Threat Database Trojans Trojan.MSIL.AgentTesla.MU

Trojan.MSIL.AgentTesla.MU

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: August 15, 2025
Last Seen: March 19, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.AgentTesla.MU
Signature status: No Signature

Known Samples

MD5: 06d9071ed8b15a6d9871f47b311f3e97
SHA1: fbd17a868c8ec29b54c77fe504a8647a27c00131
SHA256: EEF5C5FA574616E79C45B3901E6D843172B8C7BEBED1FD797C35F23155B7DB9B
File Size: 1.17 MB, 1172992 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments 8?D8G5BED83@D3B
Company Name =HJ72ID=@I=72=;G7BA
File Description E>9EEH3J>FH8JI9
File Version 10.21.31.110
Internal Name SEE THIS.exe
Legal Copyright Copyright © 1998 =HJ72ID=@I=72=;G7BA. All rights reserved.
Original Filename SEE THIS.exe
Product Name E>9EEH3J>FH8JI9
Product Version 10.21.31.110

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 320
Potentially Malicious Blocks: 11
Whitelisted Blocks: 132
Unknown Blocks: 177

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? 0 ? ? x 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 0 0 0 ? ? ? ? ? ? ? x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? x 0 ? ? ? 0 x x x ? ? ? ? ? 0 0 x ? ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext