 013140 - PO 1001621 -.exe
File type
application/x-dosexec
Size
1051648 bytes
MD5
80cc4de4362504b41b959f2b0db84ad1
SHA-1
6662822293a281303737e5465d6927ea4b6a2057
SHA-256
846c3ade72d5ad1e20300c79208baa28d18114343c719856649406eef3b8d4e2
First indexed
2024-06-05 08:20:44
Last updated
2026-09-02 21:45:08

Antivirus detections

EngineDetection
APEXMalicious
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_90% (W)
CylanceUnsafe
DeepInstinctMALICIOUS
ESET-NOD32a variant of Win32/Injector.Autoit.GAY
Elasticmalicious (high confidence)
FortinetAutoIt/Injector.FZW!tr
GoogleDetected
IkarusWin32.Outbreak
KasperskyUDS:DangerousObject.Multi.Generic
LionicTrojan.Win32.AutoIt.4!c
MalwarebytesMalware.AI.57477377
McAfeeArtemis!80CC4DE43625
McAfeeDti!846C3ADE72D5
MicrosoftTrojan:Win32/AutoitInject.OWAA!MTB
Paloaltogeneric.ml
SangforTrojan.Win32.Autoit.Voie
SkyhighBehavesLike.Win32.Injector.th
SophosTroj/AutoIt-DGJ
TrendMicro-HouseCallTROJ_GEN.F0D1C00F424
VBA32Trojan.Autoit.F
VaristW32/AutoIt.YE.gen!Eldorado
ZoneAlarmUDS:DangerousObject.Multi.Generic

Network contacts

172.67.74.152

DNS requests

api.ipify.org

Process list

NameCommand line
846c3.Trojan.exe
RegSvcs.exe"C:\846c3.Trojan.exe"