8632a6cdacd3c2ca44c427d1ef6bea4a9c16a7089a31f12fe79ba6e108860902

Classification: Malicious

8632a6cdacd3c2ca44c427d1ef6bea4a9c16a7089a31f12fe79ba6e108860902 is a malicious file sample. Linked to Agent Tesla malware. Detected by 82 antivirus engines.

Detection summary

  • 82 antivirus detections (54% detection ratio)
  • 1 IDS alerts
  • 6 processes observed
  • 2 contacted hosts
  • 2 DNS requests

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-15 14:45:05 2026-09-03 00:45:09 malicious-activity
Spyware VM-Ray 2023-11-15 17:22:37 2023-11-15 17:22:37
Keylogger VM-Ray 2023-11-15 17:22:37 2023-11-15 17:22:37
AgentTesla MalwareBazaar Abuse.ch 2023-11-15 14:27:15 2023-11-15 14:27:15 malicious-activity S0331 Agent Tesla

Tags

evasive

Sample information

Filenames
8632a6cdacd3c2ca44c427d1ef6bea4a9c16a7089a31f12fe79ba6e108860902, 8632a6cdacd3c2ca44c427d1ef6bea4a9c16a7089a31f12fe79ba6e108860902.exe, obizx.exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
730112 bytes
MD5
07ff2e53678892b871dc14286df16edc
SHA-1
2308987959856cd9245855688ef4779cf71251e7
SHA-256
8632a6cdacd3c2ca44c427d1ef6bea4a9c16a7089a31f12fe79ba6e108860902
First indexed
2023-11-15 14:26:32
Last updated
2026-09-03 00:45:09

Antivirus detections

EngineDetection
LionicTrojan.Win32.Agensla.i!c
SkyhighBehavesLike.Win32.Generic.bc
McAfeeArtemis!07FF2E536788
MalwarebytesTrojan.MalPack.PNG.Generic
SangforInfostealer.Msil.Kryptik.Vjxb
K7AntiVirusTrojan ( 005adf1c1 )
BitDefenderTrojan.GenericKD.70394791
K7GWTrojan ( 005adf1c1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn33
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AKDF
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
RisingStealer.Agensla!8.13266 (CLOUD)
SophosTroj/Krypt-ABH
F-SecureTrojan.TR/AD.Nekark.hampv
DrWebTrojan.Packed2.45901
TrendMicroTrojanSpy.Win32.NEGASTEAL.YXDKNZ
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.07ff2e53678892b8
IkarusTrojan.MSIL.Inject
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/AD.Nekark.hampv
VaristW32/MSIL_Kryptik.KDD.gen!Eldorado
Kingsoftmalware.kb.c.946
MicrosoftHackTool:Win64/Mimikatz.A
GridinsoftTrojan.Win32.AgentTesla.bot
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataWin32.Trojan.Agent.7977AL
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5541818
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.NEGASTEAL.YXDKNZ
SentinelOneStatic AI - Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ATU!tr
AVGFileRepMalware [Pws]
AvastFileRepMalware [Pws]
AVGWin32:MalwareX-gen [Pws]
AlibabaTrojanPSW:MSIL/AgentTesla.09dda317
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitIL:Trojan.MSILZilla.D89EF
AvastWin32:MalwareX-gen [Pws]
AviraHEUR/AGEN.1374281
BitDefenderIL:Trojan.MSILZilla.35311
BkavW32.AIDetectMalware.CS
CTXexe.trojan.msil
CylanceUnsafe
ESET-NOD32MSIL/Kryptik.AKDF trojan
EmsisoftIL:Trojan.MSILZilla.35311 (B)
F-SecureHeuristic.HEUR/AGEN.1374281
FortinetMSIL/Formbook.D5D0!tr.spy
GDataIL:Trojan.MSILZilla.35311
GridinsoftTrojan.Win32.AgentTesla.st!i
K7AntiVirusTrojan ( 700000201 )
K7GWTrojan ( 700000201 )
KingsoftMSIL.Trojan-PSW.Agensla.gen
LionicTrojan.Win32.AgentTesla.i!c
McAfeeDti!8632A6CDACD3
MicroWorld-eScanIL:Trojan.MSILZilla.35311
MicrosoftTrojan:MSIL/AgentTesla.ARAA!MTB
NANO-AntivirusTrojan.Win32.Agensla.kdtexk
Paloaltogeneric.ml
RisingMalware.Obfus/[email protected] (RDM.MSIL2:pTXCXl6ScJGb9D/SNVHltw)
SangforSuspicious.Win32.Save.a
SentinelOneStatic AI - Suspicious PE
SkyhighGenericRXWL-PB!07FF2E536788
TACHYONTrojan-PWS/W32.DN-AgentTesla.730112.F
TencentMalware.Win32.Gencirc.13f712a1
TrellixENSGenericRXWL-PB!07FF2E536788
TrendMicro-HouseCallTrojan.Win32.VSX.PE04C9z
VBA32TScope.Trojan.MSIL
VIPREIL:Trojan.MSILZilla.35311
ZillyaTrojan.Kryptik.Win32.4546281
ZoneAlarmTroj/Krypt-ABH
alibabacloudTrojan[stealer]:MSIL/AgentTesla.AVZO3DGW
huorongTrojanSpy/MSIL.AgentTesla.mq

Network contacts

104.26.12.205 91.235.128.141

DNS requests

api.ipify.org cp5ua.hyperhost.ua

Process list

NameCommand line
obizx.exe
obizx.exe
obizx.exe
obizx.exe
obizx.exe
obizx.exe