MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 19


Intelligence 19 IOCs YARA 5 File information Comments

SHA256 hash: 142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
SHA3-384 hash: 7e680e4963bc842b12bb1a4048a80334e3582a814fab61da10c2389cea316f20fb9ec9d37e811dc88b96e14b61278216
SHA1 hash: 8f97457c4595ebe98409604d24c08503c5c925b2
MD5 hash: c2b256be7905de98c0d0e981033fad4e
humanhash: bluebird-august-avocado-sixteen
File name:SecuriteInfo.com.Win32.PWSX-gen.14524.5749
Download: download sample
Signature AgentTesla
File size:816'640 bytes
First seen:2025-02-06 05:32:00 UTC
Last seen:2025-02-06 06:20:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'742 x AgentTesla, 19'606 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 24576:bjNsRGNs1Q8SWxY9i1s9z+fH9K1KfsWy3:bBs+v8Ii1s9u9Key
TLSH T18B05D0D42761BB06C9791574D237DCF493A40DB8F405FA966FD93BDBB89E2138808B82
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
File icon (PE):PE icon
dhash icon 01d0f0e4e4e4f878 (7 x Formbook, 3 x AgentTesla, 2 x RemcosRAT)
Reporter SecuriteInfoCom
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
517
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
SecuriteInfo.com.Win32.PWSX-gen.14524.5749
Verdict:
Malicious activity
Analysis date:
2025-02-06 05:48:50 UTC
Tags:
evasion stealer amsi-bypass agenttesla

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
micro lien msil sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
explorer lolbin obfuscated obfuscated obfuscated packed packed packer_detected
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Check if machine is in data center or colocation facility
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to log keystrokes (.Net Source)
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Suricata IDS alerts for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected Generic Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1608024 Sample: SecuriteInfo.com.Win32.PWSX... Startdate: 06/02/2025 Architecture: WINDOWS Score: 100 48 ip-api.com 2->48 50 ftp.antoniomayol.com 2->50 52 antoniomayol.com 2->52 58 Suricata IDS alerts for network traffic 2->58 60 Found malware configuration 2->60 62 Malicious sample detected (through community Yara rule) 2->62 64 11 other signatures 2->64 8 SecuriteInfo.com.Win32.PWSX-gen.14524.5749.exe 7 2->8         started        12 AEwlIYnuzGNuA.exe 5 2->12         started        signatures3 process4 file5 40 C:\Users\user\AppData\...\AEwlIYnuzGNuA.exe, PE32 8->40 dropped 42 C:\...\AEwlIYnuzGNuA.exe:Zone.Identifier, ASCII 8->42 dropped 44 C:\Users\user\AppData\Local\...\tmp28FA.tmp, XML 8->44 dropped 46 SecuriteInfo.com.W....14524.5749.exe.log, ASCII 8->46 dropped 66 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 8->66 68 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 8->68 70 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 8->70 78 3 other signatures 8->78 14 SecuriteInfo.com.Win32.PWSX-gen.14524.5749.exe 15 2 8->14         started        18 powershell.exe 23 8->18         started        20 powershell.exe 23 8->20         started        22 schtasks.exe 1 8->22         started        72 Multi AV Scanner detection for dropped file 12->72 74 Machine Learning detection for dropped file 12->74 76 Injects a PE file into a foreign processes 12->76 24 AEwlIYnuzGNuA.exe 12->24         started        26 schtasks.exe 12->26         started        28 AEwlIYnuzGNuA.exe 12->28         started        signatures6 process7 dnsIp8 54 antoniomayol.com 162.241.62.63, 21, 35811, 49736 UNIFIEDLAYER-AS-1US United States 14->54 56 ip-api.com 208.95.112.1, 49734, 49738, 80 TUT-ASUS United States 14->56 80 Loading BitLocker PowerShell Module 18->80 30 WmiPrvSE.exe 18->30         started        32 conhost.exe 18->32         started        34 conhost.exe 20->34         started        36 conhost.exe 22->36         started        82 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 24->82 84 Tries to steal Mail credentials (via file / registry access) 24->84 86 Tries to harvest and steal ftp login credentials 24->86 88 Tries to harvest and steal browser information (history, passwords, etc) 24->88 38 conhost.exe 26->38         started        signatures9 process10
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2025-02-06 04:32:31 UTC
File Type:
PE (.Net Exe)
Extracted files:
6
AV detection:
21 of 24 (87.50%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
agenttesla unknown_loader_037
Similar samples:
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla discovery execution keylogger spyware stealer trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Looks up external IP address via web service
Checks computer location settings
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
AgentTesla
Agenttesla family
Verdict:
Malicious
Tags:
external_ip_lookup
YARA:
n/a
Unpacked files
SH256 hash:
142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
MD5 hash:
c2b256be7905de98c0d0e981033fad4e
SHA1 hash:
8f97457c4595ebe98409604d24c08503c5c925b2
SH256 hash:
95005796c3a48a1d263bc7fd555e154cf5ed682ed70165ac586e06acf1a226ca
MD5 hash:
c50b4d3ad62e0be7b50bf328ec2a2063
SHA1 hash:
3d6100f776a5cad89a45924a950b53f027c29011
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
d48ee1f6f04504d641c8769aeef83185c8de8745458a3fbc362cd53c20ef10d9
MD5 hash:
e89f78e780b64eeb920d5dfebd033ffa
SHA1 hash:
b964dc9e8f5350d3a917b6a26b58853099859d8b
Detections:
win_agent_tesla_g2 INDICATOR_EXE_Packed_GEN01 INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID MALWARE_Win_AgentTeslaV2 Agenttesla_type2
Parent samples :
ff8ed2fb198f232f7916240604c204d1e467103fda567dc287dd62ca3d478d76
10c2aed16bd496bca57f3cc817ad510cc0201ac1657fd75dde1377ca038a9adf
18bbef8347972904228a700b1ed16a560400d283f27b615730414f958e67045c
a025ca2161bf1125aa31aa65ba154f261f7dae204f7abfaf5ecf392eab8e9fc2
627830b9debfa8a0a8a9cfbb89c90c0b2bd236ebc50f42564a0c91ce4edb3943
b772162c5b510c5427be045abfdc43c29756217e2ed924ce4c4388bd457a4987
115a0abcf8bfe4d0320ecc08c9f0668f35dd796b7a74c6dfeb9d6fc7dc16d214
059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522
8024f9bb6c58be103e60c07bf09d3648b61bce12dbfb6277b18a85fd8a45bc4e
8d15bcc5eca4dbafc31d1ea92c4d34b86e5d30e6b4cb0da378570bdccd7242c1
6a31f54219ee0ddbfcb2aa841f922d48a849b1b047b8693ff8c2faad2ab8fac4
979e6920fc27cda0cb462b26f221a6e521e3974ae737022db7215747f54ff349
3a32996e922e69d2a01101f0fe601687d8d98f6392cb72cb984ad86b03f8236d
f87529bd57f54630ff4e0a8391d2e02bd04df4b83ec7c2b879dc258f81103978
d48ee1f6f04504d641c8769aeef83185c8de8745458a3fbc362cd53c20ef10d9
ca690123d14bd3632ab53a076f8bfb7bd2176248af6b735af9719aca77a024b5
86e6c344630b2458ef31796359d7c14538e95982c87c803d1ffd328f2ac2bab6
474651d4f8f510094648423d6a0d97b51d2847db856251740877331e101dd372
46a2479daf646efcab8cc6fbf8037d37703dabfc6aee279465e22b9a433c8c08
363da150d891da7bb5da8056414882429067a0fcb27f58363567567bf18a323e
d2d196a12c822020c4042d607be77746951b6cb3c16201ff21ca8e9c5c786209
dea077180d1a981a1a9bd8f901bc177236825f173e5e2394161811797933fdc2
91fee98b5957d145f144b61107ea0283fc3e02eb7e19b432e868ee45ffdc528e
35931dde3f9e60ae4cbf22e5348bc4afca8d6145137a27a25216edba8b66f68e
0502e71249410dba419218374909428d7d53cca90c3cfe8861b7f8eae432a4b9
1e6a8f176a0d7a9bd0321b4c032153f48b244be1584137453bf1afc07ea10157
80cae17ac36cdddcdd35027d72f10d019d82e256fe88e0113c66432137f354fc
97a8bf73809611ee4048adc2714685bd29bba3e677f5589b1053e30e0d98cf53
18b7930562b9f73f383204f2a09e2a76ab3d772a0d3813ea42bbff257430b5ad
811c8854ea3adcd1259c28cf1dc60e0a0a2f7a44f463e98f77c277a2a2f6394b
382b40ce3e7d7fc44a80d1b9190914a401c968be78c7115a8e4e3ccd40b8888d
996a678b9f2d2434c6da9452449c3f21aac4b5e15ba7ae8c0a5ecd429d287e35
89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b
ac0c869888d9501a709cb33762d8062ecf7139116a4c0dbe07171f2c5a77b96c
142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
5fc13e8395c7c4714caacc49471c400b47d85b490c329699060acaae6bd24eab
35c894c4142cf4d35b922afcee66e1c1d1feb7803ff904371c3efc38d6d2373b
41bffb035560aeeb3d2f29aa841e7e720a5eee2aadb4717f5b874b54d07375f6
c101e6bf92c9106ff2c1f2b729c6f8876296570a2c34579755e0ed4b6527ef69
6833c243605f2cbce11cb5bf26359c068588b9b1ac0e564bee019dd45a972b53
d6a552186e5681c84a98bb28235bb1a863a0877585e984b15f38e7dfd0619225
4206293a4d4e9b93abdc77721e4c1ba151656f25c21fda7677066e0e772471b8
2bfc56f2d75628c46bc823eabb6965763268b879a249993d42794624221cae0f
499e49eaa56930307412bfe977a827c0d9ab0c361b319f912e78a13b03154af1
86ccb2e2b2b1780ec85596c64030ce2525145afa00f9e3db1c3582c4f4afe7e6
8dc5ce1b016bdaebc7d77a20cccf815a49840e239c33132d35504d03c5f6ac99
1cb4254b1a62245b30f20ccffbefb79c36b1ef324c6d401cfb6d48ddb00ce6a0
1d6d55330b2acdf2edd8d1bf9f2f134ebe700dff202939f1c1b31ad5aef41118
10364e0c6aee6b43975fd53d6289dd7e6e0f7891d4a5636cb938f68e00717d85
c0b99a4d83d20539cbcb64a75cf4195277d63ef20113a3d3d5a1affe9db263e3
a4936a4097e62c30b69b84dc50bb66cf3461abe0728ae718b9ad8fd62c8b4042
7c6ae80da5a0bb3956691a73d978541291aa9ef6d11399b33a4f32fd4008e620
SH256 hash:
c94d846e2cdb1be9a54740b587959ab5c741ae3c40e30b4b2a10b49f3279f48c
MD5 hash:
3fe0a01522dd677ea56f0a69b4872a04
SHA1 hash:
d4cbc9272c9ea6d3ef9a2c73144c9ebdcc8189d3
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
Parent samples :
e79f272da50c989ace58144be6791c62d1fed9067c29a43f39cc72986ff0d474
30af910477a154c4b07fa1cbb928f78bc7d714329f725b2a1f2cf7f3139ce351
2d5f57ef41272fafdd56ac619de62e86bf57938c96032cfa90eaa3c48930f012
6cfb80b408d5a7e58fb2fa1f7740cd0a185f59232f80da8dbb66baeebf7a0c71
baa5f55f0f4e35aa775f2237b524a7d06b366675fb9b63e02d4e822f2f422405
0313c7a5d73a613b775f28f1aaa5186b1f526b773e05e14f7fbcad1103d9f0c0
3aa419398e4918fa5f922f5d5ea8c2572c40c1b24c702ec4ff946eeb390f80c6
b1537055d6bd55685c9ecc0812c796b6668b3bb37dd6700b231e374d35ff6731
3aa746d45a8db14fb49d2fddd2141a8c41919fd262ef07140f2bb73e77e53147
beebda020556f8d3ea18fe84bb7ea68301fb9f821cf5a7fdc8c5e66b6e8a5c28
f4655548728c3901356c8b6c1cecb9f5531872b1cadd914c057d26136a45d5fe
bc6414a8917a46de783adaeb422fe1a90df4f608d16531c555529c9104c342de
43c802763ad10188bf10a16b5bbf7840447d46ec04d1bfc2ef60c58dab38d951
92f6167d4a5a568418c7439917b262922745f536b091f9b6d059ca7b4475d6cd
5e95fb52da2144a06a66a593a6f12877108ebcdeb69f8f60ad010831d4fce1eb
142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
b1d51bc9c016f36486682366f537633a12b95e16e68d7fc184f7a9bf9a48a811
5b40169c958b75d6080cc8e7fabcf81ac3d87ea0a3254d6ad2c95c158fa91aa2
06f5012aaf05a5d9aefec7a060851cf3d7ddce0220cc09b30cd87d10d69ba554
db1ac4c87efc64076e9cf93ec1581f73feea43ce6fdb7113101cf287a5968e80
bad55ab8c4ce39ff171bdbc3c86987d0b3b118aacf2ffcc38af811c739c64716
e9a1f5e4de3dfdf6cbd66863a6fa6a638cce8fa9555991756820b5af48682c79
c76072f42ba97861b01655026250c0920a3856a191144601e061318346e75e1b
76a9a68e8da599c81f44d2a43fb4fe5e5e4d2e6c5881ccf775ecd665c16939d8
78320f7a37d22d4c8c4c6be7c24e8cc3ae65775fdf5e4727fd2d72f5235c11bd
cb628a93ce3d454a17ac6653105550a7bd4af78195293640d270977ddd6a855d
6d230a2ab81a77b630dfd88b41120f44f02a96a2de01b155e25e90a09cf3cd7a
47af16cc5a248cf055155a57d1eb07844113a00c7a84802588ef7dc5f007880d
9116e489568656d24b28ddc5150f55f3010c3516515254b06cd8151437bdc6a3
f206c3a093c6174558ea0646b12e262d8549bee2255418d8968d3e0bb7218330
5a673c2139bee9e5deec79e98e0baf1026af44a5a02487d474de76d16b7eddc8
97d2ac9df49a698cbe55f68068a93604206580f9696c8bf319d55c2e637c9727
1fa0169ab531ace73ff03fd6b6ebb8ee750a56e11b8244cacfa98f1161a9d739
682ea9386cf6916b93cd4d71b6e9a56766178c8479e9a5121ca42672d4680754
81479585d4d134cc2bdfbbf5a3200a9ec5ca2d142020b53ea3302239c595b37a
49038158ec5cfaad3a3e8afefb2103cf06da101cc0fc2f2a198a955c074a061d
5b34f76345fe3155d491e7362fbed7f9c7463499a90e5d7c3e2bc4e8924021f0
a58b12ce627c7234261b7561b7f1e2bb82bdfa745a20db1259443a99e6f8c6fb
a726c5a24472b6e81e1dce922e3d462a1abda9da5bdb28c0f3893850560b1fbd
af76b424c87632143ea89a16454dacf86eed65cd53cf866fdce8f3d850ebcd9f
d2a87b1b1a1106b874e949e49a55e7e68202eaa84062c270bbf62481bb769a45
276430cda6a885ecfb17858522287a43de317bd9e1b82a8ef1f5781aa24954fb
6b9f9c57c5f95587bf894a439c808a0769b52a08d8fc8890d6a96fd6eeab7ff4
3cb79b389e24d9c7cb87e631b41e0cf3a83b18d7205c7808266d9221928294c2
b57ff0328f7e2810454bd361fe4fcfa076335b72a906a5f671e72496b490d5ef
6b9f0f95c3f9c5d2619566c75b1c165b923a6ad6941ddcfb820089535c94b9a2
1b3f1ad1eeb6d8308f9df4c3b7c6dc2d6d37776048450b8667e63a5e4008379d
cd48d8a932004dc1eaa16ce32f98aa927758df295197a759e2717d41bb66071f
1ad36be5741291c602054a8c1dca25c2fe1a48d4834722993d8190303321a585
f90e011acd738452ec9514f5c197e18175e7506d502d85ff85583772691aa4dd
6042e232fb52a8ddef6d8107806b2eb734cf4a703941e4639e5d3aa8a27d2023
089b32cad49a1917e0e5bfec67d556bbfde5f1230dbffd35d5e15e6b5ed4b1d7
98d822362f112bdb88a5f473dbf4b9773e3f58df35a45dbd6633e44d85f904a6
c6b7c7784ebcff9da356fe18cdeb164d121d9def409bfe81f445e5c77cfea314
979cecac7761f1c8cf74b514b38b637c15407b9def72c96814bec589a1d4618d
570c0fbf80fba23ae65c80ceede951848ce522b9a767fae92812d4d3efb725cf
d80fa06e8d5cd185b7d34a1007a02144a21be64e31277f6fba94f497c37b0e9e
e724651fc42f3a926cbe09e79250de98f75da2ee22e55208ec506ecab7a9a18c
62bacfd17d10d4dae8dd039b5b2c577b382e1aa21357e68d4e49505b2b05b7aa
abd0798df773037732e34f3a268722a239ea2072b49e3a62bd028e56dc7ff87b
825e01addcbe463f65b398e93d3536a9dfa01bb7924c369ef5f3d5538d7c19ab
564c051102c81d441815759ce075755af3dbc66b0a0ac6dc31d43d87a0372fe1
472bbd27a17cd8121eb418b2d81d723ac0bafe8d4cd2d39d728cb8ec2991df05
851c91c41a429bb8d553a9918ae52b98905c845bed658c09b3978acf8f578945
a4aced5979808f369f5d41d0d2e8f0a16a6c1adbe00c751dfac858fe706a2f3f
972faafbe19f1bad0659c02d3480845254ac3fd8565668988d14c3c68164a953
a30ac8c321e2bb265f9e2d3f2cfb43549a8fa6171e68d7f4fceefd6db4faacac
b06c40802695123acaef9a4d74fa336c0d60779031678ba78368673ce6b00e2a
49a5a535b2f589a41ce1e579501e1f63c8f924bf36913e07409d805861595647
fd12f6777111b76365ba8df917957861400b2e0dac2e5f3cbe345d5b8bc63d81
9fbd289d00e29700adbef12d16b2612180a5d612bd66c2596541e5e005fcf63e
9bb7cc9096119efca0507d25fbe9f033bd9bed6b14eaef1da532648c2b5ea106
d672848afdf3f3a32d6de454a3408acd1d9cc0c338e65461e63330e9d26128ab
2c2ab475e2a419c64a72c777151bce185ab19aa14a8dc9124305c6bcaf3e4d46
145f6076604900c379d5a82d6a95e6c56df274b34d77158056dccb5834516461
7b6dbf313708726318645aa72ecabe962572e8008214dffab03c151012c2df68
895d51134ff58b23a2a81460e002598505dffc3fba80ee0e7df38508b87858bf
004d0b8aa2bc2236e124fceddc2ef21c091678fc622d6bce5ed02292b0b971e4
da2fc91a8833fbc7b55879d5596e20dd17346c9cb0f30429428d7d13eca262cb
a478e93349ce5a52ef85715758a4a42d698b8163f0f57ac8382afc59c5ada256
4275d29e9c1666fd0e34ef87cb0719162bd3ae3fdf76ae2d15b55916ed39c0c8
3efe9f9182cbdb755dc49bac25113a012be3ee51815ed8923ed1693ebb259685
44a303310f4e41f9a959b1219369ff984d664b65c668e605b20950ffef93762a
078087eb0c405c3c7ad7058695cd17b271fa9f4da6271c85ff868083377b8667
260832f7830afc5e87d0e512270ff69572c64268ee3e8f9b63bcafa5a7ba2fbd
ce108a4c76c010d33b950d3dc8d4bf3c381ebd94a2d725f473065b47abd43a0c
fb05aa2de5592ca3e33b658b17f32cbd7ab5dd676cddfd3677c87a704d2fba4c
0acb6194575f0349812f6d5b0153708d2da2a5a598aa16b345f6b8627aa01f5c
3429b3aecb0389737bbb2c3a5bfc0d4f4fb51f4c6b1d83522441bc2a5011c8b1
76e018370b6dbc4a5ff9700539116e740232db4e0f5cd355dc2949eb4a301574
441d4e2afda5dd4114f7ff1cde9d4c4722a187ebb2166a1047b9c1403bacf5a4
b52af535314ad644199d9804d08e7f8eea3cdbca51c06281241a3ac58365835a
cac687693f854a3b0f08331bba5865f58babbbead6a582a2a3f7b599092c65fd
72c54730956921bbe2e5d9013b3dfdc738a98a2868ace2b85d7becc16ae6e55a
abd32c39e276956fd1c91bb346763590209bd066f157f9e9fae6449b44653c3d
e6726560f11758a5ef619319f8c23174271e78d7ee083f1bf37a5bd45e966a3d
2a1b2e65014eff8d6898cb69bdbfd860aa7a71092b87c744dffb4c0620865a51
c27531e9608480a9890b88a18f5a99d230bf1dd60a3d0c80166c4db5a5707a98
b758560d291f4483bf7071fa3ff4017e1f421681a264cd8df1d72440a7020ce8
7fef88169bcdcb30ca4d56c7233082a64dd7b972d8684785211b30750d8e6db5
7a4a48270e007cfe195b3cbd18e16c77bac607a6f6c28ad76b6ea7b6aa28750b
6a48b22bd969313fc663ff3517d4d95c316623f099b68a0b5499cb0bb7f68f0b
82bf5f4e4901a995c6218cead424b929e53113cdb0e56c556fe28a7d692b96d3
85d43b46ad06b32280ce6c581e8790e7535887834d2e950059acd803d3642b34
ffe6d376f480727369e4fa7d6a17b2b2ed8069fa34e5332dbfa99a89c68459d0
342e04edadb5210656305e1a685e5522dce4abce4479a9f9f222310ff13dd3f9
25cc6ca776e3d36b9aa29c331b522f23f1b309398372089d51297ff179a51bb6
acdeac4a1cab9a2cd3c47b8007c81a04655bcb27defac1ec5676817d9f9ac134
853b91e9b020663d17ecc679445126b293adf51dab2791e846c31adf4fbb232a
baccebd3888e8622e858e7a771d985e3eeaf05b6b73d0b67df5bdb710ec65ba5
e943c5137000037827058d4fe5bd756651b2694475a67eae0133e48c0c3b681b
db6d68befa3050c4dc21ab5fefc0372416f90743170c4f2becc8642b02323649
b6ecc427d6063c9dea04d7c1430b5f3765a159df978b1885088b8e5c854f430f
7f014e3676f77bd509ae639d5140af5cee6a3df85a4e7874b6c12a3919770617
3381a1e8b1a7c8a1de20f09202ed545d3e3c055fd364cb10ce49713e9eb6d087
848cae5f1a0c17014efd9da7cd95bac99f6ea7d1c2cba5dd3383a4e68e96dd48
fcb20640b912b0513c2c1e7b5dfdca2f42a23e11aecbf0a82c4da76f8aed568e
b8df5ca9ec2fbb02bebddb499f4c1a966bf9da4581e68eeca99a195dbd94f4fb
9f05db230894256a6be6bf1b5b523894e621cf0b43632c0465c76717058d3ebb
0a51fa0ed0a7366f1b102b14a7e0eaf60085a4bc4b39fe997195fade34ea9b07
3ec5faa6aec2047d9e190157b3361a593ea590f14a80b42d22f4492ef68e48e7
aa23282f21a7d640fe80b4911b633ab1e5c42258a3369b9c0286ff84dccec9d8
52e613978faf4b534d0864a6125d73767b06319e9adaf7d42075527e2b52b3fe
d313827b50a344b6f5a1adb8392a5be95d65e07d0c58b2e3b91524b33caf5139
334f13d0f4a955f6791b01c716247155b1d7bc48d88d172d2dc8ecb22e50c56a
8d55fa3d01f0734c4e26c030f8abef3f5c45c34068d979edaa5e1ce669a7879a
2226cd28958b39a1020812943f39bdb8fa996d83191b539ed55e34c32396e8de
1c015ce771fcaf5114418dda8f33c9d357e64de65c2ad89ba2088883a67af9b6
b87da989bc58c277f819b39884a1a5097c6e55cc522cd482f1db530f10c38ed2
ae8d6d60a7a7056e4807da4304a9515621d1621d8f49f7e9eed76709f9db6746
2f7226f97fc49d8e893e80ff5e3e1127d0ae76650045dbf30c36ddd0535c0af1
8c511dab54355d76edfda60811e62b832f7593919b5c8f683b53bf6690bc808b
6659952ec8d1a38ab1ad872d5d1c56b725c90073584858729f6a6332d83b5564
b8224738e42c6dfc5b169c544cf98d4d2fff3fc1e0fba7220b85378a8ccf9395
dc9b1005fe4366eacbafdad4a8c7da5c899af7c738fb869f9ad4779625a00efd
f74aa66c0a64b0bc95576d70551981e1d0e65de9662885cb4dde19e81bce76e2
39d75551da5fe22de373ed7ac38f66be936fbf93a9124e5f519f49a241aed84d
851ba063e10c27e13f6ac12a86eecff1ec8e003911d758cfbb5f95b8ed985dd6
e640afdf9c7df0c233c559cb4ec688a7ea57d0b0803868229704bf5b5ed4bec5
19e7128bade3246917b6367e9ffb3dc01d8674cddabbf7db9a591eaf9e5314c2
e623d866b94e97d10d1bf96252a838ed9dcbf4b4aefce4f3f30599d49ab3b774
06b5af906a2a610798b5c99dc0bd5786bcb7a9abf4c3721dbaf86dbedcc3b81a
afbf51cbceee0bb274325a6bbdeb87bcaadf086f26b97a4715a0345d2d20252e
d252032918f92158cab050e67069c51851bf1e89e7889bc81ec6348bdb916cb3
6e3ba173c53740a0d1407dc29b7c3632b53e0213bfab4c6ff466cd77995606b9
584641f56519c5e21afd3a1e3aae649d185b648a382e1491b1f698e046cdb7d0
c07269f55d74289f36f6260586c9c0b32a88cdb43c6fda914170a585b37745e8
9328b16d02a62e535e62c57d581de1acf734d91f7b7f0e848047953a8567f9d4
c7d74ae26564e2f86c6c7f5369e2ba02f5a09d70a30630c2e67e5376ed7f4fb6
e654880ee3c416a237988b239e29a282457ca35f05fde6a3268e6cb3fce3a2a3
45e055a26edbd0721d1e26f89e65406b16f4786a288ca065ad0fcff26174ad59
fc6bf2babfb2487a702dfeb041870fa997ca3223eb54f05e2aabeffbbe14094f
9a29e3c73087476b7ca24c4d244c6dbebcf0918171793eb8100a5fb7f8713276
616f692b5adbb3cd0beb80a87f9ca3baf91f44d4c979ef27d4ea1e909de8125a
127e04d32bdfb06cb7a7a1106c2a5c661ea1141216f0049292d8346e7e6786e4
c2e9dc2928bccea6c828a536c81c0fc283761f0d0c98aa30c637ae2ac2889883
9d5d52ce9a834e1db4af530c93139f0119ab4abeb0418241a6dfaa58e9a42d31
44a234e2ebc159b044afa154f48b85f0a9634751638a7ca1f1a6817c5e3ffee1
2720aa12889bbf6c3f0b8f3fa4f17e003a07f20a3089743d4bf530cfe02f0a04
f668a40ba30c3360b506cd8bab8be44d245c843fe0e7754091acb60d6f55b953
7360456ec87f544e6a9eb05a88bf81e0ce693fb4b04f6a4f6a71d05ce524abdf
76e96e27e37385083c72099dff75860bc2f6b5dfe30008ea6594955a6158019c
ed5d0573850a7b710c7ee2250d0b1849bcbac27652482f302d9632b8cdab76df
94213c6a04939eca937ffffb3f938a7dfc297cc20cd7d02d5a8a06b69d56dc79
faa9fee2bec12a0b25d42223d3171fb74343937b0d4f3b15a02135e1f60367de
304cb6ee1b7c472e7779be689bae38156a157b10eb20f490026e1465154afdaa
241a8414a8cd502eedff5360d582a8b71e0e96c188299052ff9f75a153f325b6
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments