MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 16
| SHA256 hash: | 89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b |
|---|---|
| SHA3-384 hash: | 4d1a51b8325bff8a0c46444edb235ab5dce364a46c07095237edef071af2dafad696d4593de511ad7afdf0bcf7738edb |
| SHA1 hash: | 185520ceb31c021b5d48440b31b09e7dfe6dac22 |
| MD5 hash: | d744962b80b75ddd26a4f39a8e8d4356 |
| humanhash: | ack-charlie-hawaii-alpha |
| File name: | RH-098765000.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 762'880 bytes |
| First seen: | 2025-01-24 07:46:59 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'451 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 12288:4hQu7+JZLQ81xkRbunBjtRbnRIA0FL99PvOPivjJj4OD218zVTAzwndztS:d/JZ37yyBpRbn7i9P2Pivjt4KU8VCq5 |
| Threatray | 346 similar samples on MalwareBazaar |
| TLSH | T126F4CFD03F327319DEA86934D259DDB592B51A78B044BAF66ADD3B5732CC211AE0CF02 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | 00d8f872b2b2b000 (17 x Formbook, 2 x MassLogger, 1 x SnakeKeylogger) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
10c2aed16bd496bca57f3cc817ad510cc0201ac1657fd75dde1377ca038a9adf
18bbef8347972904228a700b1ed16a560400d283f27b615730414f958e67045c
a025ca2161bf1125aa31aa65ba154f261f7dae204f7abfaf5ecf392eab8e9fc2
627830b9debfa8a0a8a9cfbb89c90c0b2bd236ebc50f42564a0c91ce4edb3943
b772162c5b510c5427be045abfdc43c29756217e2ed924ce4c4388bd457a4987
115a0abcf8bfe4d0320ecc08c9f0668f35dd796b7a74c6dfeb9d6fc7dc16d214
059bcb12cc9e2bda28d0459a49958fe9efd7e13809b4b19a4d70c5a71bb41522
8024f9bb6c58be103e60c07bf09d3648b61bce12dbfb6277b18a85fd8a45bc4e
8d15bcc5eca4dbafc31d1ea92c4d34b86e5d30e6b4cb0da378570bdccd7242c1
6a31f54219ee0ddbfcb2aa841f922d48a849b1b047b8693ff8c2faad2ab8fac4
979e6920fc27cda0cb462b26f221a6e521e3974ae737022db7215747f54ff349
3a32996e922e69d2a01101f0fe601687d8d98f6392cb72cb984ad86b03f8236d
f87529bd57f54630ff4e0a8391d2e02bd04df4b83ec7c2b879dc258f81103978
d48ee1f6f04504d641c8769aeef83185c8de8745458a3fbc362cd53c20ef10d9
ca690123d14bd3632ab53a076f8bfb7bd2176248af6b735af9719aca77a024b5
86e6c344630b2458ef31796359d7c14538e95982c87c803d1ffd328f2ac2bab6
474651d4f8f510094648423d6a0d97b51d2847db856251740877331e101dd372
46a2479daf646efcab8cc6fbf8037d37703dabfc6aee279465e22b9a433c8c08
363da150d891da7bb5da8056414882429067a0fcb27f58363567567bf18a323e
d2d196a12c822020c4042d607be77746951b6cb3c16201ff21ca8e9c5c786209
dea077180d1a981a1a9bd8f901bc177236825f173e5e2394161811797933fdc2
91fee98b5957d145f144b61107ea0283fc3e02eb7e19b432e868ee45ffdc528e
35931dde3f9e60ae4cbf22e5348bc4afca8d6145137a27a25216edba8b66f68e
0502e71249410dba419218374909428d7d53cca90c3cfe8861b7f8eae432a4b9
1e6a8f176a0d7a9bd0321b4c032153f48b244be1584137453bf1afc07ea10157
80cae17ac36cdddcdd35027d72f10d019d82e256fe88e0113c66432137f354fc
97a8bf73809611ee4048adc2714685bd29bba3e677f5589b1053e30e0d98cf53
18b7930562b9f73f383204f2a09e2a76ab3d772a0d3813ea42bbff257430b5ad
811c8854ea3adcd1259c28cf1dc60e0a0a2f7a44f463e98f77c277a2a2f6394b
382b40ce3e7d7fc44a80d1b9190914a401c968be78c7115a8e4e3ccd40b8888d
996a678b9f2d2434c6da9452449c3f21aac4b5e15ba7ae8c0a5ecd429d287e35
89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b
ac0c869888d9501a709cb33762d8062ecf7139116a4c0dbe07171f2c5a77b96c
142d4fe66ef8acb376f52ae33ec869d8782a4e63f9c92a6a20011dc9cd8f215f
5fc13e8395c7c4714caacc49471c400b47d85b490c329699060acaae6bd24eab
35c894c4142cf4d35b922afcee66e1c1d1feb7803ff904371c3efc38d6d2373b
41bffb035560aeeb3d2f29aa841e7e720a5eee2aadb4717f5b874b54d07375f6
c101e6bf92c9106ff2c1f2b729c6f8876296570a2c34579755e0ed4b6527ef69
6833c243605f2cbce11cb5bf26359c068588b9b1ac0e564bee019dd45a972b53
d6a552186e5681c84a98bb28235bb1a863a0877585e984b15f38e7dfd0619225
4206293a4d4e9b93abdc77721e4c1ba151656f25c21fda7677066e0e772471b8
2bfc56f2d75628c46bc823eabb6965763268b879a249993d42794624221cae0f
499e49eaa56930307412bfe977a827c0d9ab0c361b319f912e78a13b03154af1
86ccb2e2b2b1780ec85596c64030ce2525145afa00f9e3db1c3582c4f4afe7e6
8dc5ce1b016bdaebc7d77a20cccf815a49840e239c33132d35504d03c5f6ac99
1cb4254b1a62245b30f20ccffbefb79c36b1ef324c6d401cfb6d48ddb00ce6a0
1d6d55330b2acdf2edd8d1bf9f2f134ebe700dff202939f1c1b31ad5aef41118
10364e0c6aee6b43975fd53d6289dd7e6e0f7891d4a5636cb938f68e00717d85
c0b99a4d83d20539cbcb64a75cf4195277d63ef20113a3d3d5a1affe9db263e3
f0e65a838c01e4741493c605aab2232854d22a14d913374a2c61f083b35d7aa7
98a11f5e0943f5a8e0475b4c7d87b5f67a1d39f7c44e564d86df4ebd687686f8
a7a1f53264ca6adf45c493ccf8db7da322b51c094a305ffff264db5df146edcd
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
496183edd167fc6543a66bfc47c6a486eacf7fcafa9149d6d78c590e6d6b3be2
cff8bf19e834f403b7914c1fae20c0089b2a75a29a769c1e46aa3bb234171d1b
19ccabe99d3c6dd06c2c9f3659a7f196afcdaf84af869e573cf3545df80b997c
84c1d9c18d8e90a6e7531688800c148405426d2dba70e7218c9ee34fcf076e9a
06d1d5e5a8e641a62df3b3282dc437d24d48a31cc60f691c760023429788ec6c
0ecddd957a515d3d3ddc583b3f451d56f56273cfc844c13a8cb0b78d10b3c52b
6601f8f872a1514a98b8166c3ba55d63db44d5e9310d00f91ccf770e24742feb
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
5dbde839c07b34a42667935da05d18dbf85e630126ee3c649383a44aaa9b6602
3b1b0c6e463108f7a2f9d683fd69ebb175b10e5662b27cc7e8511fca4157f407
eeaf38c14ff27a1c50d173c3ce5c5803517d8015cf1e6d777c0eaad1eead4af1
6208e1d4a0b694b7d2a70d312f8472b2c2acd0edacbd5a2344199672d7dd84af
c53b13442d16e522db35af6431d5a3d9599206db9975245b9ca90c43d4c4645b
f42de693aaae005ec4dcf3514621f8573b422f3a3ad1bb1af370acc7c5cba233
28a65019d2736dd82fdb229c9e6f5ff053c25e095d118ae03359238f44ba22d7
fcbbc6c9a426352d6a329d9a0a055cee18d66ee62835e3d00499e4ca52761c1c
7c3a286e6c2a9e2b50a81e67dd03ba27e6dc6fa7bc87f45d0e51056252823cc1
8ed16a383adea236fea0ef757127aa5449e223ef29617e0b584286183143234c
4e591799b96dc33af9dba4b19fcb173c9c79da52b645ef063e0f6734b999a91e
d80246672d337713cd5dbae257d6cd81acdbb3b4328141a1bec0a735b9618d71
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
4ef83ac7a3bdee1a742de8de749c5afa4747acc20f8937301dcba291d1ef83d7
2f71acafcf825697cf29e5f93681f9c7128d49fee3e04a20dd506042102734a4
13fd36bd0ad2ef303ded0dac6b7cd6d4326ffebb08ff914eb44a6e75c52e8289
282a05d5e79cd8a8fecb470cdde28f483cc6fa7d70785f6e6e5e3de3dc39a979
89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b
a1333650518e3e435421e28233c84f8a5a1ca03607c5289a01da3f86e4046565
771077ce6d2c6eab4908e19af87680fba3491ce6aa9cf976d82afae3a7cdfa10
17c4031831d4166a50a72b65ebdb2a4825645a3314ba5907f46329b9da9b2a06
55864751fb6be8d2789f4e3789bd2794a9e7cbcf39d472f6a4da1d4ca2f50758
12bd2e88e60fb4e93881164b51c270121034f7ed01bef4ae0741abd8e532d77c
1efe29ca00c9e7c69c46dc8139204716a36b6074647f3ec4fb06e2ac6576d496
4fa5ea6373a2464ae2a7f499d1e19cd27f6506df81bcbde80567b79d7e211520
dcb2bc8fe4ca10f50062e50786e71539aa41240448d652876c96ce970be79162
001abbf49585db1553929901f5cfc1465e504fea17f6ffe78a344892aece146c
0873358f1252f19f17bf03e959386d2c39ceb8b90b7a73d0de11456082c2730e
0c2b52146f60798b2d069e7c660be0a95a9d7a970d75ac489a1dea7e97e441d2
f8259be27bc5c5ab89b1f8101535489f28799ae8c1251fb00aa9ec1d6389343a
e48808b99478ddce1a031afa8094dfc6d4d5002bd012e278e741b5b59794044e
976d5e9ce2356934688e015c90497c08d5334715c5d2235d5d13af314565d3d0
8f41896e69d1f83408cf68e4d6fc56849a6ee6b86145e7cc68d6caed660ac582
a14ecc9756de5e5e89e2f12839750c554f9d6b2e45773475d096d6db1fd92c04
061bc2648b58846a4dc7cc468cbf1b4bcd2be744502ea0775b705b04ef536dfe
60ebf1dc0d303257b79432e0713134f71fc044aa38f2dc85e55d20442c01add3
ee55e7f496b05d9bf98cc381e621483f549f9452d94d6ce32d4f3b59c67bec57
609bc44c18519741abb62259b700403e05cc0fd57b972ef68ca6ae8194d27f2a
4bd0336e60490dc8ede45e9ac7aeacad032fb72e1c4401552a9d4d7d52c09054
34444d4292fb1f61fad6019625d22b9b88868e8af67aa0a84f1319ce8d571f01
a9173bd9c5fcd609d03021f9e23634542691b79a791c4855fbfa248a940eda14
ca4c4cc60005ca88e582734f5f0232099184cbce1effc270fa761367b9029bd0
45aa9c752530b71775bbc59a49604fe2f8f10a3c98be4e3d789d307eebf69b9a
447174dadd9697274ba6e102647bc6847d816b63d91bd0f35d29c5c3a3401ef8
dbf83094e42dc231fe1a1b00f3fe1e4cbfaed8757afdb3d5a166e91d3b3733ea
b3d2c06489759b1433bcf9aa38c9ba9dfb400bbc4ff1deedd960f3c3dd606518
b7ffe514c90485438c522430e88937fa81bc965e74161025eb18f8c1a85275d3
490c785be9863eb038433c2a125ec62809a8bbb25f4ddba21f72772e034f577f
6c2cf6bf017b8e9c8731b0b0bc1ddfd20c14e381d5282832d5646ac29158cf73
c2aa6c735713c7b8141a6f98467fd4a41e72c536dc2d92c591e47b06ba2666b3
079e89bd883be60d3ff2dd26ecf457b181003d8317366f87995663dec23c7252
56a1a9b139520b6c51ac67413d6bd6db87771d1af9d6994290815ad99dd89102
c38b465d0723cfba8e741705451d5b4917f09640664adf5bda6c0e48026c6b3f
467d77d35a6fc815ecbd60b0b320d7ca06e0f8a340c2c3285de4c0430517f8e7
4336ddb80f3875340305306f98bd57efcb38a2182153d71308957167a295c070
d0d2ac5af6ecfdf27de6c45ab86d521294350c5a64942cd15bb5d9a1ae23b0f1
b30e339a7ecbbf9ea338c915cf1e3f8e6b6740b314ef1d08e38b1694e3446163
737981c73007c1fd4dc3cf2d9a5c79cb004fe48bdf3cba06b4ead50b3a57af13
389d68ade0d98fb86548dc560ee291397729e0474a0fcfd3299c9d534e6f1234
205e98d299b32e102e3d6fadb9659f713601f8f713be02cec1ec0f437d3be075
b8a1cbfde7cd26809f6a8a90d88d09c0558fb2417dca15d7edd5e3eac3e07073
6cdcf78d540c146fb0319b5539d1bf930c2e59c42ea8953066c648a0b65ae460
a91cf2a4699e93a3101762f542bf47b51d8ac09f8e78eaa2222c36807e0c0e72
565dd0687c5447e3714250520bc29577e6516b8bc597067ca0dff05274896b4e
b35f831b82f4648f91b37d8b8799cb26d30b069a52cf12e14ba9b4c06e8fb571
9a71da6c174ed01e2bb5fddd7bc7d2ff7e6a988b8deecd05c6935373192573ab
8b25b0ed0e18bb24684d10bb3afccf6e6290c95e89a79733914117e2c7b46b09
6a19ede919d3ef32c74ddbcefb4bfd3ef61ba2a86739978ed337639193678edb
0cac75f1f61f9fcca09695de695e469d62f7e73147ba678f7d6dcb4eea80389c
75db64719f3225f1e42a86bb7cca56871f757076f81c42802e22a83629ac4fbb
a50041a2a0cccb573e80cb188f35785613ac38230cd4d0031f738855446cabbc
c2d06459896ee441feef919813800bc4f9c382ac08e28103bea73b675e556ab3
27e9c5e774bf0946e99a7f34d14ded33ca1c236765fbcfda83e234d70d15c652
5b2a4d07425414d3e00bfe400df7cf20526f32e9b29f4b7eefb07ddc38720a15
a883ec7d3df1913ccd847c0ab5d521170adb967cb09cd5b3845e04b50aa4240c
b8dbf3db5d56d847b13c3e517dd9e9e396038948ea1189e7f57c419f493c368c
36c3f143edb273d0d6cd6738e0357ddc19b86857de46871ba96bcb1a8256b1ac
35bba0cdd40a31e401d3e668676f3e6b5c51ea9bd4850e46a6fb0b391862838a
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
774b328fd5904bd0a7d3954bf9321948b43dcc3091db995c27fe47e360d2b7aa
16a43aa836bfc334a9c67a4a6cbd25aa461b9332b7dbc5271afd75119c2a3521
42a78ab84a5fc43e1b379a2968a32f272492c860f0602649d25374d521b4b83c
a689d2c7fa2cc3712ff115a0dce0cd90c5d55c92bc87e7f24dcd05ad4a38db63
6f706398207b1fd3a00de5f859dc840cf8e100175fdabe260ebb96db5980f03c
10a5c29d6a44de5b996598f71820bff8c29cc6b5229d2c7ec0664b601d81068d
640cd2bb3f4726760684d6e3a5e56e28e37860c7d377fd18e1f428d31b47a468
4c9850cad6a1efce3f23362ff3f68fe5fee556e3e344e867f16ac821701e90ad
629e839dca37071336e2ffd8bd9250443eea5a18cc317a0edc85a3d4aa59cba9
6c8c1ce5b36a379f6fd545629aa03270575b179e4194c31f6db163bf06de6cc6
000131c03f015a78307daa5d0d21c2fc6b286f54a51b5ad14b237433e77b3ea6
ef9f3bb8a6695a4ac654b7218954695432faf87784d5c78f8d237a4532a466cb
fa3e852fa9dde2dde0c1e2254f81059f8c2f1088596e0fb9aa2e37583c26ead5
42bf798312044d50fdcd35dca04eaa7bf628fd71e876fa6fa33b95e593d7526a
94fbf90615b1baf84da26854c9c7b72115eaa12eb8392d898c7689f433980120
8b0f47fb5a7f509e14dcbc3eb94ed4d09602236123147012ef174701470ccdd3
10b78bea9f7acc71be5868fb39e4941c06ec08c4b0ea25b0957ec6b63fe37e20
1e1cda620f33f8a4e039351b55ea841fb09e0212ca2dd44cbbcd52fc88ef8f61
a8c8535f49c3869518e9d62f95086e5ac36526ea61d4203aa8d2077d33ae9faa
31c25e01cbaaeadccfa1321680bbfd51c17b876859be87fff22b2db8ee1e117c
e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b
6dab8b138cc6efc4956d434d6992307f17faadc887bb3829e950daf8bfd5f46d
14ce31b551f4f39bca04ece6143ac80a3943a957d9a6056c88b6857daf60b784
683e3979cc09db086095cbe840901b82951df941ed461f89a67b98bd0ffe5ff9
342a6c5178eacedd99cd66da3bd81e767d0aa311441ad2089b087def3f5cb088
36b2c227683d3aea101fb59edb33edb1ba28ec0753a32a5ce42b1959d6716965
88b2b7e8b37a44b6b3ed65362a01936ff5500ae073ccde2c6a5c51b0afc05d94
3600d33c7e14a371b391e1e949a16454a26014007dca981bdcd177dbd234f797
1e90ed469f2242b4882864a20ab1357789b1851f14074cc97a263ddae613a53d
b58a7d4bb391ebe2243a86ea92641445e98a4da3e51abf3d2c905fb8ac0dd9dd
19c81289b55d23365b8c4f7c6f951063b3aa05c10a4d8025dedd0893903fcb59
c95f3abb8db4e2a88ca3d533b42608b4d466d70e1e92fab9d234e6afb6ffe011
7fc8b3746ac1a4ce5a1b211f56034656c4017aef413aee72b0884ad5f0a94054
676528e924dfe6e5e119f33ac5e7e8ee5661f871759e4b32ac27b0a1d243e329
60bfb47f60c7f0a6aa8185734c85849995f497117e38ba2c2e9fdeb1330b0cf1
12cb84b318ee85c5d7b4ec15d5f6fb2c26a43f93c68e98c6f40c2e2b17bcdf65
5dc75fc4ff5d018e6f56ed3f2676781e2ae1a341a878ee5ef36513376b75a310
0d6a9673eb3db83be393b8e85fceb372b5fbad79ce1c56bd92ea4b6b3166f657
cf8609a0bf3ca9ed3e5e39abab534229213e4df0316cd0478032cf59e0f2f3dd
0531f60ef00a3998d4932da7000a10630fae4b355cb81db091008f3899e039a8
0b9d81ffc7bd0ddeed01b5a0adc279cd4a79003ce9253fc7e096fcdc63ec371c
004de56c87ec09f1022747d6713c26328397dec1a683f76aa178a48da776c82c
543a5190118c546db54b03846c3927a4cefc69809b5854fdd0fecf1763dfed2f
ee6be21c96c562717375ac6d428d00777826ddd74a59b8a1559eb353950f5d93
5c7dfeaaab049b0c4a2b6fe06c7d6d8d54202ab9b5ba637b73faa01bccb5debc
0f5ddd1e5c66b90c7a37c276228ef498be1297d5cf3823afd72b0ad08b08987a
e0f397c466a112a3c04c99cdd5a1fbacd2131a90d520d5245f5d0a2336e53233
8032eec5f8978a6eb901f96583472cc3bef407b41a3357ec253b8204305b69b2
b9581e9af28f052e463acd6117271db974830bba5a7ba5825068596947e872bd
0fdc25f5430a61cd969c0bcb2e5ed6965d4eb4dc73374649eeaf5a6b77498d6d
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTeslaV2 |
|---|---|
| Author: | ditekshen |
| Description: | AgenetTesla Type 2 Keylogger payload |
| Rule name: | AgentTeslaV3 |
|---|---|
| Author: | ditekshen |
| Description: | AgentTeslaV3 infostealer payload |
| Rule name: | AgentTeslaV5 |
|---|---|
| Author: | ClaudioWayne |
| Description: | AgentTeslaV5 infostealer payload |
| Rule name: | Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | DebuggerCheck__RemoteAPI |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | INDICATOR_EXE_Packed_GEN01 |
|---|---|
| Author: | ditekSHen |
| Description: | Detect packed .NET executables. Mostly AgentTeslaV4. |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many file transfer clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries and memory artifacts referencing sandbox DLLs typically observed in sandbox evasion |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing Windows vault credential objects. Observed in infostealers |
| Rule name: | malware_Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | MALWARE_Win_AgentTeslaV2 |
|---|---|
| Author: | ditekSHen |
| Description: | AgenetTesla Type 2 Keylogger payload |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
| Rule name: | Windows_Generic_Threat_9f4a80b2 |
|---|---|
| Author: | Elastic Security |
| Rule name: | Windows_Trojan_AgentTesla_ebf431a8 |
|---|---|
| Author: | Elastic Security |
| Reference: | https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.