MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 476cc1fe35e33d4d85763d170a06b654fa4c8994bc64b9ccaebe98c51abacbae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RedLineStealer


Vendor detections: 19


Intelligence 19 IOCs YARA 10 File information Comments

SHA256 hash: 476cc1fe35e33d4d85763d170a06b654fa4c8994bc64b9ccaebe98c51abacbae
SHA3-384 hash: b035cf83e389605e0d40def285b46bd6ef3273f9e5a8d725ba88b5c5c297a0fbde62918816da2fc7cdf87a77ba72cd51
SHA1 hash: eea1c10a47c0cb8fc2c48e10b912d15a2fc1fa9d
MD5 hash: 71da510bab006ad649bdbd7e8d4d6b4e
humanhash: potato-earth-apart-mexico
File name:DRAFT_BL_&_MBL_PO_NO_ECM1D2403-29.exe
Download: download sample
Signature RedLineStealer
File size:1'017'344 bytes
First seen:2026-05-21 13:39:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 21371b611d91188d602926b15db6bd48 (79 x Formbook, 65 x AgentTesla, 34 x SnakeKeylogger)
ssdeep 24576:OiUmSB/o5d1ubcv/FC9hRNezCQDgqK86Jjm2mq+Dzd:O/mU/ohubcvtCXyCQDgbMY
Threatray 1'586 similar samples on MalwareBazaar
TLSH T16C25235BC41CE198D87236B198A8D7BE92239F31D4604FB116F4BE833573E9C81CA59E
TrID 39.1% (.EXE) UPX compressed Win32 Executable (27066/9/6)
38.3% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
7.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.9% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
File icon (PE):PE icon
dhash icon c92526893c392131 (1 x RedLineStealer)
Reporter TomU
Tags:exe RedLineStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
180
Origin country :
CH CH
Vendor Threat Intelligence
Malware configuration found for:
AutoIt PEPacker
Details
AutoIt
extracted scripts and files
PEPacker
a UPX version number and an unpacked binary
Malware family:
agenttesla
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-05-21 14:13:46 UTC
Tags:
stealer ultravnc rmm-tool agenttesla netreactor

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
96.5%
Tags:
virus lien
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% directory
Restart of the analyzed sample
Launching a process
Using the Windows Management Instrumentation requests
Reading critical registry keys
Launching a service
Changing a file
Forced shutdown of a system process
Stealing user critical data
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
agenttesla autoit compiled-script infostealer installer-heuristic microsoft_visual_cc overlay packed packed upx
Verdict:
Malicious
File Type:
exe x32
First seen:
2024-11-08T03:38:00Z UTC
Last seen:
2026-04-07T04:42:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-11-08 06:33:45 UTC
File Type:
PE (Exe)
Extracted files:
38
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery keylogger spyware stealer trojan upx
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
outlook_office_path
Program crash
System Location Discovery: System Language Discovery
AutoIT Executable
Suspicious use of SetThreadContext
UPX packed file
Accesses Microsoft Outlook profiles
Family: AgentTesla
Unpacked files
SH256 hash:
476cc1fe35e33d4d85763d170a06b654fa4c8994bc64b9ccaebe98c51abacbae
MD5 hash:
71da510bab006ad649bdbd7e8d4d6b4e
SHA1 hash:
eea1c10a47c0cb8fc2c48e10b912d15a2fc1fa9d
SH256 hash:
19edb60074283051d9cc03995e75dabd791862b95e68fa94d4cd92c5068f1fe1
MD5 hash:
333feb82008c55ff8ed73ee9a2439cbc
SHA1 hash:
7d5545b8b96b8f8fe86c6c0334f75eb487cd3184
SH256 hash:
5b9a9daab10e69fca27727c0bd98bfe9383461095030d46fda542bb99d4c5b06
MD5 hash:
7189d3dd6be2a00627f1e4d3881ba071
SHA1 hash:
4717e5d833eb0ae148b6e913a4a7123c166ca48f
Detections:
win_samsam_auto
SH256 hash:
938dad0e291b10585f48a09ed931c43a74eca7e00b7e5d93c1de1253e5a4ea94
MD5 hash:
62ec21d8e5cb372c4c0940e263c77c33
SHA1 hash:
6a9088deafb709075938d7b714ed48aed753369d
Detections:
AgentTesla
SH256 hash:
10e6acb3dc4bcd0836c344439fb0f3adebca4fc9125121a44a2ac7a0b8cb72da
MD5 hash:
5140970891699c855454351efc5400f0
SHA1 hash:
9f22dd2edda0815f131df70705886c89dae4c1e3
Detections:
AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MALWARE_Win_RedLine
Author:ditekSHen
Description:Detects RedLine infostealer
Rule name:MAL_Malware_Imphash_Mar23_1
Author:Arnim Rupp
Description:Detects malware by known bad imphash or rich_pe_header_hash
Reference:https://yaraify.abuse.ch/statistics/
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:upx_largefile
Author:k3nr9
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:win_samsam_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RedLineStealer

Executable exe 476cc1fe35e33d4d85763d170a06b654fa4c8994bc64b9ccaebe98c51abacbae

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments