MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cfbf8e9c3e178d14a8afa864eacdf5e9ee57c82679b08bbceb56ca418c86e908. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cfbf8e9c3e178d14a8afa864eacdf5e9ee57c82679b08bbceb56ca418c86e908
SHA3-384 hash: cd6d6ecc5217487f8e01262d1fa2ecc2af48b5486f7c130fa932973ccaa165e035537125f6f79167bfe3cf5cdf3b8ba1
SHA1 hash: a917bd645e9a6ca874dcf177ed82fb457696a82b
MD5 hash: 115bd776465c42ee63e103709e4a5cd4
humanhash: spring-virginia-oven-texas
File name:Order for Purchase.exe
Download: download sample
Signature AgentTesla
File size:476'160 bytes
First seen:2020-07-24 05:32:43 UTC
Last seen:2020-07-27 06:49:17 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 12288:aFwQjE9UG1d8cyhGDMz6DB+gJIreVOkNYXiayI5UeU:QbaAhGDlv0eZNYSayfeU
Threatray 8 similar samples on MalwareBazaar
TLSH 7EA48C47CBB909FAEF5467BFE84580458BB8C03793C6E3851BABF4E4644A7644B13C92
Reporter cocaman
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Using the Windows Management Instrumentation requests
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-24 05:34:08 UTC
File Type:
PE (.Net Exe)
Extracted files:
2
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Program crash
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

Executable exe cfbf8e9c3e178d14a8afa864eacdf5e9ee57c82679b08bbceb56ca418c86e908

(this sample)

Comments