New PO.exe
Classification: Malicious
New PO.exe is a malicious file sample. Linked to Agent Tesla malware. Reported by 1 threat source, last seen 2022-04-04. Detected by 19 antivirus engines.
Detection summary
- 19 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: AGENT TESLA (S0331)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| AgentTesla | MalwareBazaar Abuse.ch | 2022-04-04 15:26:55 | 2022-04-04 15:26:55 | malicious-activity | S0331 Agent Tesla |
Sample information
- Filenames
- New PO.exe
- File type
- application/x-dosexec
- MD5
13213e066759038b9ba283565e87112d- SHA-1
e576964ac51008e5b14aed121eb8dab56fa3aca9- SHA-256
c1191fcbd8bdee63912d47d867c4cbb066568194f53df3969b3aea6dfd3734a5- First indexed
- 2022-04-04 16:15:08
- Last updated
- 2026-09-02 19:47:42
Antivirus detections
| Engine | Detection |
|---|---|
| Elastic | malicious (high confidence) |
| Cyren | W32/MSIL_Kryptik.DLB.gen!Eldorado |
| Symantec | Scr.Malcode!gdn30 |
| tehtris | Generic.Malware |
| ESET-NOD32 | a variant of MSIL/Kryptik.AESH |
| Paloalto | generic.ml |
| Kaspersky | UDS:Trojan-PSW.MSIL.Agensla |
| Avast | KeyloggerX-gen [Trj] |
| McAfee-GW-Edition | BehavesLike.Win32.Fareit.bc |
| SentinelOne | Static AI - Malicious PE |
| Trapmine | malicious.moderate.ml.score |
| Ikarus | Win32.Outbreak |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Cynet | Malicious (score: 100) |
| Malwarebytes | Malware.AI.3379172464 |
| APEX | Malicious |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | MSIL/Kryptik.ZXG!tr |
| AVG | KeyloggerX-gen [Trj] |