Jbvq.exe Trojan AgentTesla Analysis

Trojan AgentTesla
Updated on 2024-03-27 (1 month ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.170.174
DB Version:2024-03-27 16:00:23

Trojan.Win32.AgentTesla.tr

AgentTesla is a Remote Access Trojan (RAT) built on the .Net framework, primarily utilized to acquire initial access to systems. It's frequently employed within the framework of Malware-As-A-Service (MaaS). Within this illicit business model, individuals referred to as "initial access brokers" (IAB) offer their specialized expertise to criminal groups seeking to exploit corporate networks. As an initial-stage malware, AgentTesla facilitates remote access to a compromised system, subsequently permitting the downloading of more advanced secondary tools, including ransomware.

FileJbvq.exe
Checked2024-03-27 16:35:54
MD5f2d7baa099914c81eab964dc4c5b27ee
SHA10f4d556b793a16403f4351f3baa0ef0ff3e775b9
SHA256d9626d89b255a1226c4abe2d59a56f9dd6e720a90461591e0434c0ed2ddd3e05
SHA512403217fa4b47c9e0773e84cfcef5ce333e25319cd33a874174aef84928982c079808f3b1617613322191347824c8a01834283a41c365c38eb7352810d287eee2
Imphashf34d5f2d4577ed6d9ceec516c1f5a744
File Size651264 bytes

Trojan.Win32.AgentTesla.tr Removal

Trojan.Win32.AgentTesla.tr Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.AgentTesla.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation0x0000 0x04b0
Comments
CompanyNameFoni
FileDescriptionlabChrisUsick
FileVersion5.0.0.0
InternalNameJbvq.exe
LegalCopyrightCopyright © Foni
LegalTrademarks
OriginalFilenameJbvq.exe
ProductNamelabChrisUsick
ProductVersion5.0.0.0
Assembly Version5.0.0.0

Portable Executable Info

736028cee2d28fa059ca9fd8b24a2763
3503aac0799205ce84f7ded5e3f59052
c496baa4ecbaa6c4
Image Base:0x00400000
Entry Point:0x0049f316
Compilation:2024-03-22 18:24:23
Checksum:0x00000000 (Actual: 0x000aa613)
OS Version:4.0
PEiD:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:3
Imports: mscoree,
Exports: 0
Resources:3

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x0009d334 0x0009d400 06a6d26131770e0b8d71c658fb903659 7.98
.rsrc 0x000a0000 0x00001330 0x00001400 d6e1532f9284a8d0fe56ba13cd7a0d08 6.64
.reloc 0x000a2000 0x0000000c 0x00000400 171408517f0243d853ef95326d5f8171 0.06

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware