Amapejoxiqivi Trojan AgentTesla Analysis

Trojan AgentTesla
Updated on 2024-03-27 (1 month ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.170.174
DB Version:2024-03-27 16:00:23

Trojan.Win64.AgentTesla.tr

AgentTesla is a Remote Access Trojan (RAT) built on the .Net framework, primarily utilized to acquire initial access to systems. It's frequently employed within the framework of Malware-As-A-Service (MaaS). Within this illicit business model, individuals referred to as "initial access brokers" (IAB) offer their specialized expertise to criminal groups seeking to exploit corporate networks. As an initial-stage malware, AgentTesla facilitates remote access to a compromised system, subsequently permitting the downloading of more advanced secondary tools, including ransomware.

FileAmapejoxiqivi
Checked2024-03-27 16:33:00
MD5a4e1da4de6991f0e7e6de4ab3497563c
SHA155fa99225cb02841d4b8bd4d207831f8631fe855
SHA256143255a5ba28e866c50698c6ba81c7aa37cc517dd3499754136be7cea093afb2
SHA5126c7dbda6d53963f5f20a150cc56f537d86a397f63e214c98ce78f110481cecdd2c36219a9ea9af17376d5ab0e1f6b86dfc4fdadcfa10529960de01660344d59c
File Size684128 bytes

Trojan.Win64.AgentTesla.tr Removal

Trojan.Win64.AgentTesla.tr Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.AgentTesla.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation0x0000 0x04b0
CompanyNameAjasereqoqahotipi
FileDescriptionAxitelox Aditanulugu Ibelazuyolopaguvuce Okapixudafulet Iwoxuha Oqotewafo Uxicivine Owapoliteyulasoharo Adunokeqowudonomare.
FileVersion6.91.287.16
InternalNameAmapejoxiqivi
LegalCopyright© 2027 Ajasereqoqahotipi
OriginalFilenameEgeqiqajopun
ProductNameAsawimoqojan
ProductVersion6.91.287.16
CommentsIhitinomuketufajebete Obiyumekecojefin Itahuju Ojosoresejoxoxoji Ahoviwavogat Ezizazikufug Eqavuci Ekuvadaqisexab Ubobegexipo.
Translation0x0000 0x04b0
CompanyNameAjasereqoqahotipi
FileDescriptionAxitelox Aditanulugu Ibelazuyolopaguvuce Okapixudafulet Iwoxuha Oqotewafo Uxicivine Owapoliteyulasoharo Adunokeqowudonomare.
FileVersion6.91.287.16
InternalNameAmapejoxiqivi
LegalCopyright© 2027 Ajasereqoqahotipi
OriginalFilenameEgeqiqajopun
ProductNameAsawimoqojan
ProductVersion6.91.287.16
CommentsIhitinomuketufajebete Obiyumekecojefin Itahuju Ojosoresejoxoxoji Ahoviwavogat Ezizazikufug Eqavuci Ekuvadaqisexab Ubobegexipo.

Portable Executable Info

Image Base:0x00400000
Entry Point:0x00400000
Compilation:2088-08-31 21:49:55
Checksum:0x00000000 (Actual: 0x000a7a5a)
OS Version:4.0
PDB Path:C:\Windows\Containers\Confidential\DotnetGenerator\Stub\Projects\HFayo\obj\Release\HFayo.pdb
PEiD:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:2
Imports: 0
Exports: 0
Resources:3

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x000120ea 0x00012200 584cbdb9d31dbfc99355157ec26d0dab 5.91
.rsrc 0x00016000 0x00000c6c 0x00000e00 8979c178feebcde5111c02b9e0a9d8af 4.31

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware