🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a02e305139e8a68be11e13de1f8bbdea00e6881020e33843a70db93cd0160404. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: a02e305139e8a68be11e13de1f8bbdea00e6881020e33843a70db93cd0160404
SHA3-384 hash: 5058100e87501cc554281cf1810ab0d5bc9013003a274190007686243f6f67a3c93b1b57188f1c4a232e279d02344354
SHA1 hash: c06cd1abe3335a9db5e13232fa12ba83fe8eef44
MD5 hash: dd6008d8785649700c63f36da83b17e6
humanhash: beer-washington-single-utah
File name:Purchase Order 028.rar
Download: download sample
Signature AgentTesla
File size:1'332'251 bytes
First seen:2026-10-02 07:39:46 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:nstauu2Y8L6Op8yOsdhHHFnK5LcCDLqiduCixfFFmsLION4J3XNIl0mRx:nstautY6p8tsHHRcXwxOsLIOSXNIJj
TLSH T1CF5533B6DE6F6063E6B5D1977D643909A43CCD2B04358F8D2A0F92490261394FB12FBB
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter Anonymous
Tags:AgentTesla rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DK DK
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Purchase Order 028.JS
File size:5'521'284 bytes
SHA256 hash: 5d2a8aaec68af55275f74fb53e9f21b4f7f2eb7f3acc8848943e0cad6678f64d
MD5 hash: 0c6c922706879a959c6667da74a0cf3b
MIME type:text/plain
Signature AgentTesla
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade obfuscated repaired
Verdict:
Malicious
File Type:
rar
First seen:
2026-09-23T20:11:00Z UTC
Last seen:
2026-09-23T20:36:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win32.Trojan.Malgent
Status:
Malicious
First seen:
2026-09-24 00:03:53 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection defense_evasion discovery execution keylogger spyware stealer trojan
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Checks computer location settings
Executes dropped EXE
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Malware Config
C2 Extraction:
https://api.telegram.org/bot7842519054:AAFo7X7Ck72-8s9JHt9boAxHhaSm8A_EDEs/
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MULTI_Malware_AgentTesla_ForgeAuto_ed343f78_Extrait
Author:Marjoriefort
Description:Detects AgentTesla (inconnu, etat extrait)
Rule name:SUSP_VBS_Randomized_ActiveX_Downloader
Author:Marjoriefort
Description:Dropper VBS obfusque : ActiveXObject a identifiant randomise (20 MAJ), SaveToFile, .Run
Reference:Veille fraicheur 2026-09-14 / grappe VBS randomisee

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar a02e305139e8a68be11e13de1f8bbdea00e6881020e33843a70db93cd0160404

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments