Threat Database Trojans Trojan.MSIL.AgentTesla.LV

Trojan.MSIL.AgentTesla.LV

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.AgentTesla.LV
Signature status: Hash Mismatch

Known Samples

MD5: d3df2341eaa36373ce4c4db53253f09c
SHA1: 97519de31334454054c9450f6695535fa846859e
SHA256: 84A2E4DF0257B773B6040CF7C1113FE6C2D1B8EFC020C3250F45B312785328D6
File Size: 6.34 MB, 6344576 bytes
MD5: aada13f14ef0279d8f6f4c92878e2745
SHA1: c46e19da0b6ab74f409099e0f66504d4ef2f9737
SHA256: 7955BC63A4078670D1C2ED381C21A7239F01A0CE93F23ABD986D634F50B21ABB
File Size: 6.27 MB, 6271360 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name SIL International
File Description Keyman Browser Host Process
File Version 18.0.240.0
Internal Name KMBROWSERHOST
Legal Copyright © SIL International
Legal Trademarks Keyman is a registered trademark in Australia
Original Filename KMBROWSERHOST.EXE
Product Name Keyman
Product Version 18.0.240.0

Digital Signatures

Signer Root Status
SUMMER INSTITUTE OF LINGUISTICS, INC. Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • .NET
  • NewLateBinding
  • x86

Block Information

Total Blocks: 522
Potentially Malicious Blocks: 287
Whitelisted Blocks: 235
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x x x x x 0 0 x x x x x 0 0 0 x x x 0 0 0 x 0 x x x x 0 0 0 x 0 x x x x x x x x x x x 0 x x x x x x x x x x 0 0 x x x x x x x x x x x 0 x 0 0 x 0 0 0 x x x 0 0 x 0 x x x x x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 x x 0 0 0 0 x 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 0 0 0 x 0 0 x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 0 0 x x 0 0 0 0 0 0 0 x 0 x x x x x x 0 0 0 x 0 x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.AgentTesla.LV

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...