MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5a673c2139bee9e5deec79e98e0baf1026af44a5a02487d474de76d16b7eddc8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 20
| SHA256 hash: | 5a673c2139bee9e5deec79e98e0baf1026af44a5a02487d474de76d16b7eddc8 |
|---|---|
| SHA3-384 hash: | 2bb6ceb76b6af78b939b64ec88bcfdf6770f65a49ebe5fb14d5d24231d0c437d09f23bb3abddde5faabc7ef6a7069e84 |
| SHA1 hash: | b3a7185975123157a9a433b55cfa0e9a920c631e |
| MD5 hash: | d2c361ef9601a8a9ed36657ce47eaf28 |
| humanhash: | papa-neptune-salami-august |
| File name: | DHL_Delivery_Notification_Scheduled_Package_Arrival_February_12_2025_Tracking_Information.pdf.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 815'104 bytes |
| First seen: | 2025-02-06 10:02:37 UTC |
| Last seen: | 2025-02-06 16:47:28 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'451 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 12288:h8Z3cteat9dKPRhJTE/mtj9Ae8KZaaOfYatc811e8B6slRIp:uZ3ctecaJhwCpAPKMpAatF11ysRG |
| TLSH | T1BA05DFC03725AB06DD695BB09935EC7053B91DA9B010F6E2AED977DB78F87009A08F07 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | AgentTesla DHL exe |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
ae7c268e9b988e9fa86380095f0a5cbb7d04024505c01dab09feed5ab8551b8d
338bd51d53c8c482447321ad6d1ec585faedfc3b9d5429f3b33bd805eadbaf92
0a58b574ccfb2898c4ee47a8dab29174c2193731573d4578b7b5ff83ad1196d6
fda83ecb5bd6a07dedaf6be0fce7c626e21e9df94d82ddb905460e9d6a25a162
0dfe79bf85e9cfcbcd5ffa2cb21370eaf78d80d27ae4b4b0c5087afad5c6ebb8
60712b6d9bb023934b8d27fc6f54b3543a5ebfcd229cd1c4cb8f8dbaec08dc99
9952c53705dfc353eeaf4262192cc740a066cb2e401ae3ec9e2ba11706f429e2
23cd8546d36b29224b474b5fff6b67fea6a12c0bcc84b0cdc7e84ca23f5faf3d
be5f3e984fc55b64b4aafb52c1390a52ab94c92a345ba3008df931d2eb5452b5
c68ac751c2b84e31bd64a9d318fd5cde9c1fa7f9f9090940808fef7989b3ade9
a674d532150b92874dc954bb8349b6e66a006f1f7dd9381f751237cc98d38dc2
30f53c188f4ca288bab139778eb5426ee3db92ddc779c8df149b501334dd8dbb
59cbe4e681c4371b18a5f6d457369560ce9e4f0eda5a39de1acab8b5bdf73bda
7602098a6b2a95ca014488ce7c67b273a6189d7cc4daa09fb639c32fc21afa99
af1c4d4509e271497c9eac4c96c1fc5c4e419c6d73b69a5141380589e479c16a
a621353d9ba0b680e8f65d1951b47a74a08c1dc903eb071a64680a7a46793197
123afb912a466e9b9df29889e95595a3a38d8494d5a284a174ec44c243ea311d
130c869f7ce90b4dd45a1192c8cb13aa8e3f986ab29fb9f446475e2030a2d2ec
e79f272da50c989ace58144be6791c62d1fed9067c29a43f39cc72986ff0d474
10fd2d2e6c357bcffff543914c648b64fc672861551b5b098ed84a6db04126a3
2d5f57ef41272fafdd56ac619de62e86bf57938c96032cfa90eaa3c48930f012
10559de6aa9d0859f9a8b46c69a4edb950297610a98121a1fb8a3c94de06ed05
43c802763ad10188bf10a16b5bbf7840447d46ec04d1bfc2ef60c58dab38d951
b1d51bc9c016f36486682366f537633a12b95e16e68d7fc184f7a9bf9a48a811
5a673c2139bee9e5deec79e98e0baf1026af44a5a02487d474de76d16b7eddc8
e5ee0f86a7365463f8a0bdd3591624c214c8db88abf861d06d1fbd342a6fbfd1
a641f727fa4566ec19a3a04edcbe7e177aad8fb5f2381907e6c38adfa01f8a7a
6d98593e2de051c5ab3d36ddf4107ab2a0680bdb6bc73bdf9a75c62bb05b124a
cd47f0c08702e38c1ec62ae345136fb824e0ae0db0a8294b97ca9a474edec2f9
a4ce664077c1707b407385c08eb0f4e9299229717ee02b1b1b2f9745ad82613b
819f0be98d577e7949915dfd234c0ac0e0d12088eacab58f83a4418ad3675b4e
0b22914998a25304fe8e6dc1db692f037aa9b2066b43a53f0b24da35e629e6b1
470b09e386f5cd8befb4796af1aec03895b755d4219d6b9fc14e41ae5a400e23
f0c545e288910de036c58dd733fb4202b7cb45daa4e5f0e72e418544c4b1528c
b6f18002487b80c6378f7021d10cf6a6ccad659bb9e4a2c4aa9d016c48b8bfbf
aedfae05284600f51e6fe18a6f47ac68c7971e365d827bed7bc2205f27063c8d
30d5fcd7da81bc0b8d77d5b3547a227bac06bc781990f528c0bd78d696235779
357b3313f39b40d4b9acc1181d3eca642418b945e0b35cc0f3c436b9598fd8a5
353630ee79a8d39505ae091c60cb8352182cccdb9b861d1cf6ff2e19f2cc5b1e
af1593748a93b90fe69835554739c92bc7147611b405e8e93bbbffd65ec0c958
ab713363a32fee4abae9d10b1c18fd58454529f80947c5dc221379545b1c86a4
7a560acc97e0be33258afce759c4c215a91103e7b7447e487d540eca65959f4e
7c9d0d539bd2ffef3dfee864f3f7078937f7c9fe392df2f9511ad2a21be9446e
6c863b2dd3f9e7a690f4ab3a1ec9c7da83d2f20e7b82d58dae4bfae34218a878
156ffbc1adf860198501bf76e6428debdfa847e13e73796ee9bad6e982bf94d4
b7ca5eee2c0af78525e33094a2c1d38f639824b8f051a50216dc47417f426bba
cb627325f51d6abcc61a922937e0d66beb75a7c52f28341178dcfbcb01794790
dfb8ecbf4f52efbf20605c2be946d62bb062edf1dce896a9b45516c7aa90e422
b1f950d68fb3e445f741d2bb7fefbcfe1b1a756548dcc6f88b173cae77495b57
5abfe96f31b8b8e4013501cbd3e7bb332e03b37e96f04cb75f05c04f15bb66ac
e89363fb758ac1d01dffca3212cd980aa3fe199efda522052fc8c3e041b31f70
b456078d0dff3c375378480fb133a340d88ae4b59d6598ead4249d66523f3428
0707da3b9e454ee6ed7fe3bbc1e61811fa9907263ed843c98ef408f5f741690c
c368072750d355e8b4139efdc6c9007ce31c2989067248ab9312a4d7479015ff
efb452117b9b073d0200fb4ab2407615a33e2149fdebfba2881e711d187ed514
57752262d1f2b530fa014b31fe3d836f47d0b8ebcc81e275a9bf173b42f808a3
f9c3b78cce61d4ef1c118287edc5d5d3324bd64df1d2c704c087e7b073d7eb33
0f99bf966f34d5152ee51fd8510a37b3fc0792334c9b8f2475e896bc2ec72a6e
2f835a2d633b2fb81fb9375cefc17313e59a283de5869b7d7f04b42e9134cf25
3a8d95ebd1a116107405f1cb2a7d42e954643a9a0244ceef22a70b656b8525a3
6fa16359905843e294d5f805986bda12aa603775ea7db1eaf10beff3493c3b93
bf166be918695404ec2724b62671d7eac13fd67e39433894439d70a2ce534861
99d1f6ce99a8c07c33ee2dafe789299e0a51c2860882a2548c6e612606b1c1c1
ddb4d0771b710a59722707002a175602f29c6d1aeab70c61e0e9dc3eeeade55e
ed27568e72ac6bf7edfb74b5a35ea694d11ca0859753ec5816bf0d84c5803958
54368441d4ed3cdc5b14f8de606c9c0ef111838b10072a6ac68cd58d8b47bedf
c9a5fff84aef8b46605c9414b3d20e1f190e902454757c1f89179c5436422109
44ae98fe4b0b4bd2000ed7ec88e9b7458e04c1abbe64102142c1686ac4ac494b
80e7e263927b11a7f93f188d4e1e4ee34a4751187672e5298c03e6ceaf43d104
dad46ac711be7ee69322bea3f3069bcd644ba55cbbe635a232b1e76fdb08da23
73d81ccb9a09fc6ce1789df05b4fec440ba9aa3c0998da3a843e577a111def96
7b75b7d9e892e63a9fd39ccb87222d7311b6a3e9cba68cd34dc650e15e295796
3249cbb032d6aaf66c01aaddc48eab91417b1f22b97ddb659f2f5a5a5683bfb3
30af910477a154c4b07fa1cbb928f78bc7d714329f725b2a1f2cf7f3139ce351
2d5f57ef41272fafdd56ac619de62e86bf57938c96032cfa90eaa3c48930f012
6cfb80b408d5a7e58fb2fa1f7740cd0a185f59232f80da8dbb66baeebf7a0c71
baa5f55f0f4e35aa775f2237b524a7d06b366675fb9b63e02d4e822f2f422405
0313c7a5d73a613b775f28f1aaa5186b1f526b773e05e14f7fbcad1103d9f0c0
3aa419398e4918fa5f922f5d5ea8c2572c40c1b24c702ec4ff946eeb390f80c6
b1537055d6bd55685c9ecc0812c796b6668b3bb37dd6700b231e374d35ff6731
3aa746d45a8db14fb49d2fddd2141a8c41919fd262ef07140f2bb73e77e53147
beebda020556f8d3ea18fe84bb7ea68301fb9f821cf5a7fdc8c5e66b6e8a5c28
f4655548728c3901356c8b6c1cecb9f5531872b1cadd914c057d26136a45d5fe
bc6414a8917a46de783adaeb422fe1a90df4f608d16531c555529c9104c342de
43c802763ad10188bf10a16b5bbf7840447d46ec04d1bfc2ef60c58dab38d951
92f6167d4a5a568418c7439917b262922745f536b091f9b6d059ca7b4475d6cd
5e95fb52da2144a06a66a593a6f12877108ebcdeb69f8f60ad010831d4fce1eb
142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
b1d51bc9c016f36486682366f537633a12b95e16e68d7fc184f7a9bf9a48a811
5b40169c958b75d6080cc8e7fabcf81ac3d87ea0a3254d6ad2c95c158fa91aa2
06f5012aaf05a5d9aefec7a060851cf3d7ddce0220cc09b30cd87d10d69ba554
db1ac4c87efc64076e9cf93ec1581f73feea43ce6fdb7113101cf287a5968e80
bad55ab8c4ce39ff171bdbc3c86987d0b3b118aacf2ffcc38af811c739c64716
e9a1f5e4de3dfdf6cbd66863a6fa6a638cce8fa9555991756820b5af48682c79
c76072f42ba97861b01655026250c0920a3856a191144601e061318346e75e1b
76a9a68e8da599c81f44d2a43fb4fe5e5e4d2e6c5881ccf775ecd665c16939d8
78320f7a37d22d4c8c4c6be7c24e8cc3ae65775fdf5e4727fd2d72f5235c11bd
cb628a93ce3d454a17ac6653105550a7bd4af78195293640d270977ddd6a855d
6d230a2ab81a77b630dfd88b41120f44f02a96a2de01b155e25e90a09cf3cd7a
47af16cc5a248cf055155a57d1eb07844113a00c7a84802588ef7dc5f007880d
9116e489568656d24b28ddc5150f55f3010c3516515254b06cd8151437bdc6a3
f206c3a093c6174558ea0646b12e262d8549bee2255418d8968d3e0bb7218330
5a673c2139bee9e5deec79e98e0baf1026af44a5a02487d474de76d16b7eddc8
97d2ac9df49a698cbe55f68068a93604206580f9696c8bf319d55c2e637c9727
1fa0169ab531ace73ff03fd6b6ebb8ee750a56e11b8244cacfa98f1161a9d739
682ea9386cf6916b93cd4d71b6e9a56766178c8479e9a5121ca42672d4680754
81479585d4d134cc2bdfbbf5a3200a9ec5ca2d142020b53ea3302239c595b37a
49038158ec5cfaad3a3e8afefb2103cf06da101cc0fc2f2a198a955c074a061d
5b34f76345fe3155d491e7362fbed7f9c7463499a90e5d7c3e2bc4e8924021f0
a58b12ce627c7234261b7561b7f1e2bb82bdfa745a20db1259443a99e6f8c6fb
a726c5a24472b6e81e1dce922e3d462a1abda9da5bdb28c0f3893850560b1fbd
af76b424c87632143ea89a16454dacf86eed65cd53cf866fdce8f3d850ebcd9f
d2a87b1b1a1106b874e949e49a55e7e68202eaa84062c270bbf62481bb769a45
276430cda6a885ecfb17858522287a43de317bd9e1b82a8ef1f5781aa24954fb
6b9f9c57c5f95587bf894a439c808a0769b52a08d8fc8890d6a96fd6eeab7ff4
3cb79b389e24d9c7cb87e631b41e0cf3a83b18d7205c7808266d9221928294c2
b57ff0328f7e2810454bd361fe4fcfa076335b72a906a5f671e72496b490d5ef
6b9f0f95c3f9c5d2619566c75b1c165b923a6ad6941ddcfb820089535c94b9a2
1b3f1ad1eeb6d8308f9df4c3b7c6dc2d6d37776048450b8667e63a5e4008379d
cd48d8a932004dc1eaa16ce32f98aa927758df295197a759e2717d41bb66071f
1ad36be5741291c602054a8c1dca25c2fe1a48d4834722993d8190303321a585
f90e011acd738452ec9514f5c197e18175e7506d502d85ff85583772691aa4dd
6042e232fb52a8ddef6d8107806b2eb734cf4a703941e4639e5d3aa8a27d2023
089b32cad49a1917e0e5bfec67d556bbfde5f1230dbffd35d5e15e6b5ed4b1d7
98d822362f112bdb88a5f473dbf4b9773e3f58df35a45dbd6633e44d85f904a6
c6b7c7784ebcff9da356fe18cdeb164d121d9def409bfe81f445e5c77cfea314
979cecac7761f1c8cf74b514b38b637c15407b9def72c96814bec589a1d4618d
570c0fbf80fba23ae65c80ceede951848ce522b9a767fae92812d4d3efb725cf
d80fa06e8d5cd185b7d34a1007a02144a21be64e31277f6fba94f497c37b0e9e
e724651fc42f3a926cbe09e79250de98f75da2ee22e55208ec506ecab7a9a18c
62bacfd17d10d4dae8dd039b5b2c577b382e1aa21357e68d4e49505b2b05b7aa
abd0798df773037732e34f3a268722a239ea2072b49e3a62bd028e56dc7ff87b
825e01addcbe463f65b398e93d3536a9dfa01bb7924c369ef5f3d5538d7c19ab
564c051102c81d441815759ce075755af3dbc66b0a0ac6dc31d43d87a0372fe1
472bbd27a17cd8121eb418b2d81d723ac0bafe8d4cd2d39d728cb8ec2991df05
851c91c41a429bb8d553a9918ae52b98905c845bed658c09b3978acf8f578945
a4aced5979808f369f5d41d0d2e8f0a16a6c1adbe00c751dfac858fe706a2f3f
972faafbe19f1bad0659c02d3480845254ac3fd8565668988d14c3c68164a953
a30ac8c321e2bb265f9e2d3f2cfb43549a8fa6171e68d7f4fceefd6db4faacac
b06c40802695123acaef9a4d74fa336c0d60779031678ba78368673ce6b00e2a
49a5a535b2f589a41ce1e579501e1f63c8f924bf36913e07409d805861595647
fd12f6777111b76365ba8df917957861400b2e0dac2e5f3cbe345d5b8bc63d81
9fbd289d00e29700adbef12d16b2612180a5d612bd66c2596541e5e005fcf63e
9bb7cc9096119efca0507d25fbe9f033bd9bed6b14eaef1da532648c2b5ea106
d672848afdf3f3a32d6de454a3408acd1d9cc0c338e65461e63330e9d26128ab
2c2ab475e2a419c64a72c777151bce185ab19aa14a8dc9124305c6bcaf3e4d46
145f6076604900c379d5a82d6a95e6c56df274b34d77158056dccb5834516461
7b6dbf313708726318645aa72ecabe962572e8008214dffab03c151012c2df68
895d51134ff58b23a2a81460e002598505dffc3fba80ee0e7df38508b87858bf
004d0b8aa2bc2236e124fceddc2ef21c091678fc622d6bce5ed02292b0b971e4
da2fc91a8833fbc7b55879d5596e20dd17346c9cb0f30429428d7d13eca262cb
a478e93349ce5a52ef85715758a4a42d698b8163f0f57ac8382afc59c5ada256
4275d29e9c1666fd0e34ef87cb0719162bd3ae3fdf76ae2d15b55916ed39c0c8
3efe9f9182cbdb755dc49bac25113a012be3ee51815ed8923ed1693ebb259685
44a303310f4e41f9a959b1219369ff984d664b65c668e605b20950ffef93762a
078087eb0c405c3c7ad7058695cd17b271fa9f4da6271c85ff868083377b8667
260832f7830afc5e87d0e512270ff69572c64268ee3e8f9b63bcafa5a7ba2fbd
ce108a4c76c010d33b950d3dc8d4bf3c381ebd94a2d725f473065b47abd43a0c
fb05aa2de5592ca3e33b658b17f32cbd7ab5dd676cddfd3677c87a704d2fba4c
0acb6194575f0349812f6d5b0153708d2da2a5a598aa16b345f6b8627aa01f5c
3429b3aecb0389737bbb2c3a5bfc0d4f4fb51f4c6b1d83522441bc2a5011c8b1
76e018370b6dbc4a5ff9700539116e740232db4e0f5cd355dc2949eb4a301574
441d4e2afda5dd4114f7ff1cde9d4c4722a187ebb2166a1047b9c1403bacf5a4
b52af535314ad644199d9804d08e7f8eea3cdbca51c06281241a3ac58365835a
cac687693f854a3b0f08331bba5865f58babbbead6a582a2a3f7b599092c65fd
72c54730956921bbe2e5d9013b3dfdc738a98a2868ace2b85d7becc16ae6e55a
abd32c39e276956fd1c91bb346763590209bd066f157f9e9fae6449b44653c3d
e6726560f11758a5ef619319f8c23174271e78d7ee083f1bf37a5bd45e966a3d
2a1b2e65014eff8d6898cb69bdbfd860aa7a71092b87c744dffb4c0620865a51
c27531e9608480a9890b88a18f5a99d230bf1dd60a3d0c80166c4db5a5707a98
b758560d291f4483bf7071fa3ff4017e1f421681a264cd8df1d72440a7020ce8
7fef88169bcdcb30ca4d56c7233082a64dd7b972d8684785211b30750d8e6db5
7a4a48270e007cfe195b3cbd18e16c77bac607a6f6c28ad76b6ea7b6aa28750b
6a48b22bd969313fc663ff3517d4d95c316623f099b68a0b5499cb0bb7f68f0b
82bf5f4e4901a995c6218cead424b929e53113cdb0e56c556fe28a7d692b96d3
85d43b46ad06b32280ce6c581e8790e7535887834d2e950059acd803d3642b34
ffe6d376f480727369e4fa7d6a17b2b2ed8069fa34e5332dbfa99a89c68459d0
342e04edadb5210656305e1a685e5522dce4abce4479a9f9f222310ff13dd3f9
25cc6ca776e3d36b9aa29c331b522f23f1b309398372089d51297ff179a51bb6
acdeac4a1cab9a2cd3c47b8007c81a04655bcb27defac1ec5676817d9f9ac134
853b91e9b020663d17ecc679445126b293adf51dab2791e846c31adf4fbb232a
baccebd3888e8622e858e7a771d985e3eeaf05b6b73d0b67df5bdb710ec65ba5
e943c5137000037827058d4fe5bd756651b2694475a67eae0133e48c0c3b681b
db6d68befa3050c4dc21ab5fefc0372416f90743170c4f2becc8642b02323649
b6ecc427d6063c9dea04d7c1430b5f3765a159df978b1885088b8e5c854f430f
7f014e3676f77bd509ae639d5140af5cee6a3df85a4e7874b6c12a3919770617
3381a1e8b1a7c8a1de20f09202ed545d3e3c055fd364cb10ce49713e9eb6d087
848cae5f1a0c17014efd9da7cd95bac99f6ea7d1c2cba5dd3383a4e68e96dd48
fcb20640b912b0513c2c1e7b5dfdca2f42a23e11aecbf0a82c4da76f8aed568e
b8df5ca9ec2fbb02bebddb499f4c1a966bf9da4581e68eeca99a195dbd94f4fb
9f05db230894256a6be6bf1b5b523894e621cf0b43632c0465c76717058d3ebb
0a51fa0ed0a7366f1b102b14a7e0eaf60085a4bc4b39fe997195fade34ea9b07
3ec5faa6aec2047d9e190157b3361a593ea590f14a80b42d22f4492ef68e48e7
aa23282f21a7d640fe80b4911b633ab1e5c42258a3369b9c0286ff84dccec9d8
52e613978faf4b534d0864a6125d73767b06319e9adaf7d42075527e2b52b3fe
d313827b50a344b6f5a1adb8392a5be95d65e07d0c58b2e3b91524b33caf5139
334f13d0f4a955f6791b01c716247155b1d7bc48d88d172d2dc8ecb22e50c56a
8d55fa3d01f0734c4e26c030f8abef3f5c45c34068d979edaa5e1ce669a7879a
2226cd28958b39a1020812943f39bdb8fa996d83191b539ed55e34c32396e8de
1c015ce771fcaf5114418dda8f33c9d357e64de65c2ad89ba2088883a67af9b6
b87da989bc58c277f819b39884a1a5097c6e55cc522cd482f1db530f10c38ed2
ae8d6d60a7a7056e4807da4304a9515621d1621d8f49f7e9eed76709f9db6746
2f7226f97fc49d8e893e80ff5e3e1127d0ae76650045dbf30c36ddd0535c0af1
8c511dab54355d76edfda60811e62b832f7593919b5c8f683b53bf6690bc808b
6659952ec8d1a38ab1ad872d5d1c56b725c90073584858729f6a6332d83b5564
b8224738e42c6dfc5b169c544cf98d4d2fff3fc1e0fba7220b85378a8ccf9395
dc9b1005fe4366eacbafdad4a8c7da5c899af7c738fb869f9ad4779625a00efd
f74aa66c0a64b0bc95576d70551981e1d0e65de9662885cb4dde19e81bce76e2
39d75551da5fe22de373ed7ac38f66be936fbf93a9124e5f519f49a241aed84d
851ba063e10c27e13f6ac12a86eecff1ec8e003911d758cfbb5f95b8ed985dd6
e640afdf9c7df0c233c559cb4ec688a7ea57d0b0803868229704bf5b5ed4bec5
19e7128bade3246917b6367e9ffb3dc01d8674cddabbf7db9a591eaf9e5314c2
e623d866b94e97d10d1bf96252a838ed9dcbf4b4aefce4f3f30599d49ab3b774
06b5af906a2a610798b5c99dc0bd5786bcb7a9abf4c3721dbaf86dbedcc3b81a
afbf51cbceee0bb274325a6bbdeb87bcaadf086f26b97a4715a0345d2d20252e
d252032918f92158cab050e67069c51851bf1e89e7889bc81ec6348bdb916cb3
6e3ba173c53740a0d1407dc29b7c3632b53e0213bfab4c6ff466cd77995606b9
584641f56519c5e21afd3a1e3aae649d185b648a382e1491b1f698e046cdb7d0
c07269f55d74289f36f6260586c9c0b32a88cdb43c6fda914170a585b37745e8
9328b16d02a62e535e62c57d581de1acf734d91f7b7f0e848047953a8567f9d4
c7d74ae26564e2f86c6c7f5369e2ba02f5a09d70a30630c2e67e5376ed7f4fb6
e654880ee3c416a237988b239e29a282457ca35f05fde6a3268e6cb3fce3a2a3
45e055a26edbd0721d1e26f89e65406b16f4786a288ca065ad0fcff26174ad59
fc6bf2babfb2487a702dfeb041870fa997ca3223eb54f05e2aabeffbbe14094f
9a29e3c73087476b7ca24c4d244c6dbebcf0918171793eb8100a5fb7f8713276
616f692b5adbb3cd0beb80a87f9ca3baf91f44d4c979ef27d4ea1e909de8125a
127e04d32bdfb06cb7a7a1106c2a5c661ea1141216f0049292d8346e7e6786e4
c2e9dc2928bccea6c828a536c81c0fc283761f0d0c98aa30c637ae2ac2889883
9d5d52ce9a834e1db4af530c93139f0119ab4abeb0418241a6dfaa58e9a42d31
44a234e2ebc159b044afa154f48b85f0a9634751638a7ca1f1a6817c5e3ffee1
2720aa12889bbf6c3f0b8f3fa4f17e003a07f20a3089743d4bf530cfe02f0a04
f668a40ba30c3360b506cd8bab8be44d245c843fe0e7754091acb60d6f55b953
7360456ec87f544e6a9eb05a88bf81e0ce693fb4b04f6a4f6a71d05ce524abdf
76e96e27e37385083c72099dff75860bc2f6b5dfe30008ea6594955a6158019c
ed5d0573850a7b710c7ee2250d0b1849bcbac27652482f302d9632b8cdab76df
94213c6a04939eca937ffffb3f938a7dfc297cc20cd7d02d5a8a06b69d56dc79
faa9fee2bec12a0b25d42223d3171fb74343937b0d4f3b15a02135e1f60367de
304cb6ee1b7c472e7779be689bae38156a157b10eb20f490026e1465154afdaa
241a8414a8cd502eedff5360d582a8b71e0e96c188299052ff9f75a153f325b6
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTeslaV2 |
|---|---|
| Author: | ditekshen |
| Description: | AgenetTesla Type 2 Keylogger payload |
| Rule name: | AgentTeslaV3 |
|---|---|
| Author: | ditekshen |
| Description: | AgentTeslaV3 infostealer payload |
| Rule name: | AgentTeslaV5 |
|---|---|
| Author: | ClaudioWayne |
| Description: | AgentTeslaV5 infostealer payload |
| Rule name: | AgentTesla_DIFF_Common_Strings_01 |
|---|---|
| Author: | schmidtsz |
| Description: | Identify partial Agent Tesla strings |
| Rule name: | Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | INDICATOR_EXE_Packed_GEN01 |
|---|---|
| Author: | ditekSHen |
| Description: | Detect packed .NET executables. Mostly AgentTeslaV4. |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many file transfer clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing Windows vault credential objects. Observed in infostealers |
| Rule name: | malware_Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | MALWARE_Win_AgentTeslaV2 |
|---|---|
| Author: | ditekSHen |
| Description: | AgenetTesla Type 2 Keylogger payload |
| Rule name: | Multifamily_RAT_Detection |
|---|---|
| Author: | Lucas Acha (http://www.lukeacha.com) |
| Description: | Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | Windows_Generic_Threat_808f680e |
|---|---|
| Author: | Elastic Security |
| Rule name: | Windows_Trojan_AgentTesla_ebf431a8 |
|---|---|
| Author: | Elastic Security |
| Reference: | https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.