MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 8c49fab426c3cf1cd3c39332b8f287c9049fa49db760f73c21e9241bfa574d9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 19
| SHA256 hash: | 8c49fab426c3cf1cd3c39332b8f287c9049fa49db760f73c21e9241bfa574d9c |
|---|---|
| SHA3-384 hash: | 446cb31f0f811a49f21e95783c41cef11a264ac60dd2fcdc748413147b744e006c18eceabe051a2eec62d5924ffbf515 |
| SHA1 hash: | 5c58000efa10e380a70aee873b10d845020a797d |
| MD5 hash: | 2a1eca55b51eeca53dbba0ba00f3c553 |
| humanhash: | rugby-quebec-sad-minnesota |
| File name: | RFQ_New_Order_13600.1.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'108'992 bytes |
| First seen: | 2026-06-01 02:56:37 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'007 x AgentTesla, 19'914 x Formbook, 12'332 x SnakeKeylogger) |
| ssdeep | 24576:xAtO+L08+gL4/7jbBQpBtpuXdTGfHZq6XHHvS2t9PoY:xAtO1dnHbBQpRCdSZqU6+9 |
| Threatray | 3'723 similar samples on MalwareBazaar |
| TLSH | T11C3512557799CB42C8E21BB85930E77613796E8CE620C72B5EF6BCDF78643062A0C253 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| dhash icon | f0d88e8c4d86c2f0 (1 x AgentTesla, 1 x Formbook) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
8b012d3d775bd32f503cb84a6889d786c06623eeb8c840bd8c03073971530f52
6a3368fb5ffab1283df539c6f17cb1244b563f5a3ad94d96adcde2dcadab66ae
8a9b90111fec106d68dd4c23b644b9bd7eb61a71fc67cd1e2cdfb9133224c379
057dd07c9fe02bf1560249258a6bbe88a39f8d02a1a754ff655ad83f99341669
f33b8ab9fca177f47dd8cf23417361f2ac63a0832ad322e32a141a3bc9a08287
a0f64f3bb700ae9170efc662301196fe5d635dbbc72985164537a87602d6bf16
494b7386dd15192888bf519e0f72d74597f20d03835bf567756096627df6325b
d3030deea9a49c1ae50e92acdad8799c9d082c917a419200f7b7462e13d2f67e
765e69564a235c9eac6d724c685066b120cfbdd22ccf40543b3f663427003e4a
4a4d0da0f8c4cd9a46178150f755a1348100b2c5b471874f8a898258c39a26a4
6a43cc3ab93e40b4b844ed68fa3ec383683d3835d7c743a38772022951aa6976
1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045
8c49fab426c3cf1cd3c39332b8f287c9049fa49db760f73c21e9241bfa574d9c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.