MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fc06941e07dbff9fe5756f2803fe0075f29a7eca3969db7947b4d33d8ff6601. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 14


Maldoc score: 132


Intelligence 14 IOCs YARA 2 File information Comments

SHA256 hash: 4fc06941e07dbff9fe5756f2803fe0075f29a7eca3969db7947b4d33d8ff6601
SHA3-384 hash: afc711afdfd9a8fb94588986274f5ae8f90b9af727c441ccbf644556023f9c1133e575aaa864d850db4fc02814afbbb9
SHA1 hash: 49e6375f4d3f0c86658f19937a529bbda5cdc828
MD5 hash: dbcff0beaec0ad19c11a28a2f1c50a96
humanhash: london-golf-carpet-speaker
File name:Purchase_Order_PO111_125895.xlam
Download: download sample
Signature AgentTesla
File size:651'139 bytes
First seen:2026-08-11 08:36:07 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 12288:AwZvPYLSnYCby1bJ4ao7xh+wc28JlgQL9GZ:/BPszCbSbJ4/dh+p5TgQB+
TLSH T11CD4232E2413922FE5E136696D2D0C7D466DA0D2C2F1745CBACACA9714F13879B133AF
TrID 61.2% (.XLSX) Excel Microsoft Office Open XML Format document (34000/1/7)
31.5% (.ZIP) Open Packaging Conventions container (17500/1/4)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika xlsx
Reporter abuse_ch
Tags:AgentTesla CVE-2017-11882 xlam xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 132
File Format is MS Excel 2007+
Container Format is OpenXML
Office document contains 8 external relationships (see links below)
RelationshipExternal Link
hyperlink https://www.adobe.com/fr/creativecloud.html
hyperlink https://www.adobe.com/fr/creativecloud/plans.html
hyperlink https://www.adobe.com/fr/products/special-offers.html
hyperlink https://www.adobe.com/fr/creativecloud/features.html
hyperlink https://www.adobe.com/fr/offer-terms/cc-full-special-offer.html
hyperlink https://www.adobe.com/fr/creativecloud/business.html
hyperlink https://www.adobe.com/fr/
Embedded Images

MalwareBazaar found the following images embedded in this file:

MD5 hashdc.creator# of relations
bbc209c5f1e3f8b1d98d1fba0ad1a90eWIZZY PCNone
OLE dump

MalwareBazaar was able to identify 3 sections in this file using oledump:

Section IDSection sizeSection name
A1838537 bytesole10NaTIVE
A20 bytesmiUP64fPjVgfNg5lEmzo8C

Intelligence


File Origin
# of uploads :
1
# of downloads :
154
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Purchase Order PO111_125895.eml
Verdict:
No threats detected
Analysis date:
2026-08-11 12:21:50 UTC
Tags:
attachments attc-unc susp-attachments doc-url

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
text/xml
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Creating a window
Searching for synchronization primitives
Launching a process
Сreating synchronization primitives
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Embedding Objects
Behaviour
BlacklistAPI detected
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
embedequation exploit masquerade obfuscated shellcode
Label:
Malicious
Suspicious Score:
9.3/10
Score Malicious:
94%
Score Benign:
6%
Verdict:
Malicious
File Type:
xlam
First seen:
2026-08-11T04:16:00Z UTC
Last seen:
2026-08-13T05:52:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
72 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1955740 Sample: Purchase_Order_PO111_125895... Startdate: 11/08/2026 Architecture: WINDOWS Score: 72 35 use1-turn.fpjs.io 2->35 37 us2.roaming1.live.com.akadns.net 2->37 39 12 other IPs or domains 2->39 49 Malicious sample detected (through community Yara rule) 2->49 51 Antivirus detection for URL or domain 2->51 53 Antivirus / Scanner detection for submitted sample 2->53 55 Multi AV Scanner detection for submitted file 2->55 7 EXCEL.EXE 227 65 2->7         started        11 chrome.exe 1 2->11         started        13 chrome.exe 2->13         started        signatures3 process4 dnsIp5 41 mr-z01.tm-azurefd.net 150.171.110.146, 443, 49763, 49780 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 7->41 43 mr-b01.tm-azurefd.net 150.171.110.147, 443, 49744 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 7->43 45 52.110.2.4, 443, 49740 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 7->45 27 ~$Purchase_Order_PO111_125895.xlam.xlsx, data 7->27 dropped 15 splwow64.exe 7->15         started        47 192.168.2.5, 3478, 443, 49735 unknown unknown 11->47 17 chrome.exe 11->17         started        21 chrome.exe 6 11->21         started        23 chrome.exe 11->23         started        file6 process7 dnsIp8 29 bam.nr-data.net.cdn.cloudflare.net 162.247.241.14, 443, 49976 NEWRELIC-AS-1-NewRelicUS United States 17->29 31 ax-0001.ax-msedge.net 150.171.28.10, 443, 49818 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 17->31 33 151 other IPs or domains 17->33 25 Chrome Cache Entry: 1709, PDP-11 17->25 dropped file9
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Highly Suspicious Document Office Document
Threat name:
Document-OLE.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2026-08-11 07:10:08 UTC
File Type:
Document
Extracted files:
23
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments