e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a
Classification: Malicious
e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a is a malicious file sample. Linked to Fin8, Fin7 activity. Detected by 61 antivirus engines.
Detection summary
- 61 antivirus detections (48% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Fin8 |
Maltiverse |
2023-08-18 04:16:05 |
2023-08-19 20:21:52 |
malicious-activity
|
G0061 FIN8
|
| Fin7 |
Maltiverse |
2023-08-18 04:16:05 |
2023-08-19 20:21:50 |
malicious-activity
|
G0046 FIN7
|
| Generic Malware |
Hybrid-Analysis |
2023-07-24 12:30:15 |
2023-07-24 12:30:15 |
|
|
Tags
apt
backdoor
infostealer
qakbot
ransomware
Sample information
- Filenames
- e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a
- File type
- PE32+ executable (DLL) (console) x86-64 Mono/.Net ...
- Size
- 197632 bytes
- MD5
52aa13beb502a784626b674c76169c08
- SHA-1
e8d3e810d1752237b2121cde19719c282acecd75
- SHA-256
e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a
- First indexed
- 2023-07-24 12:15:46
- Last updated
- 2025-10-04 00:00:39
Antivirus detections
| Engine | Detection |
| Bkav | W32.Common.A8D256FD |
| Lionic | Trojan.Win32.Agentb.X!c |
| Elastic | malicious (moderate confidence) |
| Cynet | Malicious (score: 99) |
| CAT-QuickHeal | Trojan.MSIL |
| ALYac | Trojan.Agent.GFRR |
| Cylance | unsafe |
| VIPRE | Trojan.Agent.GFRR |
| Sangfor | Suspicious.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_100% (W) |
| BitDefender | Trojan.Agent.GFRR |
| Symantec | Trojan Horse |
| tehtris | Generic.Malware |
| ESET-NOD32 | a variant of MSIL/Agent.WIH |
| Kaspersky | HEUR:Trojan.MSIL.Agentb.gen |
| MicroWorld-eScan | Trojan.Agent.GFRR |
| Emsisoft | Trojan.Agent.GFRR (B) |
| F-Secure | Trojan.TR/Agent.aqgf |
| McAfee-GW-Edition | BehavesLike.Win64.BadFile.cc |
| FireEye | Trojan.Agent.GFRR |
| Sophos | Troj/MSILAg-AB |
| SentinelOne | Static AI - Suspicious PE |
| Webroot | W32.Trojan.Gen |
| Avira | TR/Agent.aqgf |
| MAX | malware (ai score=80) |
| Microsoft | Trojan:MSIL/AgentTesla!MSR |
| Gridinsoft | Trojan.Heur!.031122C2 |
| Arcabit | Trojan.Agent.GFRR |
| ZoneAlarm | HEUR:Trojan.MSIL.Agentb.gen |
| GData | Trojan.Agent.GFRR |
| Google | Detected |
| McAfee | Artemis!52AA13BEB502 |
| Panda | Trj/Chgt.AD |
| DeepInstinct | MALICIOUS |
| ALYac | Trojan.MSIL.Agent |
| AVG | Win64:MalwareX-gen [Misc] |
| AhnLab-V3 | Trojan/Win.Generic.C5594283 |
| Avast | Win64:MalwareX-gen [Misc] |
| Bkav | W64.AIDetectMalware.CS |
| CAT-QuickHeal | Trojan.Malagent.S30640132 |
| CTX | dll.trojan.msil |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| Elastic | malicious (high confidence) |
| Gridinsoft | Trojan.Heur!.0311A2C2 |
| Ikarus | Trojan.MSIL.Agent |
| K7AntiVirus | Trojan ( 005a975a1 ) |
| K7GW | Trojan ( 005a975a1 ) |
| Malwarebytes | Trojan.Agent.MSIL |
| MaxSecure | Trojan.Malware.73701643.susgen |
| McAfeeD | ti!E4E3A4F1C87F |
| Paloalto | generic.ml |
| Skyhigh | BehavesLike.Win64.PWSZbot.cc |
| Tencent | Msil.Trojan.Agentb.Qsmw |
| TrellixENS | Artemis!52AA13BEB502 |
| TrendMicro | TROJ_GEN.R002C0DGO23 |
| TrendMicro-HouseCall | TROJ_GEN.R002C0DGO23 |
| Varist | W64/Agent.NEDJ |
| Zillya | Trojan.Agent.Win32.3606173 |
| ZoneAlarm | Troj/MSILAg-AB |
| alibabacloud | Trojan:MSIL/AgentTesla.Gen |
Process list
| Name | Command line |
| <Ignored Process> | |
| regsvr32.exe | /s "C:\e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a.dll" |