84751bcf03258a672747728fe92c31c4a97bb7cc409960e94557a909ae60ba04

Classification: Malicious

84751bcf03258a672747728fe92c31c4a97bb7cc409960e94557a909ae60ba04 is a malicious file sample. Linked to Agent Tesla malware. Detected by 71 antivirus engines.

Detection summary

  • 71 antivirus detections
  • 2 IDS alerts
  • 2 processes observed
  • 3 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2024-01-30 01:00:03 2026-09-02 21:45:07 malicious-activity
AgentTesla MalwareBazaar Abuse.ch 2024-01-30 00:45:25 2024-01-30 00:45:25 malicious-activity S0331 Agent Tesla

Tags

evasive windows-server-utility malicious

Sample information

Filenames
84751bcf03258a672747728fe92c31c4a97bb7cc409960e94557a909ae60ba04, SecuriteInfo.com.Variant.Lazy.469857.25240.19205
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
342528 bytes
MD5
afca8f7a63a18a7c982b4fece0f8840c
SHA-1
0359612c1b3f96dd0540b3b380f776c78d6157fd
SHA-256
84751bcf03258a672747728fe92c31c4a97bb7cc409960e94557a909ae60ba04
First indexed
2024-01-30 00:46:39
Last updated
2026-09-02 21:45:07

Antivirus detections

EngineDetection
ALYacGen:Variant.Lazy.469857
APEXMalicious
AhnLab-V3Malware/Gen.RL_Reputation.C4311841
ArcabitTrojan.Lazy.D72B61
BitDefenderGen:Variant.Lazy.469857
BitDefenderThetaGen:NN.ZemsilF.36680.um0@aip1b3h
BkavW32.AIDetectMalware.CS
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.c1b3f9
Cylanceunsafe
CynetMalicious (score: 100)
DeepInstinctMALICIOUS
ESET-NOD32a variant of MSIL/GenKryptik.GTCR
Elasticmalicious (high confidence)
EmsisoftGen:Variant.Lazy.469857 (B)
FireEyeGeneric.mg.afca8f7a63a18a7c
FortinetMSIL/GenKryptik.GTCR!tr
GDataGen:Variant.Lazy.469857
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
MAXmalware (ai score=85)
MaxSecureTrojan.Malware.300983.susgen
MicroWorld-eScanGen:Variant.Lazy.469857
MicrosoftTrojan:Win32/Wacatac.B!ml
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Malicious PE
SkyhighBehavesLike.Win32.Generic.fh
SophosGeneric ML PUA (PUA)
SymantecML.Attribute.HighConfidence
TencentMsil.Trojan-QQPass.QQRob.Iajl
ZoneAlarmHEUR:Trojan-PSW.MSIL.Disco.gen
AVGWin32:PWSX-gen [Trj]
AlibabaTrojanPSW:MSIL/AgentTesla.00513eb2
Antiy-AVLTrojan/MSIL.GenKryptik
AvastWin32:PWSX-gen [Trj]
AviraHEUR/AGEN.1371297
CTXexe.trojan.msil
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
DrWebBackDoor.SpyBotNET.62
ESET-NOD32a variant of MSIL/GenKryptik.GUTR
F-SecureHeuristic.HEUR/AGEN.1371297
FortinetMSIL/Kryptik.ALKM!tr
GoogleDetected
IkarusTrojan.MSIL.Krypt
K7AntiVirusTrojan ( 005b12aa1 )
K7GWTrojan ( 005b12aa1 )
Kingsoftmalware.kb.c.999
LionicTrojan.Win32.Disco.4!c
MalwarebytesTrojan.Crypt.MSIL.Generic
MaxSecureTrojan.Malware.115904540.susgen
McAfeeArtemis!AFCA8F7A63A1
McAfeeDReal Protect-LS!AFCA8F7A63A1
MicrosoftTrojan:MSIL/AgentTesla
NANO-AntivirusTrojan.Win32.Disco.kieqps
Paloaltogeneric.ml
PandaTrj/Chgt.AD
RisingMalware.Obfus/[email protected] (RDM.MSIL2:rn8soymupZXLe88mtT1o/w)
SophosMal/Generic-S
SymantecTrojan Horse
TencentMalware.Win32.Gencirc.13ff44fb
Trapminemalicious.moderate.ml.score
VBA32TScope.Trojan.MSIL
VIPREGen:Variant.Lazy.469857
VaristW32/MSIL_Kryptik.KWV.gen!Eldorado
VirITTrojan.Win32.Genus.VAW
WebrootW32.Adware.Gen
XcitiumMalware@#y9tv0yhj23kf
YandexTrojan.GenKryptik!PDdeAAN81f0
ZillyaTrojan.GenKryptik.Win32.428415
alibabacloudTrojan[stealer]:MSIL/Disco.gen
huorongTrojan/Generic!2DF56297743237FA

Network contacts

104.26.12.205 179.43.183.46 173.231.16.75

DNS requests

api.ipify.org mail.officeemailbackup.com

Process list

NameCommand line
SecuriteInfo.com.Variant.Lazy.469857.25240.19205.exe
SecuriteInfo.com.Variant.Lazy.469857.25240.19205.exe