MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 18
| SHA256 hash: | 7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea |
|---|---|
| SHA3-384 hash: | eb2e70265df94b568612ed88cf673a309dd973ddd9a5acfcdc5366f5a2c92e59cc461d6393b05d8012262c858a0fad33 |
| SHA1 hash: | 7a04c2ba75e5bacb7052388d0fe32b2ce3e0fc3b |
| MD5 hash: | df93e537cd7ba3dbc8fefe3e5aff9e0a |
| humanhash: | oven-cup-hot-diet |
| File name: | NEW ORDER 98540-0.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 700'416 bytes |
| First seen: | 2024-03-14 13:09:17 UTC |
| Last seen: | 2024-07-25 01:39:21 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 12288:0KM9hCaVbvqZsX5HAT1dTrFATopt+O58/4g1E7nKG7eF:6UbZKgThpHS/4UEV7 |
| Threatray | 5'040 similar samples on MalwareBazaar |
| TLSH | T136E42344BBAB0E83C83D52F95812648853F29662EA72D7CC3EC965D656CDFC9D7802C3 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | 2000206060200020 (4 x AgentTesla, 1 x Formbook) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
664db26a69e4b1efb10289189887c35558bf7ca966eed02f97e523fef83f1205
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
81ace4c307c53dcb5aa5e1d7a971d373a734c747408be3a9158bb00b5b11f8a2
d5af1b5ed5eeca90dc835ed26ffc8a8854890eeefa32aacaa094b5d606d4edda
5cab510258dae33c18cd23924daefd7501ff7203ba9816704a2b0ca66508c56f
0aebca1aecba63aa6205a90f467e4c6ffb86efd928bdd7e3d7ba453eca8ffc00
af69e50524ba63cfcbaaa2de4d15434743f2f34239ad34228e4eadde55bbeae6
fc8a9c0e62e7e7df74d0d59bed35d720aca7a47021f8c55bc1bcc32fb3075a94
6a7c6a729d852d01d74832748b6571bafaefcd0bd12aced32e4fa88166af8817
9ca2b5622a36e207a1d11a748f637920d4f96d88e34b2dede0840bcce07f5788
4b39adbf8d3a4e2a5793014b4af4a4cb98d3a71c4a565dd20dc3a69928a84c72
037c7011889e43ee7456a314fbfebcc3d7abbd96aa509a34babc0d832681013f
664db26a69e4b1efb10289189887c35558bf7ca966eed02f97e523fef83f1205
fcac462e70c7009c1c8dbc15dffea8e0b8ff141fc94a95581c306d995a2748d2
2b3114ee08fb8a720819c749b1cbd68f5c8119073f34db958849b1d3eb1bdd9d
bdd4ba2aedeeebd368997ceb0a5c0372959181a08f1e5aefb4b437609630bdff
f4cefaa54034c3cfd9bf223520e2a5876ec1d161cb4a68b6b7d3e9fe892b087f
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
f79941668c6679c1f5770816ce7b68a2d518caa7d7218299f7a1908cf338297a
88737e32661e323c947753fd7c8ca1abd141e7c917dc12730a5d6634be6847fc
ea8e979a9bf6fe2e8af35cedb5d639091629a2ce626f1339c7a0a48e3cc39ba2
8ecf19dca7047302513a5818cb79bcd6c4b278f92904ed1fcc7f559c72e0de7a
e9ea79b9129140cbc495137ea1c09c0686d5a5d33c43cfd1217ee2aead41237d
312783562439afa6feb4e46153051e5af5e7c15f139bac75a25afd38caaed1ce
1875aee9f50a8e2389a125c2f77998685ee0d7d7d20b7d3f1ecadf841564e654
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
55571fa3b9f2d9a7d71c1154aac73dc3826860eaa7be12cceda40d4566ea4ce1
242ea95cfe48aaa9fca35f358ac8431cd1bd730b1ff95543a4f9d9e768115d3f
d5a0f85ffb3ee297f57ffb96a77288de2a564c5cb337b5c6c7b01da8e36545d6
285dbc8362784007c8e0a4060f48bea0818563129e5c824d34393f2c714c1a9e
ffb10236e7f77499f767e9e703c9e0a6d0b3777ff6ae06e63724f23fc7e3ea29
610224addb5b75398e556cf9780a9ad26891fa1754cbda12637903560d15dba4
959d491cbde6323dc2bf7c377a9c1e0940b988f51a3efcc0f1bd526cc0d210b4
5ca87353c4d37e66f76875a46235208796dd620ad3cb7cebc6b5e66be55b2913
d5df0f56b1209034e89de624a5ad652d070035c15f24d6b3559c34540c725b9c
590f27260d772e044dd8819c937658e02ab15050b3bf6cc3dd054c808ed3c201
89e60f82a944bb55032e88f1dff4d13242129b0bf2a3ae39aeb93904a665d4f4
8d4a83437f552b1737a406be9d9b5e4f4919a1adbf8e13f8261411d7390d604f
201cffe8bf2c15a804167c67d2a095ff655829395cb54b5c3d3c4d038efde920
224ff64e59a1b2bf45b02cb11df4f0556de0bbeb7929d37828de1c1bb8ff8772
ab5501455d6b22f8e26dd31ed265879ca6c0d3c6677793738f49360628792991
5f7a3e9cfebdb626e00af8155e710df40bab01bc5b8fcf77163cda86d23cae3d
86ea784bb86a20eff340835a0cf862d6a4a5b2309ead2c00006b65c2d8f5ebd1
0c18d82d30c57f4eb7b9ce8f7bb367b114718b077b7fd7bd838f57399c5921d0
ee591c0b19049eff4e311686e26557c5da6818438c319ed6f0df6274a56c5e05
48b161190679dd4c509ab89a5dfdfac0bdf6b557c0d77d9e4f698acf057acef8
a1a5145381a87900950867d3e6632aaf89fdedb9c898bf44fd7efbea077ab224
800fc3595eab3d807dd8199ba639d1bc6c0bdf5f1f47cf3a95c649b61056bc1c
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
f2338f728798c729c37b627d5d75bf8691a482a4b9cc4b67ae5a5ba4b45b0c85
3d648905c51d97e4998f5e24312dae37f77dbe94279847f6a124894790881082
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTeslaV3 |
|---|---|
| Author: | ditekshen |
| Description: | AgentTeslaV3 infostealer payload |
| Rule name: | INDICATOR_EXE_Packed_GEN01 |
|---|---|
| Author: | ditekSHen |
| Description: | Detect packed .NET executables. Mostly AgentTeslaV4. |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many file transfer clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing Windows vault credential objects. Observed in infostealers |
| Rule name: | malware_Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Windows_Generic_Threat_9f4a80b2 |
|---|---|
| Author: | Elastic Security |
| Rule name: | Windows_Trojan_AgentTesla_ebf431a8 |
|---|---|
| Author: | Elastic Security |
| Reference: | https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.