MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 576f4658c5c58273967350871dfd6d60e64d54d772c812f8507de67d4784f6ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 19
| SHA256 hash: | 576f4658c5c58273967350871dfd6d60e64d54d772c812f8507de67d4784f6ff |
|---|---|
| SHA3-384 hash: | d3d3a2e3dc6252085015c3049b14437cf5155f2c40c82d8a603de163a9fcda8ca56ba364e24f0cac408f9fd005c87807 |
| SHA1 hash: | f56a646248755bccb3e889611dc6631b2c885555 |
| MD5 hash: | b5a0c11acde8300f629c93e1146dcf1d |
| humanhash: | sweet-three-leopard-london |
| File name: | Payment 23832 Proforma INV. Bank Confirmation.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 778'248 bytes |
| First seen: | 2024-08-20 10:13:23 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'205 x SnakeKeylogger) |
| ssdeep | 12288:9OcbCwgqaVouaZ29rayNuQJPrBt72Tm48+O2D2yxekrI6wurYLP80PlDskR:9XC/qaSuaUpJzLyyyboWIi8LP8KDb |
| Threatray | 1'966 similar samples on MalwareBazaar |
| TLSH | T1DCF412A88304885BC56ACAF0D4D4D374D3B68E16A092D346DEEEBCBB76EA3F504415C7 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | 806cce9c90c06488 (7 x Formbook, 6 x AgentTesla, 5 x SnakeKeylogger) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
7534c32fa2dff5d752801f84545c23d8c09b7b8a698a61169a9e1a851699120c
7e9e2285a304449495c336285f1f7f0153c175ab2cd5c35492d6565d89c8c137
6cc066c3a33644d8a54496de97374b7a8804b490f7d3ca66c62c1bc6cb695fa5
72e7a39bce46e45402cbb4ae13053d57e87a62b06b53164acbe8c18ccf7dc696
db87b7e683d92aa8d013663c6bc6ba116023af2cb7f9ec6c2ad88694235f2b12
d6cbd0b24b82cebe1a66094b0678d66c5f508f5a1c98d7143de9d1871daeffc3
72e3890b8af3c836705f640704aa03680b1092e5c021a2bfff35d931062bfd89
13f0a05e86fdf85e8891b494574421ff3da0be5e7a71e48f7e32f6c9f35eb2f7
7d50338fe1feeb6944bfd552e44f266d764dafc089b853a6ee24f67ef322c124
9e6875db397f7d76fcae09d39360a73237b11b1fbfcfa7275bb7fe7cf0d87df8
943d44f043396e794716c4d82c4345e749eead0807592339cdde186a7bd83c51
a76d6e19ac59db6afea91b625c29f06f25316ccb74e1b7bdd59c68cb0aefac34
b9996528bea4f182b005ba60e72f604602f0749e5b083a013d6096a3960052d2
00082a148e8eb6745164c0cbf7c142539ada8fb4004deb8b3ae028b7181c552b
053c940f835b1c6624b6b0421b680da5c984b056734db107a7d6c8dfbe1837fd
8e3db35284b6e1ea560c14a69ea4dfd6ef8e27fe9974a609116d00f2d764bfeb
e7573cb6869df680fa42552e27b1a6bd2cd5a76c48b1660a41897dc30a0e53ba
f8353eb981e7fce8af5663a30b6ad844d44d7eda87ff717f85f0046e3c065985
ee6a1171d804498d93b3877e1649a3f0075ffad676875c875e4778823323692e
35a9609805bde63b4e22255d365fc6a61724fcb9f8456899bb085b76f0160d5d
d00af7d1aa35864537045299a782f3b010d5fe3a7e40bbe04846a2baa07a93a3
75a2f037e46961ac9e70ac8a8d52f06b4b20786ac7ac596abbb039c6a2715430
d3c4f42060fe5520553f915832b413f6f8f0f55307646f86b44b150389069463
40cebb630f935210e93b1e5569a1181a0c19cee3c4c129550dece7add29f27b6
f5dcef48d10d26c35b7123ed8b8281eb18b0aabd2fba48509da1d75732804d0d
013f695b5ec6d00214cc5835bb446a73382871e90cb17c6d8922c3b3ef7484c5
8b9ed7cbe84b68a9b190a2cfc34c605bc1e2f3851f8eeeb84d4313d8b42431ff
c9f0c595e62ee31b17e1b62cc7be551a1cd46c3395a282fead293a5033674328
046735ced511c1064c2ea51fe6fd55ea1dc5a2d19e608bea4c8df9f8f376a78d
29fc4ec2272e265faf58a71365d463e953c20dcfa192b6208a1fd6ddd25a7f11
4da4d8e83255158a09663b9da8faaecae3a0a9175571aee37567f224cb34e694
d100685c3e62fde73e33854186142c68d4fdab117a4c2eb11a1c73dc362a1277
81ed143389ad903c7669aa1da459fbda5b0d93a157ddddb7ddc1ff8e22b97e96
e762546dc786deba408a71f5cb8369a84e56e07c21e75ac56a4a7dad522b28af
878f318722d59f4bf5e617bf4daef2f12f539170f16d5b263d816a03b9d5107c
1ee774ec1cf70a9cbb1a383d7c7c61156308d936e070a0b8e726b9892dde2ca9
ae284655948354c6ed48e95cf2aaa058d376ed19d2aa69aa38eecea72ee2f576
6fce035d54888d7895091ecee886b64043cbcb5cdb410457411ae156a822973c
576f4658c5c58273967350871dfd6d60e64d54d772c812f8507de67d4784f6ff
03bc82a58bda7eff17320728048c0d37fa376a64f08504e7c0454b743790d5ac
1fb620b3a5fef04e16e34e800f05b3cb7cbad920b33c66d799d305ad15801224
dcb417103bd0f315ba7cd30f1eadfca56a56122caec7ce4afe96b410931f43e6
7bc7edf2f2fafaa8457fb596cbbcdedafd23544d75e739e777b73790965df6bb
584022a11fa25bc77ada9ec361c791001f8d8da848930b386f42841d9e0be7d6
93af04866fe94141664174864c6965777d7f78897a27ca858d6f79b653ca943a
23b9b4a46c15c5fa3b7445e8041852f3dc831547903250209ca738b1a17fb7c2
ae082792bb09ee973564e6e71c92f547fcbef3fd5d6c3b4f8e2172044cf2591e
496ba3f23ddaf5c1514228f1ca90b1de4392a159eaac3ecbd5fbe3fbb28f819f
bd0e1cfd8ac5fef73e78b0a784c11682ed8d3120e6293d7d87425e5cd65d91eb
e0b9c05954186f5d54bcaf95e425448540d4a0fdc6cac1a12899bda66e38ac37
3a4cfc46e94f08076d2ada85e0d51cf06695bfb54ad5f37c316c70d582839d15
94338a235c9207ba31032496ba04d39ae887a3155c15d57347307df2dfa16242
7ebbd7733c41e5d8d4071ac4bccca6f76577d8dda2ef2a6723b90414f444454a
d613473068f000318d1015b85a0f49f9191263041ae8debcc7250876ae146304
4813a5905b2003965fe10155c8daf3cdbb57017af02483a53a2d5ca11a9270f7
cda34c7ddc45a0ac67f0f3745b91686c285bc86f108c5c2deb36c1c3a0fb5a4f
0876a062221ba67194143bb2b1fc83d87b22860cf5e8cff64239b4b9dc251d11
7fb1caac122f0f3640e234a54256f2a97b44bdd0881124191c352c7e797b7dc2
f230dd21df49ad4ab75c02bab7e245e6727eaa88d56fe148699831a995749592
cbebcef944dc8b96250fa57c98bef408a1f3f053f303871f89f8f3035b4b3e7a
cde4e54eecb8d93a3bf01b328a33b998ef032becee8b0e375225cbce85c4a548
394633bc848d312c2e79e48b1b10eadbce297624c6b844d4f643d93b1fb33c35
a4d1c2193d3db847e5c7132074a16826beff3d069e1ba83633b8ac7bc5c88f5e
bd010d6ec97048a7017725d3c45eef92c619abfff8ac0d8557d4325c23c662e2
88844a7569de556d31dfdd8cd8f9ec7cc2e8547148c24bcf841e728d61fb9ef1
13d1eb3cb74f8edec26f2fff6a691a9c98ae8e87777802ce1f0c67fbe3c7159f
c2d0cc385181b9e1685ce28e76d5bd1865843e67eb97796a6529bfaa34774816
ab5ee9cb5c02091cec9857e12e2ac854ea6dc1618a7a479ea4b7ebc12278c29d
e251e91c26b24c6bafb419121155f89ea9bd320b5f9f143eb2f38151d18dacd6
0a9f394309023d929f72a3b781f47bd79d64c6d1cf485849f952a307678b5590
f1966d8c36df489b3dbf5b888a502de7799b3ff66213806e4dd3633ed8ee2b80
b1930e02b9dd0ed9f33b15cb20b6212c54854d5bf5045696c73572ecec373395
9e40251e52536336aee3deb9b764441efff559f90a83987c3f51db874bdee361
d36c75eeda6238e518fffee0f4b12fc0fc2e1d56d478e07b64e71814b0f4e1bb
84bf811bb0d86dbbc7f5efba235746ad56824cfffa883e66789cbe4adec1a30a
c492361ce6fdd5550bcadc9d804b30f971ceeadcd8fc549bb1bcdc9cd1f82870
9f0940b08d229480a45cd4f9d104ab5da0829dddcd968581aee5fad92b91fa80
179e544a547fd06c8af3d0aa5160448c1acf22e0d0343832097788d916051570
03dff69ef246481d70ab1a83fe3273348d165a1bab36c664dce64fa0bd5236af
f95c4cfa4575ecce08ce137d4fa5ede9fd4356814c770120dfea81d1e3ed157f
ca0e44de77ca87bdd8f7e6d9e1b778d45bbfd729a2d343c7c48cadfced235b3a
6f3edb7e9cefd209427147f4162e5dd3c87f48d12c6b4efb15c5a878ca049380
b9da0460b53615326f9123d43025e966fcb844495ede3794631f9dccabda8a6d
576f4658c5c58273967350871dfd6d60e64d54d772c812f8507de67d4784f6ff
d71c77fa0c464289f6b7fb379d7fcbf0cdd6cc8d7bacf6c989a5f0eb5c215bab
10f0f9ee32494b68132fb2b33c3b6ff4c34c98b6b11e215b1f4de0570f37af5e
e6d7aea44d50f1a31e13ca848fd9dcc8eb65a2377e409f786dcb50756c82fcc0
7945ab65ff11a8dfe0222746cb2a8dd6feab5428106b0900aee2d695254fbf50
b70065cfa09b2db420f89631e95a49daf021760dda72d34b5d57c232ac4fb48d
0ad205b2d883bca56250246f308228379c27f6114d8b740014deeef53b3412bb
03207279845f2d90be8cd6b3b525c4a236838c52def79c0afffbdf7216a03b7c
ebe2099ee35888eaaff59d9fbcf780687a6c9cf9c87511aae8ce959c7e1fc193
ba22a1fd5ccbbc56dd6c30c556637865c156a5e332e6a718c336b9d591b86a9c
cbe1d843259a92581d16088969b0ed1758866626b4ae37e7445abe6bf099f155
ffc6b173f9b255702bdcbe65dd606f6154865c7fea2b2488305ba8f0d9ccef58
f69515024de365946c3a58ce3315898196dcca5a2d5a9ba3f5b257818df4055a
08e931e2b4a954a57c72df289fbe2e4971a912e453b71f19d1859f1a350f9fba
077dc59cc8a2b17c1c2f17f0620368fe3b252c881cdb600aee54662d2699351c
31280f11bf64367779cdf2d9e04b62fd7ad53c28fd44bdf70e7793583793aca3
b96554898f3c80d013795e72b387087d02368d444f6a0fc645edfe3958fdc98d
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438 |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables signed with stolen, revoked or invalid certificates |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | PE_Potentially_Signed_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.