Concrete signature match: Trojan - Appears legitimate but performs malicious actions for .NET (Microsoft Intermediate Language) platform, family AgentTesla
AgentTesla is a well-known information-stealing Trojan written for the .NET framework. Its primary function is to exfiltrate sensitive data, including login credentials from web browsers, email clients, and other applications, as well as capture keystrokes.
No detailed analysis available from definition files.
de0892e8c62f21f2fb6669f8b4bf28a7bd9c014cc5820735491c44ce93fe0f090b67d298c72d5ce44862870a253e2fae7011e9bb615b4edb17fee6227f252819Immediately isolate the affected machine from the network to prevent data exfiltration. Run a full antivirus scan to remove all malicious components. Assume all credentials on the device are compromised and immediately reset passwords for all critical accounts (email, corporate, financial).