MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0b40807dfedf1f90c902cd919c7bf04cd89896498b80de9c5b0ac02e2b3e6599. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0b40807dfedf1f90c902cd919c7bf04cd89896498b80de9c5b0ac02e2b3e6599
SHA3-384 hash: 20aff42575d1395b41349f22485ac45478f525feb3912253a2566fbe2b30c10de9a8dc453e23a88c8e8945a19bccac8a
SHA1 hash: b85f4405a75706c4ad866883657737f703e1a921
MD5 hash: 3dfaa6e0bd2aa34d7faec4875c1eb33b
humanhash: blue-social-summer-green
File name:Payee advise Updated value date due to COVID-19 Lockdown.exe
Download: download sample
Signature AgentTesla
File size:447'488 bytes
First seen:2020-04-21 05:51:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'744 x AgentTesla, 19'608 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 12288:Ji2Knt2x4xQB4OT9ZvZE1JVhEmEO+OxgSnLeL3FnCwtJ:9vxYQBDbOPV5gSnLeL3FnfJ
Threatray 1'173 similar samples on MalwareBazaar
TLSH 4F9402853A1CCE6BCA7D09FA4597004813B5563DB6D1E7A94FC4A1D989CBBC0ED02EB3
Reporter cocaman
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

AgentTesla

Executable exe 0b40807dfedf1f90c902cd919c7bf04cd89896498b80de9c5b0ac02e2b3e6599

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments