MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9a31156b6d7eb6076d0bb4a2f593fc21be304aa9e559547e2ee4a6232608c35e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 16
| SHA256 hash: | 9a31156b6d7eb6076d0bb4a2f593fc21be304aa9e559547e2ee4a6232608c35e |
|---|---|
| SHA3-384 hash: | 4950599531ee8eace216603d055e35bbea3a2928cacb1c05e63f40ec23f221280b7e103b4844275802e1b53f5aa0b017 |
| SHA1 hash: | fdaf90874200fca372135cbc1d78599e1f38f43a |
| MD5 hash: | 1e63c9ad686c5f6cf395f6aae426006a |
| humanhash: | lemon-snake-xray-yankee |
| File name: | orden_##9887532#2587568450323533950_3464665478768797989878009878769769789.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 757'256 bytes |
| First seen: | 2024-05-15 19:16:37 UTC |
| Last seen: | 2024-05-15 20:17:33 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:v7aWNjpkskxRDqaCgqeR5F6HkkoFtjDS5FxbXLKdwrbZi8cKN2YjeqX0qXOZkGKR:v7aWNjpkskxRDqaCgqeR+ofyrbZi9iV/ |
| TLSH | T153F4120437B45F3AD4BAEFF9A0B1641583F6B91F30A0EB19ADD241EE6960F600611F67 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CAVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
89d69f0365c11bc349cd92ad79cd3066b2225fe41dc2def83deef2661dea01a2
a745b4a8dbdad5c84183ce33793aac75423bdb99fd3a3fca646fbeb66e1059f2
9a31156b6d7eb6076d0bb4a2f593fc21be304aa9e559547e2ee4a6232608c35e
9897c1f7d4ecf7e68ba31bef6c909543d69c6bbd95a17d061f45ed13f4b92bfd
1723b52fb0a05e96e165eda1385729bc64d02ae86afaaa3d1661637ec2d27192
6c0748b811be208d404f519d342c5d63faa2e0dcfefe64131d6ed500285eb0f4
69b1e423fcc489f982d8aeae0cbeee56140b7d8a8810a8c98a7dee8424c00174
2fc7d83ec6fcdfaa540dd36add9c20c880ff865927530305d736af40c8bbce6c
142fb3857b4ca67fa862800dc443d4e405f419e1699d1c31de66d913ef038b15
ec0b5ee59f4421a87c7f912e1af5f27d9e1ae135ffdc07cdd646d1b877c8c6ec
f3b2e714a23ff2060a9f40f574727b5916363b45266653849d6aa5775a51f051
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTesla_DIFF_Common_Strings_01 |
|---|---|
| Author: | schmidtsz |
| Description: | Identify partial Agent Tesla strings |
| Rule name: | INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438 |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables signed with stolen, revoked or invalid certificates |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | PE_Potentially_Signed_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.