864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976

Classification: Malicious

864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976 is a malicious file sample. Linked to Agent Tesla malware. Detected by 46 antivirus engines.

Detection summary

  • 46 antivirus detections (63% detection ratio)
  • 0 IDS alerts
  • 5 processes observed
  • 0 contacted hosts
  • 1 DNS requests

MITRE ATT&CK associations

Malware families: AGENT TESLA (S0331)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2023-11-20 15:00:05 2026-09-03 00:45:08 malicious-activity
AgentTesla MalwareBazaar Abuse.ch 2023-11-20 14:33:42 2023-11-20 14:33:42 malicious-activity S0331 Agent Tesla

Tags

ransomware evasive infostealer

Sample information

Filenames
864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976, PPAP-EDP F-678605..exe
File type
PE32 executable (GUI) Intel 80386 Mono/.Net assemb ...
Size
858624 bytes
MD5
8fc0f2641714f0e67e0a7c0b9a736c93
SHA-1
8e9affa0c7dba687dbd559f9ee1cdb86119dd856
SHA-256
864fd318ac33d9788aaaa7ec0414ace672ca381ef2f7d4d878e3e4789c9b8976
First indexed
2023-11-20 14:32:48
Last updated
2026-09-03 00:45:08

Antivirus detections

EngineDetection
LionicTrojan.Win32.Taskun.4!c
MicroWorld-eScanGen:Variant.Ransom.Loki.10386
SkyhighArtemis
McAfeeArtemis!8FC0F2641714
Cylanceunsafe
SangforTrojan.Msil.Kryptik.Vq08
AlibabaTrojan:MSIL/GenKryptik.384e60ad
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Ransom.Loki.D2892
BitDefenderThetaGen:NN.ZemsilF.36792.0m0@aiBKKwp
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn33
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AKER
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderGen:Variant.Ransom.Loki.10386
AvastWin32:PWSX-gen [Trj]
SophosTroj/Krypt-ABH
F-SecureTrojan.TR/Kryptik.gejzz
VIPREGen:Variant.Ransom.Loki.10386
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8fc0f2641714f0e6
EmsisoftGen:Variant.Ransom.Loki.10386 (B)
SentinelOneStatic AI - Malicious PE
VaristW32/Faker.J.gen!Eldorado
AviraTR/Kryptik.gejzz
Kingsoftmalware.kb.c.952
GridinsoftTrojan.Win32.Gen.se!i
MicrosoftTrojan:MSIL/AgentTesla.ASFW!MTB
ZoneAlarmHEUR:Trojan.MSIL.Taskun.gen
GDataWin32.Trojan.Agent.FTJ6LV
GoogleDetected
ALYacGen:Variant.Ransom.Loki.10386
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00KK23
RisingMalware.Obfus/[email protected] (RDM.MSIL2:UmxNNWmLnZyMGp5IuHyKhQ)
YandexTrojan.Igent.b1e20D.2
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.GCKQ!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.0c7dba
DeepInstinctMALICIOUS

DNS requests

**

Process list

NameCommand line
PPAP-EDPF-678605..exe
powershell.exeAdd-MpPreference -ExclusionPath "C:\PPAP-EDPF-678605..exe"
powershell.exeAdd-MpPreference -ExclusionPath "%APPDATA%\gRPoIHPUWHnl.exe"
schtasks.exe/Create /TN "Updates\gRPoIHPUWHnl" /XML "%TEMP%\tmp5E00.tmp"
RegSvcs.exe