MalwareBazaar Database

This page shows some basic information the YARA rule AgentTesla_PowerShell_Base64_AES_Wrapper including corresponding malware samples.

Database Entry


YARA Rule:AgentTesla_PowerShell_Base64_AES_Wrapper
Author:Aldair Maihuiri
Description:Detects the observed PowerShell Base64 normalization and AES wrapper used before in-memory execution
Firstseen:2026-10-08 18:50:25 UTC
Lastseen:2026-10-08 19:00:38 UTC
Sightings:10

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter