MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 305324e2931f477a0fda50fa6d98ff3d7a70919e07e593fbd505d9a6958e67c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 305324e2931f477a0fda50fa6d98ff3d7a70919e07e593fbd505d9a6958e67c9
SHA3-384 hash: 7519d0f29f10f02c19cae427a03c4e75f4d5612ac3136e593d147f14e98b1d53c29011e0018f57cb4a3d316fecc6b9c6
SHA1 hash: b853416eead1e474cd9933c3350b0c5be1573c13
MD5 hash: 82dd0b932fd4b9a9460ad1db561635e6
humanhash: berlin-fix-mobile-bravo
File name:ORDER INQUIRY.scr.exe
Download: download sample
Signature AgentTesla
File size:394'752 bytes
First seen:2020-06-12 16:52:52 UTC
Last seen:2020-06-12 17:36:38 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'666 x AgentTesla, 19'479 x Formbook, 12'209 x SnakeKeylogger)
ssdeep 6144:2pknieagJKng8aGMy0JxIodbdYS0e0uvx7PE0AlNYeRr+PJvhOnq1D/l0:2UKg8bMy0Mub8WQZYGr2hO
Threatray 8 similar samples on MalwareBazaar
TLSH 1784128933F42321D77BD7F52EA6E4440BB6542B8862CE0E5CE8D0C61D33B625C59E6B
Reporter James_inthe_box
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-12 16:52:23 UTC
File Type:
PE (.Net Exe)
Extracted files:
5
AV detection:
21 of 26 (80.77%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla keylogger rezer0 spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla Payload
rezer0
AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments