MalwareBazaar Database

This page shows some basic information the YARA rule AgentTesla_Loader_PowerShell_AES including corresponding malware samples.

Database Entry


YARA Rule:AgentTesla_Loader_PowerShell_AES
Author:Aldair Maihuiri
Description:PowerShell AES-256-CBC loader that decrypts an embedded payload and executes it in memory via Invoke-Expression
Firstseen:2026-10-06 07:22:49 UTC
Lastseen:2026-10-08 19:00:38 UTC
Sightings:24

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter