MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5ecfea430f1801299be4a50346c041ba396e4b7e30f635f7ec579ebf56328d80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5ecfea430f1801299be4a50346c041ba396e4b7e30f635f7ec579ebf56328d80
SHA3-384 hash: b97eddf166c8e73082ea24395c1743573bd4a5574f899219fc03d020afce28c47ff1e9dc17b7a9fd90757e4bcbe60dff
SHA1 hash: cb2eededbe6170240087c7b064c796172efc6937
MD5 hash: 0bafbc9084197d63cda39fb07aa052cd
humanhash: april-one-iowa-whiskey
File name:159cc3260e1b27827b87142c5e948540.exe
Download: download sample
Signature AgentTesla
File size:296'448 bytes
First seen:2020-03-26 15:48:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 6144:+0Zqyss3X90nTOw9Oomt2b3hIMwEo9GdGb:h3KTCoK2mMw
Threatray 10'405 similar samples on MalwareBazaar
TLSH 4E542A7C6B88B902F73D093389D1666152F294834D22CB4F2EC45AFD7F527C92D4A3A6
Reporter abuse_ch
Tags:AgentTesla exe GuLoader


Avatar
abuse_ch
Payload dropped by GuLoader from the following URL:
https://drive.google.com/uc?export=download&id=18Sw7zgGXNNnOyX6QQQFeUrNWPW7aOqS9

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

c6f28fbdd3d80d9319afb172ff9ea326952c6d1de8b99a2772e3d83b3f28316b

AgentTesla

Executable exe 5ecfea430f1801299be4a50346c041ba396e4b7e30f635f7ec579ebf56328d80

(this sample)

  
Dropped by
MD5 159cc3260e1b27827b87142c5e948540
  
Dropped by
MD5 3bc4759a803d9875e89188f6fe74d3c4
  
Dropped by
GuLoader
  
Dropped by
SHA256 c6f28fbdd3d80d9319afb172ff9ea326952c6d1de8b99a2772e3d83b3f28316b
  
Dropped by
SHA256 d0050b4798cc9e37b77dee8c00de359cfbc59f72274d12c53773812149578d60

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments