MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6a2dff579e9e1d9c274c0cfb88e34b815389ff242cd7e05db08badfd9d0699c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 18
| SHA256 hash: | 6a2dff579e9e1d9c274c0cfb88e34b815389ff242cd7e05db08badfd9d0699c0 |
|---|---|
| SHA3-384 hash: | d9151a57c8df1764323992b15a3623b3dfcf0e2ccaef75db2a2ec0b25f2952391569e56e82d4342345328ca9e6d0aee8 |
| SHA1 hash: | e54344846679c4eb74c0edece3061ed73baf4575 |
| MD5 hash: | 8c9c8e430e1eef28ed30c860b0d5458b |
| humanhash: | jupiter-eleven-five-oven |
| File name: | 6a2dff579e9e1d9c274c0cfb88e34b815389ff242cd7e05db08badfd9d0699c0 |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'000'448 bytes |
| First seen: | 2026-06-08 09:19:15 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'067 x AgentTesla, 20'019 x Formbook, 12'352 x SnakeKeylogger) |
| ssdeep | 24576:VE30nNrmH5uL3rSqGKukPx/TvRUlfbVbVzIIkr1:VJSHgL3OqGgRJUljVbVzMp |
| Threatray | 99 similar samples on MalwareBazaar |
| TLSH | T179251294269ED306D0B64BF02871D1B813746EAAE430C70B9FC93CDFB9B57A05845B97 |
| TrID | 72.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.4% (.EXE) Win64 Executable (generic) (6522/11/2) 4.4% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Magika | pebin |
| dhash icon | 68e48c98b6b6b4c8 (5 x AgentTesla, 2 x a310Logger, 2 x Expiro) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
HUVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
95f214d4e4b557548f2077ed9ab2f260471326b442a45824db16ec7c58fe0900
8a3fe2533d9c2036dd92b2b437b8d1ca237308d4383cdfb4cf13eadd9012060a
6fc591dec9831bfce04458d407a74f24728019a03ac61a8aa0cbc64791c68d63
ad131f58df2bb784cc7182a2afb12c7dbc9c139bcd881d913eb7776e9b399c02
2cbe0104d0a55f21c2f0e895a50df2ffdbdebfe2e020c7b5dead6aaeb233467e
a23faad998ccfd975f0123b836dd65c158f931f1ea3c01e5415c82a148b08f89
5300e3303b8d3213380216de0de7f3321cac74a6a8e5c7f2d506d3a5db92b42d
c38ce940408c9ec3b60a00d3329b4d3acbb2b801ecc173db0236ad8a35b8aa6c
3962e783a7d66e1fcc1a26328c1cb3f9e1af50a1005a447449999d5f5b8bd880
ce3562ba09381cf9931edac0983a7f732b5d1007ea878416fed7fb3a9958cb8d
6a2dff579e9e1d9c274c0cfb88e34b815389ff242cd7e05db08badfd9d0699c0
31e865593612d7aaaf78295fbcac8bbb765349eafa691fdf4fd624e0d2880a37
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | FreddyBearDropper |
|---|---|
| Author: | Dwarozh Hoshiar |
| Description: | Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip. |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.