Trojan

Trojan:MSIL/AgentTesla.RD!MTB (file analysis)

Malware Removal

The Trojan:MSIL/AgentTesla.RD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/AgentTesla.RD!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com

How to determine Trojan:MSIL/AgentTesla.RD!MTB?


File Info:

crc32: 8E14F992
md5: a4f515215df903d12cb8b6b1cb65fa34
name: rac2.exe
sha1: f018d3f922752a35c22c3706b33fe2dbd606efdd
sha256: 7b3b5a6eb9179fab73411217196fe912e9adf36d2f5c1360e92db06062da3d88
sha512: bdded9e10d5fda13140b61801a524209eb1ba27ca5b003618dc2d343650a0dfd280d0a6ec582386e74ffc3baa3e91356a152368f470f24942f1b41bdd231748b
ssdeep: 24576:hqF49gHuQUyslhtWyBeivNVKSjfe8dWsNVxyffcKsY7slhtWG:hjhtWrivNDje8IQgffgLhtW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Bouygues Construction (C)
Assembly Version: 0.95.2.134
InternalName: FaPdb.exe
FileVersion: 0.94.2.163
CompanyName: Bouygues Construction
LegalTrademarks:
Comments: Saclay plateau
ProductName: Tribunal de Grande Instance
ProductVersion: 0.94.2.163
FileDescription: Tribunal de Grande Instance
OriginalFilename: FaPdb.exe

Trojan:MSIL/AgentTesla.RD!MTB also known as:

DrWebTrojan.PackedNET.372
MicroWorld-eScanTrojan.GenericKD.34139094
McAfeeFareit-FWJ!A4F515215DF9
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056a4281 )
BitDefenderTrojan.GenericKD.34139094
K7GWTrojan ( 0056a4281 )
Invinceaheuristic
F-ProtW32/MSIL_Kryptik.BAZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataWin32.Trojan-Stealer.Raccoon.2D8SD4
KasperskyHEUR:Trojan.MSIL.Gorgon.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.34139094 (B)
F-SecureTrojan.TR/AD.StellarStealer.hifkw
MaxSecureTrojan.Malware.300983.susgen
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
CyrenW32/MSIL_Kryptik.BAZ.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/AD.StellarStealer.hifkw
MAXmalware (ai score=83)
MicrosoftTrojan:MSIL/AgentTesla.RD!MTB
ArcabitTrojan.Generic.D208EBD6
ZoneAlarmHEUR:Trojan.MSIL.Gorgon.gen
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.AgentTesla.R343529
MalwarebytesSpyware.PasswordStealer
ESET-NOD32a variant of MSIL/GenKryptik.ENVP
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
SentinelOneDFI – Malicious PE
FortinetMSIL/GenKryptik.ENVP!tr
Ad-AwareTrojan.GenericKD.34139094
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM03.0.7302.Malware.Gen

How to remove Trojan:MSIL/AgentTesla.RD!MTB?

Trojan:MSIL/AgentTesla.RD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment