MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a9bba02b96d42694417f39596c58112f086b63160d2bd5ff4beef616fb130bb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 15
| SHA256 hash: | a9bba02b96d42694417f39596c58112f086b63160d2bd5ff4beef616fb130bb2 |
|---|---|
| SHA3-384 hash: | 0a12ffbb3a313bb652fc89652f2ae4d9d8a6ee3a76b86440f9e21ab5a3d56d8854e8c77d4562eda86ea44daa416fef7e |
| SHA1 hash: | df1045306471a6b392cce2f28bfd4efdae6dd31b |
| MD5 hash: | e0659414477aceed1bd5ef7c92dc6b7b |
| humanhash: | jersey-glucose-bravo-berlin |
| File name: | 1719563345e26e65224caa7856e1dbefb47fea82365877084939cf3d196b299dfd2558b45a338.dat-decoded |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 244'224 bytes |
| First seen: | 2024-06-28 08:29:06 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'124 x AgentTesla, 20'137 x Formbook, 12'362 x SnakeKeylogger) |
| ssdeep | 3072:BhGIm6GyWP/rUcJhwyyyyyyyyyyyyyyyyyyyyy1yyyyyyyyyyyy9yyyybe4VGDmH:BNm6GyWP/rRdBG6SOqeV |
| TLSH | T1013400037E88EB11E1A87E3782EF6C2413B2B4C71673C60B9F49AF6514516926C7E72D |
| TrID | 60.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.8% (.SCR) Windows screen saver (13097/50/3) 8.7% (.EXE) Win64 Executable (generic) (10523/12/4) 5.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.1% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| Reporter | |
| Tags: | AgentTesla base64-decoded exe |