864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976
Classification: Malicious
864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976 is a malicious file sample. Linked to Agent Tesla malware. Detected by 46 antivirus engines.
Detection summary
- 46 antivirus detections (63% detection ratio)
- 0 IDS alerts
- 5 processes observed
- 0 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2023-11-20 15:00:05 |
2026-09-03 00:45:08 |
malicious-activity
|
|
| AgentTesla |
MalwareBazaar Abuse.ch |
2023-11-20 14:33:42 |
2023-11-20 14:33:42 |
malicious-activity
|
S0331 Agent Tesla
|
Tags
ransomware
evasive
infostealer
Sample information
- Filenames
- 864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976, PPAP-EDP F-678605..exe
- File type
- PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
- Size
- 858624 bytes
- MD5
8fc0f2641714f0e67e0a7c0b9a736c93
- SHA-1
8e9affa0c7dba687dbd559f9ee1cdb86119dd856
- SHA-256
864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976
- First indexed
- 2023-11-20 14:32:48
- Last updated
- 2026-09-03 00:45:08
Antivirus detections
| Engine | Detection |
| Lionic | Trojan.Win32.Taskun.4!c |
| MicroWorld-eScan | Gen:Variant.Ransom.Loki.10386 |
| Skyhigh | Artemis |
| McAfee | Artemis!8FC0F2641714 |
| Cylance | unsafe |
| Sangfor | Trojan.Msil.Kryptik.Vq08 |
| Alibaba | Trojan:MSIL/GenKryptik.384e60ad |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Arcabit | Trojan.Ransom.Loki.D2892 |
| BitDefenderTheta | Gen:NN.ZemsilF.36792.0m0@aiBKKwp |
| VirIT | Trojan.Win32.MSIL_Heur.A |
| Symantec | Scr.Malcode!gdn33 |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | a variant of MSIL/Kryptik.AKER |
| Cynet | Malicious (score: 100) |
| APEX | Malicious |
| Kaspersky | HEUR:Trojan.MSIL.Taskun.gen |
| BitDefender | Gen:Variant.Ransom.Loki.10386 |
| Avast | Win32:PWSX-gen [Trj] |
| Sophos | Troj/Krypt-ABH |
| F-Secure | Trojan.TR/Kryptik.gejzz |
| VIPRE | Gen:Variant.Ransom.Loki.10386 |
| Trapmine | malicious.high.ml.score |
| FireEye | Generic.mg.8fc0f2641714f0e6 |
| Emsisoft | Gen:Variant.Ransom.Loki.10386 (B) |
| SentinelOne | Static AI - Malicious PE |
| Varist | W32/Faker.J.gen!Eldorado |
| Avira | TR/Kryptik.gejzz |
| Kingsoft | malware.kb.c.952 |
| Gridinsoft | Trojan.Win32.Gen.se!i |
| Microsoft | Trojan:MSIL/AgentTesla.ASFW!MTB |
| ZoneAlarm | HEUR:Trojan.MSIL.Taskun.gen |
| GData | Win32.Trojan.Agent.FTJ6LV |
| Google | Detected |
| ALYac | Gen:Variant.Ransom.Loki.10386 |
| MAX | malware (ai score=85) |
| Malwarebytes | Generic.Malware.AI.DDS |
| Panda | Trj/GdSda.A |
| TrendMicro-HouseCall | TROJ_GEN.F0D1C00KK23 |
| Rising | Malware.Obfus/[email protected] (RDM.MSIL2:UmxNNWmLnZyMGp5IuHyKhQ) |
| Yandex | Trojan.Igent.b1e20D.2 |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | MSIL/GenKryptik.GCKQ!tr |
| AVG | Win32:PWSX-gen [Trj] |
| Cybereason | malicious.0c7dba |
| DeepInstinct | MALICIOUS |
Process list
| Name | Command line |
| PPAP-EDPF-678605..exe | |
| powershell.exe | Add-MpPreference -ExclusionPath "C:\PPAP-EDPF-678605..exe" |
| powershell.exe | Add-MpPreference -ExclusionPath "%APPDATA%\gRPoIHPUWHnl.exe" |
| schtasks.exe | /Create /TN "Updates\gRPoIHPUWHnl" /XML "%TEMP%\tmp5E00.tmp" |
| RegSvcs.exe | |