MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 87455c255848e08c1e95370d6744c196a9d6ba793353312d929e43a4e2c006ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 9
| SHA256 hash: | 87455c255848e08c1e95370d6744c196a9d6ba793353312d929e43a4e2c006ea |
|---|---|
| SHA3-384 hash: | f5eebab39b5cbb511b10cf7a57d0a1db8c2d1451604997c056fd8077f8086b1c9fcd828ba2f7e84ec4926332167b139e |
| SHA1 hash: | d021b46c74e131124a7b4c3b6b004ff8e38d5395 |
| MD5 hash: | e51789e6769e567dfe2ed2cc98b9f4d7 |
| humanhash: | sink-sierra-saturn-charlie |
| File name: | Prefer Quotation.pdf |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 184'824 bytes |
| First seen: | 2024-04-17 07:56:51 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/pdf |
| ssdeep | 3072:7vRtf4KV41iOBoekcHFXJnHbtuzj7yNp40UFI/z/92+xNhNr5+m8hH4:7vAhk6gKnHbQzj7Umxczg+Jp5+mWH4 |
| TLSH | T164041279E87FE48AD8464C7BDD6A359F4B29B10283FA19B2B0754F5A9004E71F272370 |
| Reporter | |
| Tags: | AgentTesla pdf sansisc |
Intelligence
File Origin
# of uploads :
1
# of downloads :
552
Origin country :
USVendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
PDF File
Verdict:
Malicious
Threat level:
10/10
Confidence:
100%
Tags:
phishing
Verdict:
Malicious
Labled as:
Trojan.Generic
Label:
Benign
Suspicious Score:
2.8/10
Score Malicious:
28%
Score Benign:
72%
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Clickable URLs found in PDF pointing to potentially malicious files
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to log keystrokes (.Net Source)
Downloads suspicious files via Chrome
Drops executable to a common third party application directory
Found malware configuration
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the Telegram API (likely for C&C communication)
Writes to foreign memory regions
Yara detected AgentTesla
Yara detected Telegram RAT
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2024-04-12 16:36:11 UTC
File Type:
Document
Extracted files:
14
AV detection:
8 of 38 (21.05%)
Threat level:
2/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.