MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 18
| SHA256 hash: | 013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec |
|---|---|
| SHA3-384 hash: | 27cbb8b8214b8bc35132ac830a4d036d3784eea637c44a1fbabcb5782dcd09b0eac6ead236ead2bde755915958e6d829 |
| SHA1 hash: | f939fa2fe72186b86568059b2d58aa71ec7afda5 |
| MD5 hash: | a11e18061c47a984ee961b26ea6a42ce |
| humanhash: | social-lion-mobile-massachusetts |
| File name: | 013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 701'952 bytes |
| First seen: | 2025-05-09 13:03:41 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'738 x AgentTesla, 19'597 x Formbook, 12'241 x SnakeKeylogger) |
| ssdeep | 12288:HpkPTB5ZkNd2j23LwPDLhDVAfrQLYHqDG3LmGGFBfJWV1nNDQ8NMU0Hfff2Xi:2adOuLMDLQjXqDYGF1A3tQ8NLni |
| TLSH | T185E4120ED7616A77C20C0777E013264852B7C422F552F36A98D9AEB44FB6F54C886FCA |
| TrID | 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.0% (.EXE) Win64 Executable (generic) (10522/11/4) 6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.2% (.EXE) Win32 Executable (generic) (4504/4/1) 1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Magika | pebin |
| dhash icon | 0000000000000000 (872 x AgentTesla, 496 x Formbook, 296 x RedLineStealer) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
3489a2eab1c57d0eee2ce6e5773e1f4f53ee6e5d8963e0099efc7e190d0c2f1c
e6fe2241c57847a4911e325b6d3692839f9033de0c99ddeabd47e8d62022bcd1
faac3d9161a1d539ec42986280eeab6246b71c427fa176a239562c110448a1c1
074efb70a49088638d0e62cc3637a75627afe9286c3f2d024e78ea9f247582fe
23808b7d7764dc5d702974b63f7b15c92d86e0ca95826edb47b2f919d911b9c8
6036a28c74493ce0e6d87a468959a047011d2e6cf63807d9a3d154b8642d7e65
be838fc4e67ed12838f4d0ec554524d54e80a03a3949ced4edfb958edbcb24b8
4867fd993605221960bb0289477ed3a14727ed81cc14b8da8b61e3f509d097f5
37da80758e0acd6993e9a2639927c5bcbf8388526fa93168a9b70f6619775df9
c06298e32597bfdf3374174b8f458169df5d561280f5aa11fd25868c67a5de9f
a90bca8c1f6a63cc34a896eb3883428fab6fb6b4aca385ac917fdafcdbf9e774
048ae81730730b45b67054c6ca4e83d727c07b14568397bc95ef51e4825e830d
ea8cce203873c762292f08d1d461a3f38521f1e77bc175dd68b4fef76ceabd19
bda5884e1a65b59d74d3366608a4841111d43d0b6a865879736f5179bac1bcf3
fa1cfaafe2029ee02035b899a389916cb02bac4270d3f438be0a5013f170e420
f2414faf44fac2135ccce1d5fe5c3a53ec3fcde7ad295e2e112af373b02da086
03a317048a5778933751cbf631e08c5b870ec2da45d74466c53f460a603d7d42
4d59b35375d85ca3dd06c76cedea67009a37075e179d0ae192b9412b24bec974
54f50cdad3e5039d3207566e1b9de6e16913993ba2aa711e6f91a68e093ed9c4
b9ee87f239e3ee4599d666b1b755f97ab4c2ab45507654ec1485f9d60af710ca
c6424a8d5558035680e043348443092f2ad0295be323d2848f6509639990ea28
278854f2430457153ca438c78d14f2469083281da9ec3baebad93d4dd7a3c125
1e98340b6b95bf8c7f96f0b3825473f914d71f78dd2a3032f1f8c3b78c118223
8ef48c6c52f5fed10b8d7c572da9d657ba1fb813a04356de5a47055e9b1250ef
9c100d322eee0b94c9d996c7bc1167df02a820d34dd4b5ee30748d331b064595
c7de64db20145557f5070412a4e15d4d2a00487974e8fce0f4bc3ee42999bd04
5b97cd88bfb20b5d92d426072bc581d159fea064159872e983805bd2c225e64c
ff5bccafd98ba9bd46b459881d752902794630c891dd98764fc1b51cb25a1aed
800a4bab620b5a0c3e184b76cd1a345d5b74b7754fd6aa10a37742e801c5d850
b91da8b8d9a3a5da385a0bde839b80d16824f485746b75597e9236a96d7b2445
3bed682a9298367059c63e05f0b565dbad9f5959302f239c00a92eb3aeb16d67
a7ae95af3a74e706c7a3370b351ba6070b7470e5b6fae98b59fc2612d1e4376e
3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8
07a74041ab09d6e30042a163e518da8c70f644924d576a268c981baad87a19ae
699abf03b319292d82d86e3669e6e0e59ed5d704064c56212dbcbde4a8d8fadd
8b3c3e6d8c540773529da82ad7c28265d6a5462e96d1f07a7781dd76c6004ac5
e0ec24c22840b9435a7fcba35fcc9fc13b371abea00ead5ef60ec9f0893630b3
013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec
51fde361f93dc3702ed13354d064da8422188f3e1b06d9c9b04951da07d89cb8
dc4e9ca482f2b9e15b04d70b2be7ecb6ec63a40e83da756503cbb1b9fbe023c1
5f8549af42d110a594441941f439b1a7c1d58ec75cf7acf9c9bdfcea75dadedd
9720a63f66e6f0fe2d93c9bd9e1ca3df5ca8520b9eaad9f52bd41fcce8a731fe
f9510c8431f00936d5ad598f8cb291f8b7c332f3af0fed696a99a1474c0ed706
1ff4344aa791b6f759f9e9d9655c28b468e33fb13017e33f707fc623769cf2ed
fd18b3110de032bd03901bdac15cb00fcc17f2292fdd791e5c4072caf70facc8
6b0cd55a4c6a299025ba02dc9d1962b494401c31d0125651a19c655c7bfc2a8c
e4997c748608a44552daf6262f503b22f5d77e20bb4b411c6342bcf6c1690ff1
be382be770efca98969b48895a2e7c41595a77cd79154a730db6b5ea9f0d2270
240c09f1a97bb6068fbe9c61b6026c0997dc5f2a06ae80e0c15ec691f40f30ee
c37baca5c488614ed44b90ade56d534975201dfa94327ed216b3c87e3ff8cc7a
35f56e6019406ee4247dfaf7a96e210eee795c8b05dc3c3666a2f644a8d4beab
70bb4b9ac0088fce0935763104020af0a92019cb428e3babc917739aec044296
f4cc69d1063ddca10b48ccf8c8c1380585144405f1bf3f938bdf0906d6229020
d0fcc696c691aaa8f1e3af4d7f4fab044704d96cf3f908af6681175715dc62be
c0affc728572d1e897d2869bd72b870bbe6851423e77f4b026306ade7d978e25
9434611a36173f7b73f3e3392e2ae8be5031cfff80ddf9a6638d1ee1aa81d05d
013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec
8e44219248894eb248a11f54284a1c9b999ea0177209907f868ab8bc2783b9b7
31a83a4477bc742ccccec7cd1ef6cf0b56fce9735efd420763eb1ac82ed81842
a33c0ffb1a4ff6c80695b6f068d8c9fd434086f091554d75a6d99205c26e805f
bdb7b7cd3368224c457242baf24c2235e60d077f13741363c2307f1fbccfe5ff
a4870649d8987960960d6ce4482ec7ea064c268eac6d85eec8caac07303b61cc
393fecc94068036d3e4515448c33085cc7d8b8374a98b401e37d3ff751be8dd7
4fe3d56a5cb89bdf31145b7ce1c17f22d8d1616dd491fdf1462bf623ca8b3a10
a0f63bbedc34b836ef3e4f2bae53abda8ac334c5541a6d12f5659c2b131db6a7
c3e60b1c3a6a89355139b5213bd09d61dce0505d36e792b972e24b99fbb89850
4cd5676a9e5f1f59e10c246d9a6c674518e66031fea5e17d23318ece2c5e9c67
cbbdd74333f2f2ebb9b1019d15b011b64594b1cf5651edbf8671d2a2bcab929c
efd69a0ac7b81d3d2fe4900b06a98066f2517e0d9364361d396e143d6f90d128
c0676910f1362864201df2da6fc69db6b679c8ba7fc0f66a2dc47c2236142bce
417c165a04979b22d52eeb3fda53a4b6a699f80c3fc89a69fd408ea0fbad16ac
a7a427b9b9f7ce1d847bce150139c546e43f61d49c637ee425d24f52803d47c8
f199e8a011ce9dc5c0e579358241f64e951ea530ff27052ebc41f09f1b6546b1
4c2d6b024e7af04fe1a42d5afad603b085bf37eff5f3a0b9d59a42b3c2828cc9
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTeslaV2 |
|---|---|
| Author: | ditekshen |
| Description: | AgenetTesla Type 2 Keylogger payload |
| Rule name: | AgentTeslaV3 |
|---|---|
| Author: | ditekshen |
| Description: | AgentTeslaV3 infostealer payload |
| Rule name: | AgentTeslaV5 |
|---|---|
| Author: | ClaudioWayne |
| Description: | AgentTeslaV5 infostealer payload |
| Rule name: | Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | DebuggerCheck__RemoteAPI |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | INDICATOR_EXE_Packed_GEN01 |
|---|---|
| Author: | ditekSHen |
| Description: | Detect packed .NET executables. Mostly AgentTeslaV4. |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many file transfer clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries and memory artifacts referencing sandbox DLLs typically observed in sandbox evasion |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing Windows vault credential objects. Observed in infostealers |
| Rule name: | malware_Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | MALWARE_Win_AgentTeslaV2 |
|---|---|
| Author: | ditekSHen |
| Description: | AgenetTesla Type 2 Keylogger payload |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | Windows_Generic_Threat_779cf969 |
|---|---|
| Author: | Elastic Security |
| Rule name: | Windows_Trojan_AgentTesla_ebf431a8 |
|---|---|
| Author: | Elastic Security |
| Reference: | https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (GUARD_CF) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.