Gridinsoft Logo

Spermis.exe Trojan AgentTesla Analysis

Trojan AgentTesla
Updated on 2024-06-30 (3 months ago)
Checked by Online Virus Scanner
Online Virus Checker v.1.0.181.174
DB Version: 2024-06-30 08:00:11

Trojan.Win64.AgentTesla.tr

AgentTesla is a Remote Access Trojan (RAT) built on the .Net framework, primarily utilized to acquire initial access to systems. It's frequently employed within the framework of Malware-As-A-Service (MaaS). Within this illicit business model, individuals referred to as "initial access brokers" (IAB) offer their specialized expertise to criminal groups seeking to exploit corporate networks. As an initial-stage malware, AgentTesla facilitates remote access to a compromised system, subsequently permitting the downloading of more advanced secondary tools, including ransomware.

File spermis.exe
Checked 2024-06-30 05:56:24
MD5 db8304f8a6293c2d0d4b7cf032850d62
SHA1 d2a6258b3f2df2a96b2f1fc3f1f7ea4ad38f09da
SHA256 20007df38d3098c13edd282b59935f2c042d92c46f2fa4cac2de616e63e0f1d5
SHA512 49078b299ccf377604acc8d8fd528b0ed4cb8007ede0b36cce4c2954432134057f14c0e9445e11d6a82413950df2479c69e14cc44b60203e6a9924e7d96c7825
File Size 2453504 bytes

Trojan.Win64.AgentTesla.tr Removal

Trojan.Win64.AgentTesla.tr Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win64.AgentTesla.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation 0x0000 0x04b0
Comments
CompanyName
FileDescription NerestPC recode
FileVersion 1.0.0.0
InternalName NerestPC recode.exe
LegalCopyright Copyright © 2024
LegalTrademarks
OriginalFilename NerestPC recode.exe
ProductName NerestPC recode
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Portable Executable Info

8d74db0052851164a08bc3381d730a03
c2f17a2cf8ae435060d7b71b65d1a2e9
e422a8c8694a9be0
Image Base: 0x00400000
Entry Point: 0x00400000
Compilation: 2091-11-05 18:08:36
Checksum: 0x00000000 (Actual: 0x00262df3)
OS Version: 4.0
PEiD: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
Sign: The PE file does not contain a certificate table.
Sections: 4
Imports: 0
Exports: 0
Resources: 4

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x0010ffe0 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.uE/ 0x00112000 0x0012a2ff 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.Co[ 0x0023e000 0x00249bc8 0x00249c00 05452ab553bff2ca88216f90f2532192 7.97
.rsrc 0x00488000 0x0000cf94 0x0000d000 014ba90daeb4e6bb2f9c8dfb847f1074 7.87

Leave a comment *

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware