s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d high

📛 Threat Title

AgentTesla: COPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe

Category: AgentTesla First seen: Last updated:

Description

File type: exe. Size: 472064 bytes. Tags: AgentTesla, exe. Reporter: abuse_ch. First seen: 2020-02-13 11:55:46.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain copy-scanb840284-img-2020-13-02-document-pdf.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/copy-scanb840284-img-2020-13-02-document-pdf.exe

IOC database

Type
domain
Value
copy-scanb840284-img-2020-13-02-document-pdf.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/copy-scanb840284-img-2020-13-02-document-pdf.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
650 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d VT 57 / 75

IOC database

Type
hash_sha256
Value
094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
AgentTesla

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 57 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win32.RL_Generic.C4009441
Alibaba malicious Trojan:Win32/CSKryptik.ali2000030
alibabacloud malicious Backdoor:MSIL/Noancooe.A
ALYac malicious Spyware.AgentTesla
Antiy-AVL malicious Trojan[Spy]/MSIL.Noon
APEX malicious Malicious
Arcabit malicious Trojan.Generic.DFCFA
Avira malicious HEUR/AGEN.1323934
BitDefender malicious Trojan.GenericKDZ.64762
Bkav malicious W32.Malware.41DF1E1E
CAT-QuickHeal malicious Trojan.YakbeexMSIL.ZZ4
ClamAV malicious Win.Packed.Generickdz-10031713-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DrWeb malicious Trojan.PackedNET.211
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKDZ.64762 (B)
ESET-NOD32 malicious MSIL/TrojanDropper.Agent.EOZ trojan
F-Secure malicious Heuristic.HEUR/AGEN.1323934
Fortinet malicious MSIL/Agent.EOZ!tr.dldr
GData malicious Trojan.GenericKDZ.64762
Google malicious Detected
huorong malicious Trojan/Generic!CFBB9098823D5E7A
Ikarus malicious Trojan.MSIL.Crypt
Jiangmin malicious TrojanSpy.MSIL.anac
K7AntiVirus malicious Trojan ( 700000201 )
K7GW malicious Trojan ( 700000201 )
Kaspersky malicious HEUR:Trojan-Spy.MSIL.Noon.gen
Kingsoft malicious malware.kb.c.1000
Lionic malicious Trojan.Win32.Noon.l!c
Malwarebytes malicious Trojan.Crypt.MSIL
MaxSecure malicious Trojan.Malware.73691310.susgen
McAfeeD malicious ti!094FD325049B
Microsoft malicious Trojan:Win32/Occamy.C09
MicroWorld-eScan malicious Trojan.GenericKDZ.64762
NANO-Antivirus malicious Trojan.Win32.PackedNET.hanopy
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
Rising malicious Spyware.Noon!8.E7C9 (KTSE)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious GenericRXJQ-HT!2F6432C5AF8D
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
tehtris malicious Generic.Malware
Tencent malicious Malware.Win32.Gencirc.144f9c70
TrellixENS malicious GenericRXJQ-HT!2F6432C5AF8D
TrendMicro malicious TrojanSpy.MSIL.NEGASTEAL.RJAHQFX
TrendMicro-HouseCall malicious TrojanSpy.MSIL.NEGASTEAL.RJAHQFX
Varist malicious W32/MSIL_Dropper.A.gen!Eldorado
VBA32 malicious TScope.Trojan.MSIL
VIPRE malicious Trojan.GenericKDZ.64762
VirIT malicious Trojan.Win32.MSIL.IIV
ViRobot malicious Trojan.Win32.S.Agent.472064.DF
Xcitium malicious Malware@#8km78w4ao8q4
Yandex malicious Trojan.DR.Agent!Hl7pvasMhUQ

Details From VirusTotal

Basic Properties
MD52f6432c5af8d10b04caed90d410ec7ad
SHA-14b1fc10818dd534922feef4d521eb3574337e3c0
SHA-256094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
VHash24503675155140a43d5201c1
SSDEEP12288:GCU4gtAxIflaBAFGWf1yN6OcsiUIpqpcsHs4d8/U:MwIflaBaIH2Us69d88
TLSHT165A4BF181BB98C13F54BA6BAC4D942C9E2FCD57B8907F759D41129D60F0ABA7AC023C7
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size461.0 KB
History
Creation date2020-02-13 08:06 UTC
First seen on VirusTotal2020-02-13 11:13 UTC
Last submission2026-03-13 15:26 UTC
Last analysis2026-05-08 00:34 UTC
Last modified on VirusTotal2026-05-08 02:39 UTC
Known Names
  • AppliWio.exe
  • 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.exe
  • rl_094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
  • 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.bin
  • COPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe
hash_sha1 4b1fc10818dd534922feef4d521eb3574337e3c0 VT 59 / 75

IOC database

Type
hash_sha1
Value
4b1fc10818dd534922feef4d521eb3574337e3c0
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 59 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win32.RL_Generic.C4009441
Alibaba malicious Trojan:Win32/CSKryptik.ali2000030
alibabacloud malicious Backdoor:MSIL/Noancooe.A
ALYac malicious Spyware.AgentTesla
Antiy-AVL malicious Trojan[Spy]/MSIL.Noon
APEX malicious Malicious
Arcabit malicious Trojan.Generic.DFCFA
Avast malicious Win32:MalwareX-gen [Klg]
AVG malicious Win32:MalwareX-gen [Klg]
Avira malicious TR/W32.MalwareX
BitDefender malicious Trojan.GenericKDZ.64762
Bkav malicious W32.Malware.41DF1E1E
CAT-QuickHeal malicious Trojan.YakbeexMSIL.ZZ4
ClamAV malicious Win.Packed.Generickdz-10031713-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PackedNET.211
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKDZ.64762 (B)
ESET-NOD32 malicious MSIL/TrojanDropper.Agent.EOZ trojan
F-Secure malicious Trojan.TR/W32.MalwareX
Fortinet malicious MSIL/Agent.EOZ!tr.dldr
GData malicious Trojan.GenericKDZ.64762
Google malicious Detected
huorong malicious Trojan/Generic!CFBB9098823D5E7A
Ikarus malicious Trojan.MSIL.Crypt
Jiangmin malicious TrojanSpy.MSIL.anac
K7AntiVirus malicious Trojan ( 700000201 )
K7GW malicious Trojan ( 700000201 )
Kaspersky malicious HEUR:Trojan-Spy.MSIL.Noon.gen
Lionic malicious Trojan.Win32.Noon.l!c
Malwarebytes malicious Trojan.Crypt.MSIL
MaxSecure malicious Trojan.Malware.73691310.susgen
McAfeeD malicious ti!094FD325049B
Microsoft malicious Trojan:Win32/Occamy.C09
MicroWorld-eScan malicious Trojan.GenericKDZ.64762
NANO-Antivirus malicious Trojan.Win32.PackedNET.hanopy
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
Rising malicious Spyware.Noon!8.E7C9 (KTSE)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious GenericRXJQ-HT!2F6432C5AF8D
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
tehtris malicious Generic.Malware
Tencent malicious Malware.Win32.Gencirc.144f9c70
TrellixENS malicious GenericRXJQ-HT!2F6432C5AF8D
TrendMicro malicious TrojanSpy.MSIL.NEGASTEAL.RJAHQFX
TrendMicro-HouseCall malicious TrojanSpy.MSIL.NEGASTEAL.RJAHQFX
Varist malicious W32/MSIL_Dropper.A.gen!Eldorado
VBA32 malicious TScope.Trojan.MSIL
VIPRE malicious Trojan.GenericKDZ.64762
VirIT malicious Trojan.Win32.MSIL.IIV
ViRobot malicious Trojan.Win32.S.Agent.472064.DF
Xcitium malicious Malware@#8km78w4ao8q4
Zillya malicious Dropper.Agent.Win32.416246

Details From VirusTotal

Basic Properties
MD52f6432c5af8d10b04caed90d410ec7ad
SHA-14b1fc10818dd534922feef4d521eb3574337e3c0
SHA-256094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
VHash24503675155140a43d5201c1
SSDEEP12288:GCU4gtAxIflaBAFGWf1yN6OcsiUIpqpcsHs4d8/U:MwIflaBaIH2Us69d88
TLSHT165A4BF181BB98C13F54BA6BAC4D942C9E2FCD57B8907F759D41129D60F0ABA7AC023C7
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size461.0 KB
History
Creation date2020-02-13 08:06 UTC
First seen on VirusTotal2020-02-13 11:13 UTC
Last submission2026-03-13 15:26 UTC
Last analysis2026-05-24 04:35 UTC
Last modified on VirusTotal2026-05-24 06:35 UTC
Known Names
  • AppliWio.exe
  • 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.exe
  • rl_094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
  • 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.bin
  • COPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe
hash_md5 2f6432c5af8d10b04caed90d410ec7ad VT 59 / 75

IOC database

Type
hash_md5
Value
2f6432c5af8d10b04caed90d410ec7ad
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 59 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win32.RL_Generic.C4009441
Alibaba malicious Trojan:Win32/CSKryptik.ali2000030
alibabacloud malicious Backdoor:MSIL/Noancooe.A
ALYac malicious Spyware.AgentTesla
Antiy-AVL malicious Trojan[Spy]/MSIL.Noon
APEX malicious Malicious
Arcabit malicious Trojan.Generic.DFCFA
Avast malicious Win32:MalwareX-gen [Klg]
AVG malicious Win32:MalwareX-gen [Klg]
Avira malicious TR/W32.MalwareX
BitDefender malicious Trojan.GenericKDZ.64762
Bkav malicious W32.Malware.41DF1E1E
CAT-QuickHeal malicious Trojan.YakbeexMSIL.ZZ4
ClamAV malicious Win.Packed.Generickdz-10031713-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PackedNET.211
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKDZ.64762 (B)
ESET-NOD32 malicious MSIL/TrojanDropper.Agent.EOZ trojan
F-Secure malicious Trojan.TR/W32.MalwareX
Fortinet malicious MSIL/Agent.EOZ!tr.dldr
GData malicious Trojan.GenericKDZ.64762
Google malicious Detected
huorong malicious Trojan/Generic!CFBB9098823D5E7A
Ikarus malicious Trojan.MSIL.Crypt
Jiangmin malicious TrojanSpy.MSIL.anac
K7AntiVirus malicious Trojan ( 700000201 )
K7GW malicious Trojan ( 700000201 )
Kaspersky malicious HEUR:Trojan-Spy.MSIL.Noon.gen
Lionic malicious Trojan.Win32.Noon.l!c
Malwarebytes malicious Trojan.Crypt.MSIL
MaxSecure malicious Trojan.Malware.73691310.susgen
McAfeeD malicious ti!094FD325049B
Microsoft malicious Trojan:Win32/Occamy.C09
MicroWorld-eScan malicious Trojan.GenericKDZ.64762
NANO-Antivirus malicious Trojan.Win32.PackedNET.hanopy
Paloalto malicious generic.ml
Panda malicious Trj/GdSda.A
Rising malicious Spyware.Noon!8.E7C9 (KTSE)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious GenericRXJQ-HT!2F6432C5AF8D
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
tehtris malicious Generic.Malware
Tencent malicious Malware.Win32.Gencirc.144f9c70
TrellixENS malicious GenericRXJQ-HT!2F6432C5AF8D
TrendMicro malicious TrojanSpy.MSIL.NEGASTEAL.RJAHQFX
TrendMicro-HouseCall malicious TrojanSpy.MSIL.NEGASTEAL.RJAHQFX
Varist malicious W32/MSIL_Dropper.A.gen!Eldorado
VBA32 malicious TScope.Trojan.MSIL
VIPRE malicious Trojan.GenericKDZ.64762
VirIT malicious Trojan.Win32.MSIL.IIV
ViRobot malicious Trojan.Win32.S.Agent.472064.DF
Xcitium malicious Malware@#8km78w4ao8q4
Zillya malicious Dropper.Agent.Win32.416246

Details From VirusTotal

Basic Properties
MD52f6432c5af8d10b04caed90d410ec7ad
SHA-14b1fc10818dd534922feef4d521eb3574337e3c0
SHA-256094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
VHash24503675155140a43d5201c1
SSDEEP12288:GCU4gtAxIflaBAFGWf1yN6OcsiUIpqpcsHs4d8/U:MwIflaBaIH2Us69d88
TLSHT165A4BF181BB98C13F54BA6BAC4D942C9E2FCD57B8907F759D41129D60F0ABA7AC023C7
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size461.0 KB
History
Creation date2020-02-13 08:06 UTC
First seen on VirusTotal2020-02-13 11:13 UTC
Last submission2026-03-13 15:26 UTC
Last analysis2026-05-24 04:35 UTC
Last modified on VirusTotal2026-05-24 06:35 UTC
Known Names
  • AppliWio.exe
  • 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.exe
  • rl_094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d
  • 094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d.bin
  • COPY-SCANB840284-IMG-2020-13-02-DOCUMENT-PDF.exe

References (2)

Remediations (10)

  • web:0xmrmagnezi.github.io

    After analyzing the file with DNSpy, I identified the malware's unpacking function. It unpacks itself into memory and executes as a new process. As shown in Figure 5, I saved the unpacked content to a new file for further analysis. In addition, I successfully dumped a DLL that is generated during the malware's execution.

  • web:any.run

    Agent Tesla is a password stealer spyware that can be used by attackers to spy on victims, allowing them to see everything that has been typed in supported programs and web-browsers. Follow live malware statistics of this stealer and get new reports, samples, IOCs, etc.

  • web:en.wikipedia.org

    Agent Tesla is a remote access trojan (RAT) written in .NET that has been actively targeting users with Microsoft Windows OS-based systems since 2014. It is a versatile malware with a wide range of capabilities, including sensitive information stealing, keylogging and screenshot capture. Since its release, this malicious software has received regular updates. It is sold as a malware-as-a ...

  • web:fortgale.com

    It has now become common practice to insert the email addresses of victims in the Bcc (blind carbon copy ) field. The email text refers to a purchase order, and attached is a compressed archive in LZH format containing the executable file named ORDINE DI ACQUISTO N. BCM190282.exe. The executable has been identified as the Malware Agent Tesla, which, before compromising the system, initiates a ...

  • web:github.com

    Some of my publicly available Malware analysis and Reverse engineering. - Dump-GUY/Malware-analysis-and-Reverse-engineering

  • web:www.broadcom.com

    The CHM file comes via a downloaded PowerShell script which drops a loader DLL file that in turn loads Agent Tesla into a legitimate Windows process called 'RegAsm.exe'. The PDF file uses two different methods to deliver the Agent Tesla malware. First, opening the PDF file will trigger a PowerShell command to load Agent Tesla.

  • web:www.fortiguard.com

    FortiGuard Labs captured a phishing campaign that spreads a new Agent Tesla variant. This well-known malware family uses a .Net-based Remote Access Trojan (RAT) and data stealer to gain initial access by exploiting vulnerabilities Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802. The Agent Tesla core module can collect sensitive information from the victim's device that may ...

  • web:www.fortinet.com

    An in-depth analysis of a phishing campaign that continues to exploit a known vulnerability with a new Agent Tesla variant. Learn more.

  • web:www.gatewatcher.com

    Agent Tesla is a .NET-based Trojan and credential-stealing malware that first appeared in 2014. This malware family gained significant momentum during the 2020 pandemic. This software is sold for just a few dozen dollars, with support provided by its creators. Most of the time, the attack vector is a targeted malicious email, often sent from a compromised account. This email contains either an ...

  • web:www.sonicwall.com

    The PDF file contains a link which downloads a malicious PowerPoint file, which then executes AgentTesla as the final payload on the victims machine. The threat actors are now more focused on delivery mechanism and infection chain, by keeping a low profile and very less exposure of malicious code to traditional security providers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.