MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5fa5e7baf08438c75596491747f74e756630ec217d601c1ac9c33c3827f52a0d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 15
| SHA256 hash: | 5fa5e7baf08438c75596491747f74e756630ec217d601c1ac9c33c3827f52a0d |
|---|---|
| SHA3-384 hash: | 5fa4b3245cb916e61194332c393bdc5b6d2f12e2c3257a393542d2d66777e9c62c8b36de954e100ac113657e4a564163 |
| SHA1 hash: | c8c1ac9a51e7b3b7f99d63dfde659fd024d798f6 |
| MD5 hash: | 1348c2044d73f9d7b3b0c25ad1051831 |
| humanhash: | connecticut-black-magnesium-xray |
| File name: | ACCOUNT Attach.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 793'600 bytes |
| First seen: | 2023-05-05 07:19:24 UTC |
| Last seen: | 2023-05-13 22:46:38 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:yW11KduuLI0C0mKI+tghvwAP29fsYmQomhuqPr+eWFofXCQER9Hf:LPK0uEum8tgZpPcfsdW6erv9ERl |
| Threatray | 2'973 similar samples on MalwareBazaar |
| TLSH | T106F4F02533B9B7A0ECF683F86608A001AFB46D6057B6E6D84DC6F0C95194F0DF650B97 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
1863faaafba4ed1cb5e13451aab6ccc864569bd65c7f01e58da3c66f2f0bafb5
c6930aedb822a6dc5f7f7956e1e6fac29f18e045c92c1634eedfba7ec9bd138a
e756df77e86e02e94de56aa2afc47e715d1c11d891c96fab09adddbb91c18d42
758abca83bd447ee9d858b6535a6e8afaa024ecdda39c8d9987cf8d9773ea5c4
5fa5e7baf08438c75596491747f74e756630ec217d601c1ac9c33c3827f52a0d
d0f80693d3549f105e2db006994180bb647006072a107571c0f408fc187d1621
6e3e359cc194330109d69cf1327bd806135195bed196e3fabd14f6ccf9d3e79d
dce5cc1b0218e1f354e61012d9c5ffe4ff9f3c99e986faaf3d6386e5188b6fc6
61460fe1019d76b7dececc3c70ac70f58b05a372bc08ed5c591a521fc244d740
152d09a5037ea51e0ed7e7f7dce2551dd65f0805f6c0d6da9a0157b9c406c9e0
e5134d502b62ac76c8ba7c2bb7e729b348e6573d0829ce22777874d30cfc9fb6
ec1d8e37579205e9a77b181f281dfac637d28a5a446a03327698b8004e33249c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | BitcoinAddress |
|---|---|
| Author: | Didier Stevens (@DidierStevens) |
| Description: | Contains a valid Bitcoin address |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.