MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 698e1b8cdcf63ffd2c9d4d9a246eef3a3f60b41cd1689fbf55412b78239f7e44. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 17


Intelligence 17 IOCs YARA 5 File information Comments

SHA256 hash: 698e1b8cdcf63ffd2c9d4d9a246eef3a3f60b41cd1689fbf55412b78239f7e44
SHA3-384 hash: b9dec0fdf82f89b7e0dcf4059d5d93c2c06fb6b7c2b0d0d44a0d6abb5940a8f395dadd11b02c4def4b7b65144dc22d7b
SHA1 hash: 8ce4b4828560504d1d4015dc4e77409a7f84be65
MD5 hash: 61ad00879835cd123b6b36ff4f05744e
humanhash: neptune-wolfram-jupiter-september
File name:698e1b8cdcf63ffd2c9d4d9a246eef3a3f60b41cd1689fbf55412b78239f7e44
Download: download sample
Signature AgentTesla
File size:1'177'600 bytes
First seen:2026-06-08 08:40:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'067 x AgentTesla, 20'020 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 24576:SlRhhrPtibbVOk56mYZ9z9lXIZlY0z5IchtJ25Sh47g5wFSSSI/:utli0iJQz2lYqIAqSG
Threatray 4 similar samples on MalwareBazaar
TLSH T1C54512443206CD05E5569BB98C70E3B417344E80F871D327AEFA7EEF787665668283E2
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon eaeaa8a8eaaaa8aa (3 x Formbook, 1 x PhantomStealer, 1 x DarkCloud)
Reporter adrian__luca
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
virus krypt lien msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-26T00:38:00Z UTC
Last seen:
2026-06-08T07:43:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-05-26 03:29:04 UTC
File Type:
PE (.Net Exe)
Extracted files:
14
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Unpacked files
SH256 hash:
698e1b8cdcf63ffd2c9d4d9a246eef3a3f60b41cd1689fbf55412b78239f7e44
MD5 hash:
61ad00879835cd123b6b36ff4f05744e
SHA1 hash:
8ce4b4828560504d1d4015dc4e77409a7f84be65
SH256 hash:
c3642477410d346a3300a79109c1f8471e60cfb745fd4927ad8ce55a79bee573
MD5 hash:
16e81df52f8641a0f0f8a531d07fcf2c
SHA1 hash:
2d7f9cfbe6f6449dcfbb4ee8b08ebaba992495eb
Detections:
win_agent_tesla_g2 AgentTesla
SH256 hash:
08282737652b6044c13515305f7093c2c115ff2f6c03949072fd0c3045a1e1bd
MD5 hash:
6e3fa45715fd113c4665e2d3fd4db981
SHA1 hash:
5e9b2105d370a2e4a3ca107e4228e81efe00fdd9
SH256 hash:
aee93a7b785cc0e825c7de19bd97f95563d05b77e7c8b816bea54bf14936dd0f
MD5 hash:
46c57cb9fa8bac0e52a77e8354bb35d1
SHA1 hash:
e326052186b300afb09faecd5ed26c47dc73e800
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments