MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e6f5db27f161b7c42860df087218ace6a753079f09a186cf4ef0ce6d79f21d6f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e6f5db27f161b7c42860df087218ace6a753079f09a186cf4ef0ce6d79f21d6f
SHA3-384 hash: 3151584527a4b736744277444546e7b0ced34df55176b1b31383c6b6847f4bc67218e8b878d48d90aba98e3a2e090acf
SHA1 hash: fc82d3e429217a09673dce578b18029fc4895a0f
MD5 hash: 349178514a8d8c9ac49a44628c752c64
humanhash: aspen-salami-mississippi-two
File name:Bank Details And Proforma Invoice_pdf.scr
Download: download sample
Signature AgentTesla
File size:804'352 bytes
First seen:2020-03-30 12:05:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 12288:gxYzvkuYvg1Aw1XUsdN9MpAWVfQDdOiJ+:h4NlwqspMpAWVfAgI+
Threatray 712 similar samples on MalwareBazaar
TLSH 4805ACC0EE5BE90AC25805F4C98EC20DC630EF985B42EE846A49F35916B235DCDDD6F6
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Rdn
Status:
Malicious
First seen:
2020-03-30 16:19:27 UTC
File Type:
PE (.Net Exe)
Extracted files:
22
AV detection:
23 of 30 (76.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments