MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0a99db14d49955334e10fe81245fd1f155f4308b6392c17282dbdf7ac2255e12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 14
| SHA256 hash: | 0a99db14d49955334e10fe81245fd1f155f4308b6392c17282dbdf7ac2255e12 |
|---|---|
| SHA3-384 hash: | 42d4832fedc923c9069a5082a0ae9d342244bf2ef86c893499b9c8401b2366d99b4e6ae0efcffe38166c8aa14c9927d1 |
| SHA1 hash: | af83beb7fb7c54e5cd845e0f9901fad39262edc7 |
| MD5 hash: | 2f2508bbace426bb456c27a2a240e753 |
| humanhash: | lemon-lion-hamper-grey |
| File name: | ooMNej81u4XDt83.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 674'816 bytes |
| First seen: | 2024-04-30 05:33:09 UTC |
| Last seen: | 2024-04-30 06:37:44 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 12288:bohB778Q1sazLdMw1UgNhzjMSwui32EdYOwh5q4rvn:khBHsazLCQTzwLnW1jq4rv |
| TLSH | T15FE4232D52DCABA4F7DE47FF6E9185078BB1B71309E1FB9925C034C9ED42B051A208AD |
| TrID | 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.0% (.EXE) Win64 Executable (generic) (10523/12/4) 6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.2% (.EXE) Win32 Executable (generic) (4504/4/1) 1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| File icon (PE): | |
| dhash icon | 4018f9e960e20464 (19 x AgentTesla, 6 x Formbook, 2 x PureLogsStealer) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
31c2094811f57fa89d734773efebb7edd3287ca9b3b89df8969ad71941006494
0a99db14d49955334e10fe81245fd1f155f4308b6392c17282dbdf7ac2255e12
7b4d102d36c7bfd0223c1cc849251b8ba1b9e8ebc85df98bbad6233ea2ad5ac8
d6e7c231b0aeee159700e68b79eb19d932e851a64a4a82ad1a1c72efc2faa72b
f1eab19801011161336857ec73752f3c5f9f63654cb89149854205c4357635b5
894d9676b643e6d8d16b0d77c93a01ebdfe38ac616923d903982978cbc450481
d465b497cc4e770a9deb09b102aa234991e38358f801f79dd2bb922a4c318497
63b303a4e01924ae9ca9fcfc7f75cf87144598342415df3cdd802440d770add1
5386b2eb77cc7380bec83dddc6594d4174a2ad01af73c29e813aa6a432779507
38100e0eb4432850500bed29244869b5e9b8d328e907352605b35f923ac903a9
06f6eccac99f9be344bfba51fbccb827405551767d00224ef06c2e2f525f95af
bc3bb7cdc4c87d2888c0c64f15f9953a79da7baa2d31874dd168db28f2b79256
809767aab51beef5e228607daf87e53a03d96b5ca11d31d1ea21f78fbe07b8df
7be312de7e9ded87516f8bd6fbc605def8f145f959a628bdbc100eb6dd449f00
ed1f8cb20d6acb1a1ff4da5c132ec4592fa7f0b6e7e162092ac7044f360dd15d
4047e764771fd462a5f5a98dcee4628968b550a8da08e82a8ba238fd8b09efb3
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.