MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 12


Intelligence 12 IOCs YARA 2 File information Comments

SHA256 hash: 059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522
SHA3-384 hash: 7341d7cabab2d0daeabc02edea3ac066777d7edbff0b203a76a5eb2a62be098e9fc2fe229f73097eb4616d4a57006ce9
SHA1 hash: aa63618eb0bd0bce5d957263f57fe4a666a50b21
MD5 hash: 57be41b56110386ad16ade8622cb54fd
humanhash: two-nitrogen-lemon-sink
File name:RDE0987678000.bat
Download: download sample
Signature AgentTesla
File size:1'079'808 bytes
First seen:2024-07-01 12:49:56 UTC
Last seen:2024-07-01 13:21:36 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash bd3825b6e0410966f0c31f64b6c7644a (36 x AgentTesla, 15 x Formbook, 6 x RemcosRAT)
ssdeep 24576:XAHnh+eWsN3skA4RV1Hom2KXcmtc04m1XErox6Z:Kh+ZkldoPKsac04GEQ
TLSH T1C035AC0273D1D036FFABA2739B6AE2055AB87D254133852F13981D79BD701B2273E663
TrID 49.2% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
22.7% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
9.0% (.EXE) Win64 Executable (generic) (10523/12/4)
5.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
File icon (PE):PE icon
dhash icon aae2f3e38383b629 (2'034 x Formbook, 1'183 x CredentialFlusher, 666 x AgentTesla)
Reporter adrian__luca
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
363
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Searching for the window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
autoit epmicrosoft_visual_cc fingerprint keylogger lolbin masquerade microsoft_visual_cc packed shell32
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
60 / 100
Signature
AI detected suspicious sample
Binary is likely a compiled AutoIt script file
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Nymeria
Status:
Malicious
First seen:
2024-07-01 12:50:20 UTC
File Type:
PE (Exe)
Extracted files:
28
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Verdict:
unknown
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
AutoIT Executable
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
d48ee1f6f04504d641c8769aeef83185c8de8745458a3fbc362cd53c20ef10d9
MD5 hash:
e89f78e780b64eeb920d5dfebd033ffa
SHA1 hash:
b964dc9e8f5350d3a917b6a26b58853099859d8b
Detections:
win_agent_tesla_g2 INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients Agenttesla_type2 MALWARE_Win_AgentTeslaV2 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL INDICATOR_EXE_Packed_GEN01 INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Parent samples :
ff8ed2fb198f232f7916240604c204d1e467103fda567dc287dd62ca3d478d76
10c2aed16bd496bca57f3cc817ad510cc0201ac1657fd75dde1377ca038a9adf
18bbef8347972904228a700b1ed16a560400d283f27b615730414f958e67045c
a025ca2161bf1125aa31aa65ba154f261f7dae204f7abfaf5ecf392eab8e9fc2
627830b9debfa8a0a8a9cfbb89c90c0b2bd236ebc50f42564a0c91ce4edb3943
b772162c5b510c5427be045abfdc43c29756217e2ed924ce4c4388bd457a4987
115a0abcf8bfe4d0320ecc08c9f0668f35dd796b7a74c6dfeb9d6fc7dc16d214
059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522
8024f9bb6c58be103e60c07bf09d3648b61bce12dbfb6277b18a85fd8a45bc4e
8d15bcc5eca4dbafc31d1ea92c4d34b86e5d30e6b4cb0da378570bdccd7242c1
6a31f54219ee0ddbfcb2aa841f922d48a849b1b047b8693ff8c2faad2ab8fac4
979e6920fc27cda0cb462b26f221a6e521e3974ae737022db7215747f54ff349
3a32996e922e69d2a01101f0fe601687d8d98f6392cb72cb984ad86b03f8236d
f87529bd57f54630ff4e0a8391d2e02bd04df4b83ec7c2b879dc258f81103978
d48ee1f6f04504d641c8769aeef83185c8de8745458a3fbc362cd53c20ef10d9
ca690123d14bd3632ab53a076f8bfb7bd2176248af6b735af9719aca77a024b5
86e6c344630b2458ef31796359d7c14538e95982c87c803d1ffd328f2ac2bab6
474651d4f8f510094648423d6a0d97b51d2847db856251740877331e101dd372
46a2479daf646efcab8cc6fbf8037d37703dabfc6aee279465e22b9a433c8c08
363da150d891da7bb5da8056414882429067a0fcb27f58363567567bf18a323e
d2d196a12c822020c4042d607be77746951b6cb3c16201ff21ca8e9c5c786209
dea077180d1a981a1a9bd8f901bc177236825f173e5e2394161811797933fdc2
91fee98b5957d145f144b61107ea0283fc3e02eb7e19b432e868ee45ffdc528e
35931dde3f9e60ae4cbf22e5348bc4afca8d6145137a27a25216edba8b66f68e
0502e71249410dba419218374909428d7d53cca90c3cfe8861b7f8eae432a4b9
1e6a8f176a0d7a9bd0321b4c032153f48b244be1584137453bf1afc07ea10157
80cae17ac36cdddcdd35027d72f10d019d82e256fe88e0113c66432137f354fc
97a8bf73809611ee4048adc2714685bd29bba3e677f5589b1053e30e0d98cf53
18b7930562b9f73f383204f2a09e2a76ab3d772a0d3813ea42bbff257430b5ad
811c8854ea3adcd1259c28cf1dc60e0a0a2f7a44f463e98f77c277a2a2f6394b
382b40ce3e7d7fc44a80d1b9190914a401c968be78c7115a8e4e3ccd40b8888d
996a678b9f2d2434c6da9452449c3f21aac4b5e15ba7ae8c0a5ecd429d287e35
89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b
ac0c869888d9501a709cb33762d8062ecf7139116a4c0dbe07171f2c5a77b96c
142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
5fc13e8395c7c4714caacc49471c400b47d85b490c329699060acaae6bd24eab
35c894c4142cf4d35b922afcee66e1c1d1feb7803ff904371c3efc38d6d2373b
41bffb035560aeeb3d2f29aa841e7e720a5eee2aadb4717f5b874b54d07375f6
c101e6bf92c9106ff2c1f2b729c6f8876296570a2c34579755e0ed4b6527ef69
6833c243605f2cbce11cb5bf26359c068588b9b1ac0e564bee019dd45a972b53
d6a552186e5681c84a98bb28235bb1a863a0877585e984b15f38e7dfd0619225
4206293a4d4e9b93abdc77721e4c1ba151656f25c21fda7677066e0e772471b8
2bfc56f2d75628c46bc823eabb6965763268b879a249993d42794624221cae0f
499e49eaa56930307412bfe977a827c0d9ab0c361b319f912e78a13b03154af1
86ccb2e2b2b1780ec85596c64030ce2525145afa00f9e3db1c3582c4f4afe7e6
8dc5ce1b016bdaebc7d77a20cccf815a49840e239c33132d35504d03c5f6ac99
1cb4254b1a62245b30f20ccffbefb79c36b1ef324c6d401cfb6d48ddb00ce6a0
1d6d55330b2acdf2edd8d1bf9f2f134ebe700dff202939f1c1b31ad5aef41118
10364e0c6aee6b43975fd53d6289dd7e6e0f7891d4a5636cb938f68e00717d85
c0b99a4d83d20539cbcb64a75cf4195277d63ef20113a3d3d5a1affe9db263e3
SH256 hash:
059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522
MD5 hash:
57be41b56110386ad16ade8622cb54fd
SHA1 hash:
aa63618eb0bd0bce5d957263f57fe4a666a50b21
Detections:
AutoIT_Compiled
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIT_Compiled
Author:@bartblaze
Description:Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

Executable exe 059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
CHECK_NXMissing Non-Executable Memory Protectioncritical
Reviews
IDCapabilitiesEvidence
AUTH_APIManipulates User AuthorizationADVAPI32.dll::AllocateAndInitializeSid
ADVAPI32.dll::CopySid
ADVAPI32.dll::FreeSid
ADVAPI32.dll::GetLengthSid
ADVAPI32.dll::GetTokenInformation
ADVAPI32.dll::GetAce
COM_BASE_APICan Download & Execute componentsole32.dll::CLSIDFromProgID
ole32.dll::CoCreateInstance
ole32.dll::CoCreateInstanceEx
ole32.dll::CoInitializeSecurity
ole32.dll::CreateStreamOnHGlobal
MULTIMEDIA_APICan Play MultimediaWINMM.dll::mciSendStringW
WINMM.dll::timeGetTime
WINMM.dll::waveOutSetVolume
SECURITY_BASE_APIUses Security Base APIADVAPI32.dll::AddAce
ADVAPI32.dll::AdjustTokenPrivileges
ADVAPI32.dll::CheckTokenMembership
ADVAPI32.dll::DuplicateTokenEx
ADVAPI32.dll::GetAclInformation
ADVAPI32.dll::GetSecurityDescriptorDacl
SHELL_APIManipulates System ShellSHELL32.dll::ShellExecuteExW
SHELL32.dll::ShellExecuteW
SHELL32.dll::SHFileOperationW
WIN32_PROCESS_APICan Create Process and ThreadsADVAPI32.dll::CreateProcessAsUserW
KERNEL32.DLL::CreateProcessW
ADVAPI32.dll::CreateProcessWithLogonW
KERNEL32.DLL::OpenProcess
ADVAPI32.dll::OpenProcessToken
ADVAPI32.dll::OpenThreadToken
WIN_BASE_APIUses Win Base APIKERNEL32.DLL::TerminateProcess
KERNEL32.DLL::SetSystemPowerState
KERNEL32.DLL::LoadLibraryA
KERNEL32.DLL::LoadLibraryExW
KERNEL32.DLL::LoadLibraryW
KERNEL32.DLL::GetDriveTypeW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.DLL::WriteConsoleW
KERNEL32.DLL::ReadConsoleW
KERNEL32.DLL::SetStdHandle
KERNEL32.DLL::GetConsoleCP
KERNEL32.DLL::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.DLL::CopyFileExW
KERNEL32.DLL::CopyFileW
KERNEL32.DLL::CreateDirectoryW
KERNEL32.DLL::CreateHardLinkW
KERNEL32.DLL::CreateFileW
IPHLPAPI.DLL::IcmpCreateFile
WIN_BASE_USER_APIRetrieves Account InformationKERNEL32.DLL::GetComputerNameW
ADVAPI32.dll::GetUserNameW
ADVAPI32.dll::LogonUserW
ADVAPI32.dll::LookupPrivilegeValueW
WIN_NETWORK_APISupports Windows NetworkingMPR.dll::WNetAddConnection2W
MPR.dll::WNetUseConnectionW
WIN_REG_APICan Manipulate Windows RegistryADVAPI32.dll::RegConnectRegistryW
ADVAPI32.dll::RegCreateKeyExW
ADVAPI32.dll::RegDeleteKeyW
ADVAPI32.dll::RegOpenKeyExW
ADVAPI32.dll::RegQueryValueExW
ADVAPI32.dll::RegSetValueExW
WIN_USER_APIPerforms GUI ActionsUSER32.dll::BlockInput
USER32.dll::CloseDesktop
USER32.dll::CreateMenu
USER32.dll::EmptyClipboard
USER32.dll::FindWindowExW
USER32.dll::FindWindowW

Comments