MB-094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
high
📛 Threat Title
AgentTesla: COPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe
Description
File type: exe. Size: 472064 bytes. Tags: AgentTesla, exe. Reporter: abuse_ch. First seen: 2020-02-13 11:55:46.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
copy-scanb840284-img-2020-13-02-document-pdf.exe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/copy-scanb840284-img-2020-13-02-document-pdf.exe
IOC database
- Type
- domain
- Value
copy-scanb840284-img-2020-13-02-document-pdf.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/copy-scanb840284-img-2020-13-02-document-pdf.exe
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 650 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
VT 57 / 75
IOC database
- Type
- hash_sha256
- Value
094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- AgentTesla
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 57 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Generic.C4009441 |
| Alibaba | malicious | Trojan:Win32/CSKryptik.ali2000030 |
| alibabacloud | malicious | Backdoor:MSIL/Noancooe.A |
| ALYac | malicious | Spyware.AgentTesla |
| Antiy-AVL | malicious | Trojan[Spy]/MSIL.Noon |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.DFCFA |
| Avira | malicious | HEUR/AGEN.1323934 |
| BitDefender | malicious | Trojan.GenericKDZ.64762 |
| Bkav | malicious | W32.Malware.41DF1E1E |
| CAT-QuickHeal | malicious | Trojan.YakbeexMSIL.ZZ4 |
| ClamAV | malicious | Win.Packed.Generickdz-10031713-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DrWeb | malicious | Trojan.PackedNET.211 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKDZ.64762 (B) |
| ESET-NOD32 | malicious | MSIL/TrojanDropper.Agent.EOZ trojan |
| F-Secure | malicious | Heuristic.HEUR/AGEN.1323934 |
| Fortinet | malicious | MSIL/Agent.EOZ!tr.dldr |
| GData | malicious | Trojan.GenericKDZ.64762 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Generic!CFBB9098823D5E7A |
| Ikarus | malicious | Trojan.MSIL.Crypt |
| Jiangmin | malicious | TrojanSpy.MSIL.anac |
| K7AntiVirus | malicious | Trojan ( 700000201 ) |
| K7GW | malicious | Trojan ( 700000201 ) |
| Kaspersky | malicious | HEUR:Trojan-Spy.MSIL.Noon.gen |
| Kingsoft | malicious | malware.kb.c.1000 |
| Lionic | malicious | Trojan.Win32.Noon.l!c |
| Malwarebytes | malicious | Trojan.Crypt.MSIL |
| MaxSecure | malicious | Trojan.Malware.73691310.susgen |
| McAfeeD | malicious | ti!094FD325049B |
| Microsoft | malicious | Trojan:Win32/Occamy.C09 |
| MicroWorld-eScan | malicious | Trojan.GenericKDZ.64762 |
| NANO-Antivirus | malicious | Trojan.Win32.PackedNET.hanopy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Spyware.Noon!8.E7C9 (KTSE) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | GenericRXJQ-HT!2F6432C5AF8D |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| tehtris | malicious | Generic.Malware |
| Tencent | malicious | Malware.Win32.Gencirc.144f9c70 |
| TrellixENS | malicious | GenericRXJQ-HT!2F6432C5AF8D |
| TrendMicro | malicious | TrojanSpy.MSIL.NEGASTEAL.RJAHQFX |
| TrendMicro-HouseCall | malicious | TrojanSpy.MSIL.NEGASTEAL.RJAHQFX |
| Varist | malicious | W32/MSIL_Dropper.A.gen!Eldorado |
| VBA32 | malicious | TScope.Trojan.MSIL |
| VIPRE | malicious | Trojan.GenericKDZ.64762 |
| VirIT | malicious | Trojan.Win32.MSIL.IIV |
| ViRobot | malicious | Trojan.Win32.S.Agent.472064.DF |
| Xcitium | malicious | Malware@#8km78w4ao8q4 |
| Yandex | malicious | Trojan.DR.Agent!Hl7pvasMhUQ |
Details From VirusTotal
Basic Properties
| MD5 | 2f6432c5af8d10b04caed90d410ec7ad |
| SHA-1 | 4b1fc10818dd534922feef4d521eb3574337e3c0 |
| SHA-256 | 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d |
| VHash | 24503675155140a43d5201c1 |
| SSDEEP | 12288:GCU4gtAxIflaBAFGWf1yN6OcsiUIpqpcsHs4d8/U:MwIflaBaIH2Us69d88 |
| TLSH | T165A4BF181BB98C13F54BA6BAC4D942C9E2FCD57B8907F759D41129D60F0ABA7AC023C7 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 461.0 KB |
History
| Creation date | 2020-02-13 08:06 UTC |
| First seen on VirusTotal | 2020-02-13 11:13 UTC |
| Last submission | 2026-03-13 15:26 UTC |
| Last analysis | 2026-05-08 00:34 UTC |
| Last modified on VirusTotal | 2026-05-08 02:39 UTC |
Known Names
AppliWio.exe094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.exerl_094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.binCOPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe
hash_sha1
4b1fc10818dd534922feef4d521eb3574337e3c0
VT 59 / 75
IOC database
- Type
- hash_sha1
- Value
4b1fc10818dd534922feef4d521eb3574337e3c0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 59 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Generic.C4009441 |
| Alibaba | malicious | Trojan:Win32/CSKryptik.ali2000030 |
| alibabacloud | malicious | Backdoor:MSIL/Noancooe.A |
| ALYac | malicious | Spyware.AgentTesla |
| Antiy-AVL | malicious | Trojan[Spy]/MSIL.Noon |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.DFCFA |
| Avast | malicious | Win32:MalwareX-gen [Klg] |
| AVG | malicious | Win32:MalwareX-gen [Klg] |
| Avira | malicious | TR/W32.MalwareX |
| BitDefender | malicious | Trojan.GenericKDZ.64762 |
| Bkav | malicious | W32.Malware.41DF1E1E |
| CAT-QuickHeal | malicious | Trojan.YakbeexMSIL.ZZ4 |
| ClamAV | malicious | Win.Packed.Generickdz-10031713-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PackedNET.211 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKDZ.64762 (B) |
| ESET-NOD32 | malicious | MSIL/TrojanDropper.Agent.EOZ trojan |
| F-Secure | malicious | Trojan.TR/W32.MalwareX |
| Fortinet | malicious | MSIL/Agent.EOZ!tr.dldr |
| GData | malicious | Trojan.GenericKDZ.64762 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Generic!CFBB9098823D5E7A |
| Ikarus | malicious | Trojan.MSIL.Crypt |
| Jiangmin | malicious | TrojanSpy.MSIL.anac |
| K7AntiVirus | malicious | Trojan ( 700000201 ) |
| K7GW | malicious | Trojan ( 700000201 ) |
| Kaspersky | malicious | HEUR:Trojan-Spy.MSIL.Noon.gen |
| Lionic | malicious | Trojan.Win32.Noon.l!c |
| Malwarebytes | malicious | Trojan.Crypt.MSIL |
| MaxSecure | malicious | Trojan.Malware.73691310.susgen |
| McAfeeD | malicious | ti!094FD325049B |
| Microsoft | malicious | Trojan:Win32/Occamy.C09 |
| MicroWorld-eScan | malicious | Trojan.GenericKDZ.64762 |
| NANO-Antivirus | malicious | Trojan.Win32.PackedNET.hanopy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Spyware.Noon!8.E7C9 (KTSE) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | GenericRXJQ-HT!2F6432C5AF8D |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| tehtris | malicious | Generic.Malware |
| Tencent | malicious | Malware.Win32.Gencirc.144f9c70 |
| TrellixENS | malicious | GenericRXJQ-HT!2F6432C5AF8D |
| TrendMicro | malicious | TrojanSpy.MSIL.NEGASTEAL.RJAHQFX |
| TrendMicro-HouseCall | malicious | TrojanSpy.MSIL.NEGASTEAL.RJAHQFX |
| Varist | malicious | W32/MSIL_Dropper.A.gen!Eldorado |
| VBA32 | malicious | TScope.Trojan.MSIL |
| VIPRE | malicious | Trojan.GenericKDZ.64762 |
| VirIT | malicious | Trojan.Win32.MSIL.IIV |
| ViRobot | malicious | Trojan.Win32.S.Agent.472064.DF |
| Xcitium | malicious | Malware@#8km78w4ao8q4 |
| Zillya | malicious | Dropper.Agent.Win32.416246 |
Details From VirusTotal
Basic Properties
| MD5 | 2f6432c5af8d10b04caed90d410ec7ad |
| SHA-1 | 4b1fc10818dd534922feef4d521eb3574337e3c0 |
| SHA-256 | 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d |
| VHash | 24503675155140a43d5201c1 |
| SSDEEP | 12288:GCU4gtAxIflaBAFGWf1yN6OcsiUIpqpcsHs4d8/U:MwIflaBaIH2Us69d88 |
| TLSH | T165A4BF181BB98C13F54BA6BAC4D942C9E2FCD57B8907F759D41129D60F0ABA7AC023C7 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 461.0 KB |
History
| Creation date | 2020-02-13 08:06 UTC |
| First seen on VirusTotal | 2020-02-13 11:13 UTC |
| Last submission | 2026-03-13 15:26 UTC |
| Last analysis | 2026-05-24 04:35 UTC |
| Last modified on VirusTotal | 2026-05-24 06:35 UTC |
Known Names
AppliWio.exe094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.exerl_094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.binCOPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe
hash_md5
2f6432c5af8d10b04caed90d410ec7ad
VT 59 / 75
IOC database
- Type
- hash_md5
- Value
2f6432c5af8d10b04caed90d410ec7ad- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 59 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Generic.C4009441 |
| Alibaba | malicious | Trojan:Win32/CSKryptik.ali2000030 |
| alibabacloud | malicious | Backdoor:MSIL/Noancooe.A |
| ALYac | malicious | Spyware.AgentTesla |
| Antiy-AVL | malicious | Trojan[Spy]/MSIL.Noon |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.DFCFA |
| Avast | malicious | Win32:MalwareX-gen [Klg] |
| AVG | malicious | Win32:MalwareX-gen [Klg] |
| Avira | malicious | TR/W32.MalwareX |
| BitDefender | malicious | Trojan.GenericKDZ.64762 |
| Bkav | malicious | W32.Malware.41DF1E1E |
| CAT-QuickHeal | malicious | Trojan.YakbeexMSIL.ZZ4 |
| ClamAV | malicious | Win.Packed.Generickdz-10031713-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.PackedNET.211 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKDZ.64762 (B) |
| ESET-NOD32 | malicious | MSIL/TrojanDropper.Agent.EOZ trojan |
| F-Secure | malicious | Trojan.TR/W32.MalwareX |
| Fortinet | malicious | MSIL/Agent.EOZ!tr.dldr |
| GData | malicious | Trojan.GenericKDZ.64762 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Generic!CFBB9098823D5E7A |
| Ikarus | malicious | Trojan.MSIL.Crypt |
| Jiangmin | malicious | TrojanSpy.MSIL.anac |
| K7AntiVirus | malicious | Trojan ( 700000201 ) |
| K7GW | malicious | Trojan ( 700000201 ) |
| Kaspersky | malicious | HEUR:Trojan-Spy.MSIL.Noon.gen |
| Lionic | malicious | Trojan.Win32.Noon.l!c |
| Malwarebytes | malicious | Trojan.Crypt.MSIL |
| MaxSecure | malicious | Trojan.Malware.73691310.susgen |
| McAfeeD | malicious | ti!094FD325049B |
| Microsoft | malicious | Trojan:Win32/Occamy.C09 |
| MicroWorld-eScan | malicious | Trojan.GenericKDZ.64762 |
| NANO-Antivirus | malicious | Trojan.Win32.PackedNET.hanopy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Spyware.Noon!8.E7C9 (KTSE) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | GenericRXJQ-HT!2F6432C5AF8D |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| tehtris | malicious | Generic.Malware |
| Tencent | malicious | Malware.Win32.Gencirc.144f9c70 |
| TrellixENS | malicious | GenericRXJQ-HT!2F6432C5AF8D |
| TrendMicro | malicious | TrojanSpy.MSIL.NEGASTEAL.RJAHQFX |
| TrendMicro-HouseCall | malicious | TrojanSpy.MSIL.NEGASTEAL.RJAHQFX |
| Varist | malicious | W32/MSIL_Dropper.A.gen!Eldorado |
| VBA32 | malicious | TScope.Trojan.MSIL |
| VIPRE | malicious | Trojan.GenericKDZ.64762 |
| VirIT | malicious | Trojan.Win32.MSIL.IIV |
| ViRobot | malicious | Trojan.Win32.S.Agent.472064.DF |
| Xcitium | malicious | Malware@#8km78w4ao8q4 |
| Zillya | malicious | Dropper.Agent.Win32.416246 |
Details From VirusTotal
Basic Properties
| MD5 | 2f6432c5af8d10b04caed90d410ec7ad |
| SHA-1 | 4b1fc10818dd534922feef4d521eb3574337e3c0 |
| SHA-256 | 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d |
| VHash | 24503675155140a43d5201c1 |
| SSDEEP | 12288:GCU4gtAxIflaBAFGWf1yN6OcsiUIpqpcsHs4d8/U:MwIflaBaIH2Us69d88 |
| TLSH | T165A4BF181BB98C13F54BA6BAC4D942C9E2FCD57B8907F759D41129D60F0ABA7AC023C7 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 461.0 KB |
History
| Creation date | 2020-02-13 08:06 UTC |
| First seen on VirusTotal | 2020-02-13 11:13 UTC |
| Last submission | 2026-03-13 15:26 UTC |
| Last analysis | 2026-05-24 04:35 UTC |
| Last modified on VirusTotal | 2026-05-24 06:35 UTC |
Known Names
AppliWio.exe094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.exerl_094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.binCOPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe
References (2)
-
MalwareBazaar sample page
File type: exe. Size: 472064 bytes. Tags: AgentTesla, exe. Reporter: abuse_ch. First seen: 2020-02-13 11:55:46.
- Triage report
Remediations (10)
-
web:0xmrmagnezi.github.io
After analyzing the file with DNSpy, I identified the malware's unpacking function. It unpacks itself into memory and executes as a new process. As shown in Figure 5, I saved the unpacked content to a new file for further analysis. In addition, I successfully dumped a DLL that is generated during the malware's execution.
-
web:any.run
Agent Tesla is a password stealer spyware that can be used by attackers to spy on victims, allowing them to see everything that has been typed in supported programs and web-browsers. Follow live malware statistics of this stealer and get new reports, samples, IOCs, etc.
-
web:en.wikipedia.org
Agent Tesla is a remote access trojan (RAT) written in .NET that has been actively targeting users with Microsoft Windows OS-based systems since 2014. It is a versatile malware with a wide range of capabilities, including sensitive information stealing, keylogging and screenshot capture. Since its release, this malicious software has received regular updates. It is sold as a malware-as-a ...
-
web:fortgale.com
It has now become common practice to insert the email addresses of victims in the Bcc (blind carbon copy ) field. The email text refers to a purchase order, and attached is a compressed archive in LZH format containing the executable file named ORDINE DI ACQUISTO N. BCM190282.exe. The executable has been identified as the Malware Agent Tesla, which, before compromising the system, initiates a ...
-
web:github.com
Some of my publicly available Malware analysis and Reverse engineering. - Dump-GUY/Malware-analysis-and-Reverse-engineering
-
web:www.broadcom.com
The CHM file comes via a downloaded PowerShell script which drops a loader DLL file that in turn loads Agent Tesla into a legitimate Windows process called 'RegAsm.exe'. The PDF file uses two different methods to deliver the Agent Tesla malware. First, opening the PDF file will trigger a PowerShell command to load Agent Tesla.
-
web:www.fortiguard.com
FortiGuard Labs captured a phishing campaign that spreads a new Agent Tesla variant. This well-known malware family uses a .Net-based Remote Access Trojan (RAT) and data stealer to gain initial access by exploiting vulnerabilities Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802. The Agent Tesla core module can collect sensitive information from the victim's device that may ...
-
web:www.fortinet.com
An in-depth analysis of a phishing campaign that continues to exploit a known vulnerability with a new Agent Tesla variant. Learn more.
-
web:www.gatewatcher.com
Agent Tesla is a .NET-based Trojan and credential-stealing malware that first appeared in 2014. This malware family gained significant momentum during the 2020 pandemic. This software is sold for just a few dozen dollars, with support provided by its creators. Most of the time, the attack vector is a targeted malicious email, often sent from a compromised account. This email contains either an ...
-
web:www.sonicwall.com
The PDF file contains a link which downloads a malicious PowerPoint file, which then executes AgentTesla as the final payload on the victims machine. The threat actors are now more focused on delivery mechanism and infection chain, by keeping a low profile and very less exposure of malicious code to traditional security providers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.