MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6fb44726508256fa7a1275d852b4dd872363485eb743e31dfe14f1f76c23a14a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6fb44726508256fa7a1275d852b4dd872363485eb743e31dfe14f1f76c23a14a
SHA3-384 hash: 3d586949d21f762b7b7219274761e105ef852b04b21d324704906a42c68bfcc9b58659e7b8f110b693098a9b41696f27
SHA1 hash: 2e58921f61e37ae4bde6147585c6a6bc4c02583c
MD5 hash: a55395f19cb7bbd6753f526e027e26b7
humanhash: shade-lima-helium-fix
File name:M5vgpkzSOslPHv2.exe
Download: download sample
Signature AgentTesla
File size:633'344 bytes
First seen:2020-09-08 13:21:46 UTC
Last seen:2020-09-08 13:39:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'658 x AgentTesla, 19'469 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:CcU4JnrwDuu/PXZrFQJ19h3T2ORtUxxdVAaoJ3HkzG5Y6ukW4WZ70O+v6E0Ua:CcQX/BhEHNHU1GztHkzGgn
TLSH C4D4BE9D3210B2EEC857D4769EA92CB4EA617C7B831B5113902371EE9A7D887CF144F2
Reporter James_inthe_box
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
100
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sending a UDP request
Creating a window
Launching a process
Creating a process with a hidden window
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-09-08 03:28:09 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
spyware keylogger trojan stealer family:agenttesla
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetThreadContext
Looks up external IP address via web service
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments