🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7d3d83bb98ff3eb9f9bf8afecf4b55ab9d8e606f9c19b99d6141c224ab658315. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 14


Intelligence 14 IOCs YARA File information Comments

SHA256 hash: 7d3d83bb98ff3eb9f9bf8afecf4b55ab9d8e606f9c19b99d6141c224ab658315
SHA3-384 hash: d850b6d129430a29b476553b6bd2f55a94cb00dbf9488b4c67704dda1eb679857958d5322bf6da7e922994bc9d48fcab
SHA1 hash: 7d2daa32879fa9d8c617af43b03215496ead6b35
MD5 hash: f70d530338a208cdcb5ebf9ce09dfd97
humanhash: neptune-fix-rugby-north
File name:f70d530338a208cdcb5ebf9ce09dfd97.bat
Download: download sample
Signature AgentTesla
File size:7'936 bytes
First seen:2026-05-16 22:33:58 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 96:IuCf9IQa8LhLbsMwoOAbqsYAQzayCbYUEH5KVq2ayCBcP5E:KSB8VkfhsYFavQ5Ko2a+P5E
Threatray 3'686 similar samples on MalwareBazaar
TLSH T15EF128254B8E36BBBC473C86B15E4514DE45503E17DAE4B6A00C2D2B1FD2DDF9F22095
Magika batch
Reporter BastianHein
Tags:AgentTesla bat

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Malware family:
agenttesla
ID:
1
File name:
_7d3d83bb98ff3eb9f9bf8afecf4b55ab9d8e606f9c19b99d6141c224ab658315.txt
Verdict:
Malicious activity
Analysis date:
2026-05-16 22:35:42 UTC
Tags:
loader auto-startup autoit stealer evasion ultravnc rmm-tool agenttesla amsi-bypass

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
91.7%
Tags:
obfuscated shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
crypto obfuscated powershell
Verdict:
Malicious
Labled as:
PowerShell/TrojanDownloader.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-16T19:39:00Z UTC
Last seen:
2026-05-17T18:22:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.BAT.Generic HEUR:HackTool.Multi.AmsiETWPatch.gen Backdoor.MSIL.Cardinal.sb Trojan.PowerShell.Cobalt.sb HEUR:Trojan.Script.Obfus.gen
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-05-16 22:34:58 UTC
File Type:
Text (Batch)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments