MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 18


Intelligence 18 IOCs YARA 15 File information Comments

SHA256 hash: 7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
SHA3-384 hash: eb2e70265df94b568612ed88cf673a309dd973ddd9a5acfcdc5366f5a2c92e59cc461d6393b05d8012262c858a0fad33
SHA1 hash: 7a04c2ba75e5bacb7052388d0fe32b2ce3e0fc3b
MD5 hash: df93e537cd7ba3dbc8fefe3e5aff9e0a
humanhash: oven-cup-hot-diet
File name:NEW ORDER 98540-0.exe
Download: download sample
Signature AgentTesla
File size:700'416 bytes
First seen:2024-03-14 13:09:17 UTC
Last seen:2024-07-25 01:39:21 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger)
ssdeep 12288:0KM9hCaVbvqZsX5HAT1dTrFATopt+O58/4g1E7nKG7eF:6UbZKgThpHS/4UEV7
Threatray 5'040 similar samples on MalwareBazaar
TLSH T136E42344BBAB0E83C83D52F95812648853F29662EA72D7CC3EC965D656CDFC9D7802C3
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
File icon (PE):PE icon
dhash icon 2000206060200020 (4 x AgentTesla, 1 x Formbook)
Reporter James_inthe_box
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
365
Origin country :
US US
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea.exe
Verdict:
Malicious activity
Analysis date:
2024-03-14 13:10:38 UTC
Tags:
stealer agenttesla

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Reading critical registry keys
DNS request
Connection attempt
Sending a custom TCP request
Launching a process
Moving a file to the Program Files subdirectory
Replacing files
Stealing user critical data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Contains functionality to log keystrokes (.Net Source)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected Generic Downloader
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2024-03-14 08:12:38 UTC
File Type:
PE (.Net Exe)
Extracted files:
24
AV detection:
23 of 37 (62.16%)
Threat level:
  2/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Unpacked files
SH256 hash:
8eef06f4bda5c86191586e37123425d1034d77337f30404c08aafc7afa7f8f8c
MD5 hash:
3bb17ba6c449b72aaae84293d7a7bd5e
SHA1 hash:
d4547a03a93155189aad5c9552f361a4d45db704
Detections:
AgentTesla win_agent_tesla_g2 INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients Agenttesla_type2 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_EXE_Packed_GEN01 INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
SH256 hash:
c10c9b0882bac6f788f48b4dabe3291b14e639e650f2b9fcb0bc174ac92ae02b
MD5 hash:
7c7fb6daa78beb69128991ff893143ed
SHA1 hash:
c01bb99984b12b84129db80eae1d5d8341a358e2
SH256 hash:
024d1b2c5ed6c8efcd1a4c1647c65c5b54d811a016ee4783fbf6512f45cbdce0
MD5 hash:
a96f220f4835ee76b378792f89de7f02
SHA1 hash:
6771ce7ec38ce8f39e5b98181d6e7f39be71be51
SH256 hash:
e6b25e7250cdd5f75ec51545b9105bdf202d880898ec9c4cd75c131d9262e1d0
MD5 hash:
0c01ecddd3880a71ee7b626706813efb
SHA1 hash:
37eecee4ca36bb984095155b6a3a2e640f452e0d
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d
5cab510258dae33c18cd23924daefd7501ff7203ba9816704a2b0ca66508c56f
0aebca1aecba63aa6205a90f467e4c6ffb86efd928bdd7e3d7ba453eca8ffc00
af69e50524ba63cfcbaaa2de4d15434743f2f34239ad34228e4eadde55bbeae6
fc8a9c0e62e7e7df74d0d59bed35d720aca7a47021f8c55bc1bcc32fb3075a94
6a7c6a729d852d01d74832748b6571bafaefcd0bd12aced32e4fa88166af8817
9ca2b5622a36e207a1d11a748f637920d4f96d88e34b2dede0840bcce07f5788
4b39adbf8d3a4e2a5793014b4af4a4cb98d3a71c4a565dd20dc3a69928a84c72
037c7011889e43ee7456a314fbfebcc3d7abbd96aa509a34babc0d832681013f
664db26a69e4b1efb10289189887c35558bf7ca966eed02f97e523fef83f1205
fcac462e70c7009c1c8dbc15dffea8e0b8ff141fc94a95581c306d995a2748d2
2b3114ee08fb8a720819c749b1cbd68f5c8119073f34db958849b1d3eb1bdd9d
bdd4ba2aedeeebd368997ceb0a5c0372959181a08f1e5aefb4b437609630bdff
f4cefaa54034c3cfd9bf223520e2a5876ec1d161cb4a68b6b7d3e9fe892b087f
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
f79941668c6679c1f5770816ce7b68a2d518caa7d7218299f7a1908cf338297a
88737e32661e323c947753fd7c8ca1abd141e7c917dc12730a5d6634be6847fc
ea8e979a9bf6fe2e8af35cedb5d639091629a2ce626f1339c7a0a48e3cc39ba2
8ecf19dca7047302513a5818cb79bcd6c4b278f92904ed1fcc7f559c72e0de7a
e9ea79b9129140cbc495137ea1c09c0686d5a5d33c43cfd1217ee2aead41237d
312783562439afa6feb4e46153051e5af5e7c15f139bac75a25afd38caaed1ce
1875aee9f50a8e2389a125c2f77998685ee0d7d7d20b7d3f1ecadf841564e654
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
55571fa3b9f2d9a7d71c1154aac73dc3826860eaa7be12cceda40d4566ea4ce1
242ea95cfe48aaa9fca35f358ac8431cd1bd730b1ff95543a4f9d9e768115d3f
d5a0f85ffb3ee297f57ffb96a77288de2a564c5cb337b5c6c7b01da8e36545d6
285dbc8362784007c8e0a4060f48bea0818563129e5c824d34393f2c714c1a9e
ffb10236e7f77499f767e9e703c9e0a6d0b3777ff6ae06e63724f23fc7e3ea29
610224addb5b75398e556cf9780a9ad26891fa1754cbda12637903560d15dba4
959d491cbde6323dc2bf7c377a9c1e0940b988f51a3efcc0f1bd526cc0d210b4
5ca87353c4d37e66f76875a46235208796dd620ad3cb7cebc6b5e66be55b2913
d5df0f56b1209034e89de624a5ad652d070035c15f24d6b3559c34540c725b9c
590f27260d772e044dd8819c937658e02ab15050b3bf6cc3dd054c808ed3c201
89e60f82a944bb55032e88f1dff4d13242129b0bf2a3ae39aeb93904a665d4f4
8d4a83437f552b1737a406be9d9b5e4f4919a1adbf8e13f8261411d7390d604f
201cffe8bf2c15a804167c67d2a095ff655829395cb54b5c3d3c4d038efde920
224ff64e59a1b2bf45b02cb11df4f0556de0bbeb7929d37828de1c1bb8ff8772
ab5501455d6b22f8e26dd31ed265879ca6c0d3c6677793738f49360628792991
5f7a3e9cfebdb626e00af8155e710df40bab01bc5b8fcf77163cda86d23cae3d
86ea784bb86a20eff340835a0cf862d6a4a5b2309ead2c00006b65c2d8f5ebd1
0c18d82d30c57f4eb7b9ce8f7bb367b114718b077b7fd7bd838f57399c5921d0
ee591c0b19049eff4e311686e26557c5da6818438c319ed6f0df6274a56c5e05
48b161190679dd4c509ab89a5dfdfac0bdf6b557c0d77d9e4f698acf057acef8
a1a5145381a87900950867d3e6632aaf89fdedb9c898bf44fd7efbea077ab224
800fc3595eab3d807dd8199ba639d1bc6c0bdf5f1f47cf3a95c649b61056bc1c
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
f2338f728798c729c37b627d5d75bf8691a482a4b9cc4b67ae5a5ba4b45b0c85
3d648905c51d97e4998f5e24312dae37f77dbe94279847f6a124894790881082
SH256 hash:
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
MD5 hash:
df93e537cd7ba3dbc8fefe3e5aff9e0a
SHA1 hash:
7a04c2ba75e5bacb7052388d0fe32b2ce3e0fc3b
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTeslaV3
Author:ditekshen
Description:AgentTeslaV3 infostealer payload
Rule name:INDICATOR_EXE_Packed_GEN01
Author:ditekSHen
Description:Detect packed .NET executables. Mostly AgentTeslaV4.
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients
Author:ditekSHen
Description:Detects executables referencing many file transfer clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID
Author:ditekSHen
Description:Detects executables referencing Windows vault credential objects. Observed in infostealers
Rule name:malware_Agenttesla_type2
Author:JPCERT/CC Incident Response Group
Description:detect Agenttesla in memory
Reference:internal research
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Windows_Generic_Threat_9f4a80b2
Author:Elastic Security
Rule name:Windows_Trojan_AgentTesla_ebf431a8
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments