e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a

Classification: Malicious

e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a is a malicious file sample. Linked to Fin8, Fin7 activity. Detected by 61 antivirus engines.

Detection summary

  • 61 antivirus detections (48% detection ratio)
  • 0 IDS alerts
  • 2 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Intrusion sets: FIN8 (G0061) FIN7 (G0046)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Fin8 Maltiverse 2023-08-18 04:16:05 2023-08-19 20:21:52 malicious-activity G0061 FIN8
Fin7 Maltiverse 2023-08-18 04:16:05 2023-08-19 20:21:50 malicious-activity G0046 FIN7
Generic Malware Hybrid-Analysis 2023-07-24 12:30:15 2023-07-24 12:30:15

Tags

apt backdoor infostealer qakbot ransomware

Sample information

Filenames
e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a
File type
PE32+ executable (DLL) (console) x86-64 Mono/.Net ...
Size
197632 bytes
MD5
52aa13beb502a784626b674c76169c08
SHA-1
e8d3e810d1752237b2121cde19719c282acecd75
SHA-256
e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a
First indexed
2023-07-24 12:15:46
Last updated
2025-10-04 00:00:39

Antivirus detections

EngineDetection
BkavW32.Common.A8D256FD
LionicTrojan.Win32.Agentb.X!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.MSIL
ALYacTrojan.Agent.GFRR
Cylanceunsafe
VIPRETrojan.Agent.GFRR
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Agent.GFRR
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Agent.WIH
KasperskyHEUR:Trojan.MSIL.Agentb.gen
MicroWorld-eScanTrojan.Agent.GFRR
EmsisoftTrojan.Agent.GFRR (B)
F-SecureTrojan.TR/Agent.aqgf
McAfee-GW-EditionBehavesLike.Win64.BadFile.cc
FireEyeTrojan.Agent.GFRR
SophosTroj/MSILAg-AB
SentinelOneStatic AI - Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Agent.aqgf
MAXmalware (ai score=80)
MicrosoftTrojan:MSIL/AgentTesla!MSR
GridinsoftTrojan.Heur!.031122C2
ArcabitTrojan.Agent.GFRR
ZoneAlarmHEUR:Trojan.MSIL.Agentb.gen
GDataTrojan.Agent.GFRR
GoogleDetected
McAfeeArtemis!52AA13BEB502
PandaTrj/Chgt.AD
DeepInstinctMALICIOUS
ALYacTrojan.MSIL.Agent
AVGWin64:MalwareX-gen [Misc]
AhnLab-V3Trojan/Win.Generic.C5594283
AvastWin64:MalwareX-gen [Misc]
BkavW64.AIDetectMalware.CS
CAT-QuickHealTrojan.Malagent.S30640132
CTXdll.trojan.msil
CylanceUnsafe
CynetMalicious (score: 100)
Elasticmalicious (high confidence)
GridinsoftTrojan.Heur!.0311A2C2
IkarusTrojan.MSIL.Agent
K7AntiVirusTrojan ( 005a975a1 )
K7GWTrojan ( 005a975a1 )
MalwarebytesTrojan.Agent.MSIL
MaxSecureTrojan.Malware.73701643.susgen
McAfeeDti!E4E3A4F1C87F
Paloaltogeneric.ml
SkyhighBehavesLike.Win64.PWSZbot.cc
TencentMsil.Trojan.Agentb.Qsmw
TrellixENSArtemis!52AA13BEB502
TrendMicroTROJ_GEN.R002C0DGO23
TrendMicro-HouseCallTROJ_GEN.R002C0DGO23
VaristW64/Agent.NEDJ
ZillyaTrojan.Agent.Win32.3606173
ZoneAlarmTroj/MSILAg-AB
alibabacloudTrojan:MSIL/AgentTesla.Gen

Process list

NameCommand line
<Ignored Process>
regsvr32.exe/s "C:\e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a.dll"