MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abd4a743c4aa8fb625f1af14edc51606fc1b8e1a15396d9db706c1fd3cf41395. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 14


Intelligence 14 IOCs YARA File information Comments

SHA256 hash: abd4a743c4aa8fb625f1af14edc51606fc1b8e1a15396d9db706c1fd3cf41395
SHA3-384 hash: ef63a24afc31d49bf788e2d55bc9c442f9c4295757d395ff5d08fc5b975a61bf56de32cbda38fa7a4fc01dd223028f4a
SHA1 hash: 51780ce1ca221f893441330aef6ed8ba2d9d7fc6
MD5 hash: bfbfbe3d395b944474c79432ef47b433
humanhash: social-grey-pip-seventeen
File name:【PI202211385】in US dollars.pdf.exe
Download: download sample
Signature AgentTesla
File size:859'136 bytes
First seen:2023-12-18 10:53:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'744 x AgentTesla, 19'612 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 12288:KCwEx2iNXPTPxgQDuxG5c5Xur0HVq2FsSw/xIDX5VQvlZ1crttGQiOkUZv8Ta:nwk1JTPxgZOEV9Fg/iTLGKttGc3Zv
Threatray 2'949 similar samples on MalwareBazaar
TLSH T17B05C23C49BE223BD6B5C6B5CBEC8827F05CA46F3150AD6594DBC36613C6A4274E322D
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4505/5/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Reporter cocaman
Tags:AgentTesla exe INVOICE

Intelligence


File Origin
# of uploads :
1
# of downloads :
399
Origin country :
CH CH
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Launching a process
Creating a file
Using the Windows Management Instrumentation requests
Reading critical registry keys
DNS request
Stealing user critical data
Unauthorized injection to a system process
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
Antivirus / Scanner detection for submitted sample
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses an obfuscated file name to hide its real file extension (double extension)
Writes to foreign memory regions
Yara detected AgentTesla
Yara detected AntiVM3
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2023-12-18 08:25:36 UTC
File Type:
PE (.Net Exe)
Extracted files:
8
AV detection:
19 of 23 (82.61%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
AgentTesla
Unpacked files
SH256 hash:
d01f3dea3851602ba5a0586c60430d286adf6fcc7e17aab080601a66630606e5
MD5 hash:
579197d4f760148a9482d1ebde113259
SHA1 hash:
cf6924eb360c7e5a117323bebcb6ee02d2aec86d
SH256 hash:
344da810e68b92825d5243b621565c6b6534ce5e07a1c754534ac4121cece8b2
MD5 hash:
ba29675b1f71cc417455b10d53f9a307
SHA1 hash:
ac391bdd4f617234ea482d3568568d9f6b27431c
SH256 hash:
23f0988a2516bbed0cc362a6d88b743bc07dc03c92c38ba4e2796cddbd28a9db
MD5 hash:
e23eedd13ea327d25bdebb8dcf8c12fc
SHA1 hash:
63c7b872a816e77e147d4ff5d5706bfa96205872
Detections:
AgentTeslaXorStringsNet MSIL_SUSP_OBFUSC_XorStringsNet INDICATOR_EXE_Packed_GEN01
Parent samples :
5d6eb27a75b5149750cb2891e26f18aa808f2cfe9dd633777028bbcbbce10105
333bc1da1ebac150e52df580ad487c35d31caa25bcdd8e06dd1579cd6dd86019
9e9271e281e82549c613d3aba4a0603536a63c960bf42c16302f6b7668de0d78
310cca45875cb77640bd15ff405af55de5a00828088722da1681aaa2cc90c931
e446bfc6a1d4e343f6840965abf9d010f5c32e06b188d3d076fd2e3e0b0bab79
c6e74929d1f5df0946833f77f1074f8a8518a642067b129dae1ad261ded796f2
bf97757e1e84e0b3c97e2df6f9262873ab853605d2859ca93852dcb6d24513a9
5726f0ac293bb3dd4a0fce6bd6e7f7d9ded4ecbed55733bab4c91be2e58be478
b9d37d2bd06ca6ea4cfc72d49f30ffab897351e19f4cd31464a2a3314ee642ba
067aca62f68ca0996bca1267c8fec3859a412a514db8878808bfd576359f5ee9
9ade1aaf821812d038b9bab451e0b48fad06c688e738a522e2d3d9947421209a
4581026ca8972214b08a22a0b621d607997da7586b828e02bfab11a5ca5de33f
4ea83aefa492b4ba2b49e13e34023674ed8b50373a9f521dc887178f60b60965
ea334a8065334c73ce7ab24aaf3aa8d2bf400bfcc1389b5859e76348191a43f5
27e36aeb932b11f7f1a9eb8f7cc2ff7cc7d05549d3936aaaf5a6566cfd72166f
256ea055c6552920ec84ce91c5e9caae6bf9ed5a262c1f237adf8be1a99e8272
40247a3716900e213541061e25967670cfaa9415f554228dd6766e93a0def8f5
9ff3cd3ff6bb45bd888b2eaeebef3aef2784182df2ef03449d435098166882ba
d3b064dd11c1c634020c0c155bf9e33c1f0ad2fd8fc85eb1ffd44e05cfd4c291
2bed887fca5ae34bb249eb750e20b7542c9209a169745ad2bd9176618042f8ee
30a2b97369cb49a104c48274ea39b1af4b3a1eb9f8ece684632ee00bc409daeb
6e41de3cfe2a499488f1eae60dc1ba0f35f0e86c2428271e78bc8ddb51e26d0c
af87ecc512fe3271689f7674ab31070633ac5a85b3a5b2ac585068f3127b77c7
427883d7c6eb502e12e7ae65c1d2c241c8815998faea9dcfd9681d8f40f1f665
f37444849fb5d3f512aa399c0ccc8bbac2dac9a725c7965f445cc472f64a727e
23f0988a2516bbed0cc362a6d88b743bc07dc03c92c38ba4e2796cddbd28a9db
4644d82860cef54c8cd84971e923baa8ddc0347375701c7dbf5a884bb1c5771c
5d0e819a624b53524558b2e89007e0a645123a0e401a4dd5c2e5f709730e8f0e
e1836520ed6edb7fe91462076fdba7e96174e4506e7fd2df69de260199e5c020
2685ea1f640c12172fb5e136a624f56fd904627b6523a75c7f9357c0313ec518
a8ee0501ce8a092cc0cdbbfd3572db5c3ad505e054ffc24e4af4b6678726f850
dd9072aa04107fc87a791671e749e9b8833fa7885271e392ee1db9fdd30ff7ef
5f38f51f0ecaf46523adab8c5597af29894278716ebee0e1a87bde9863424b88
0caa683c9f3f6bcad952386397eb6a3e70d5c0f4b2b3d8b144f03a620e81ef0f
4f20ef240b6cd77d44c9515a39f1f9a4f12cdd84a043fa63a9928fd8728e3106
c0fcad9ddeff65354abef66d0d0ff63091aa7a090e7b281514956367d9bcde40
fa77fd0bc332cc52417da2001bbfee518d2d6cb6c363d15e67d1417afe784325
1f3c7beff0c3f2e7f7c21ae2ad886224c71a739c7554ba8f38aa3f9019ec48db
9e7eaf53bfef161396377f312d623d10c49746779710206acbe408496e50d68e
01af6a15beb6d627c8e7d255eb0d8f2e1167d710b101973b8da9b50246368bf3
2c02305910d1d64b8128f8519f65a75a9d33a27cfc21de77bbd087fde9bef580
b723d813af59659cb9a6164a6b1e9e2ec42353ca05272cd3b773282e76fc2385
4f9ab5722f95d20fc30c81bf817157c48c6e3f6e53a5a2881ff846be338eb360
f6ceb475c843b5339bdd85afc176eba77bf0d7a133afa4e092e3cd9e93889a7a
4ffdc291532f5d4d2960372a807b3215c9486d6fb643d09c64fc2ecf23cb31d8
eca31a8b84856348ea97f1a1469c8b34f6afc80b79e5a0d40fca44f2a4139d0f
becf6b9764ef6665d04082b9f4879b9bb1fef8976d752411778b7d83fae74057
9de62e10117526b21be8cded286a1522be0237d4b6e24d51d5bef8cd66cf7eb4
47dfb65b3426e320eb7e9ba01ab8fe1e12bc00ffc217f148676638823978c350
4bd728557c59a4ab89a5d3bd881603e69fa41247bab33f22d95404e532b21b24
fcd1fb8ea7cf43f01388e7763017ff869ccd345ce8d4cebfd9b97dbd2496520f
ed3e5af47aca29408248c203ccc55369d5c8e1c7d468b613fd3993fdec39eb08
4b521275a1d1b0a5c527419333dddda642148dde8cefd4fb9a8e4657848844b3
d8c86642c4e7e86d3591143c9bd7a7ca0278ed8812908b81e5633948ebee2eee
ee87b91b6480592bf45354a624ef6b478ed812f5ef33e36dbb6775fe057dbcfa
b68d03062282d38f52d9c19540ec2e1ec85eb501fac42d5ac64c4f77b1e087c1
d7c1ff8739d0d26e441b0828edd8e77700a97d19231d1cf0dbb105735f793ef0
ac3f1194d74f5cc87908936d768285d75e7df2171b653271a59568399b0753de
2af7b3022340dcc9a68e42e7b6c429e12923b62f81a36bb59e61a6121fdf2052
1cbbef03f82222e64ba32d7834fc6d1718b5cdb7f2f9b90ccf7d0732a95615f6
e9f611aaae38af4a81b3dda7c5997a4c8e852b6b87f4462b70bf5b5fa016e584
c7d5597ac8ed4d56434f101e6fe02c9ef5482f36502fa5b4f764b52ea643a5da
c70c391c3da0b64bb0f82437b3ebe6b18efa3cf871c2d890820725a060474bf1
abd4a743c4aa8fb625f1af14edc51606fc1b8e1a15396d9db706c1fd3cf41395
73d86b4c5e0ec35d75e6d81fa0244f5320a267b34fa37b12f5d548958c9390f4
b95ca7569939cdab51f2d7f4b20e8d76cb94a08b26e38aaedf4d6d84faf7d12b
SH256 hash:
c681e39199e58b59eadda0b0fcf86b9fc2e6c43cb2ec392bc05627245b2148e4
MD5 hash:
44c9c77691c640a1c57dc3b82db6cf70
SHA1 hash:
4da3e3d560a75b61a381ed657e34b0ff89548568
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
ada28dc16f1eb7d03ad145b01c1525e832d18bcd8a179dd68c1f5c4313b5853f
9496ea650a182fc8c1b87b205c226d44b7271186b473b156cfb727c2e81dca0a
2fefc7f1b4dec38932b815ef1192a4343c4face356016de5ede1c17958950975
be69955e99c6aec10c257ba0211df9cce2fd5af533a8932ba447b1450aa35699
59d1135fc573e663c3c92460520c6ac49ef035d3ad789cf69708cc6c6409a9bf
bb0563d0a398d0501bda4848f662f494dc8807b2ca7e81fd733d38e1145f1efc
ba33d177c1fbc1f4f44ae77af00eb377e9196b2f9f1556e94fd82b942883be13
9996fd83b852a172c456594e49d2a13d94b0c8d55a9a2d28e5658853ed819b28
c5cd096e51840ab5ceb8a29c7efedee7ae3f16562bdd4779b5b1bd44dfc784e4
128b915c058609131a3ae2ae25b26aea06b51a0001bb9b9794b9cf401f16668c
961501b7f2e2ba7d255fc9cc4de8dfd0697dd2265c2e4e316f92854166614c31
5c7c411ea48976a55a30558e1ce6147a7f28b6b99d84083e1f01de1db86bb588
9dd7786a5c103076ba73cce2e2a3dad65a6a76684c781a86d924cddf9bffc8b3
a3980c5f653e99fe53dc88f60a9ca1b4954b8cee932085ea57b1f46b9c7ab4c1
30f5366a61da542dd959a186cf9ae3cbc13efa1d66fcb67631b62cfd8ee52612
9feeb14ac128b73d9c6eaaea8c91272ed93a1780c126b6ca90ed077f1185484a
ea93863c147402b54407c3a1eff90043b55e76a08aa3ff4a8823469dd4d9def5
46295ce76105598ad1d887f772d13391523cf76347b3ce1f8be1db96053c278c
9704e443a68009427028c22fdb39eb3e28a32709d42358b1df4c95d16a4112fe
ac44b7c74193bdc699761d10f631bde2dd81b7f4d23d57f6cd240c62a9b26331
6464a6492dd967af2d0582451a3574b456699f0337cc6b10c088988078fed79f
4c3c1031279a42eb5955cccfd5a006235cd27b909503d10ad4eb1c10dc5cebfe
e404945ee6da74e3dda8a92dbb0e7e163c46a48c84aa0a291456a0f66a5030fa
5336c951ff27b8609dab0bcde98c674d54e972eafc5514039d0a893fdd52a965
b25ebc1b52d81dfb1cf844c3b87d65c0a307589b2775c12aa7c7c2ebcf74fcd1
6bffe8588990f845c6eeafbdd359e2355dbcd68de8b0605175935886857970bb
0390ab5a06e04c8c38776aeeea11fd0352230d049be1defb139e71e8906114ba
3e43fe5dce47c5a3115320ac38040f4b6367e58356a06810ca638579da1bf3d1
fccac8700366b9cf48eafc5c012a1616534d26fc6501d4014e56a0619d5d0db4
b965df83cfeec960e1372166cd73d936ebfb3be2986db0bf953bf2b67b5209ce
3d537a7796fa465cdff1388141e37df9ff689007f024808b90381640f99b9b7d
9cf514b4555e47eccf07148c0e961250d108d04d8187a4aa224629f7a0961142
8737b9c5969931c61500427c301c40e635acec433bd4450e1dca9f202e97fb6f
6819d0ef008f17b3bffc407cbc8e37c43eabfdc39bdb10029afb535f542e4d86
7948315565e8321056661c7aabdeb10e01ca73d2425a6f6bd17593a0ffb484ef
531ba82cdd6f8cba501fd8c5160ec637c2193ce69c455dd8e591da083f2c80da
509f9d3065054df28846986ba9a1190361092f3bad865d77ef2ff10d32151ad2
abd4a743c4aa8fb625f1af14edc51606fc1b8e1a15396d9db706c1fd3cf41395
4a0a2c6bf6a863c1c56fb7b6657fd8cd60369e03fb40d8634eb5ee37d8575390
5721a2c6e2c0a577828b9e4b3690a18a7df63e541aeba65781464c1f73e8da91
24ba94ab2486ed9bbac37e3fb3508b6bb38ec8bafe1c0816719351e0790a21f4
e5ba53de1a80eda27337da32ad9bf522473c542fc42a434fff3fc843cbdf88ed
d2312c82b0ef97a5bfcf73173a4b72a720c2194278d6a7815091e4f4727e6a61
fe708d845a9c3e6d3338b2a146a4a5e68fe05d448b72a63bd60f4b431b243d9f
56cd0e12747b872def87829710c32165fc42e34ed351872e1750fbc13a8c31a0
93c052934438599045e6d9a3177f5d7d57960cad17070bc74444c1e4818bb81b
3de39937dbba16980b665dcf03505af8bd11a77a9f09d8e5ca69837932a9340e
b2617dccd3165177226a7c23effd6dd4e51e0c06c7ad57818ef1461ecaaa13e0
4f8ef9616b1237912967776aff09a8b8fea96837f78787911ce7405ecb4b001d
33208d34b4f679b8ec036d5be12f4d2ca960dbbd8af46b20247d5df93f1f63a5
3ae22f99bd5e1772eb6f9abb1d127c8682b5847b6e7e062d843ef236db85e828
94afbf76b9c59a5e2ae4bc864a78c41f92602c5b37e6771eb29864344b69dbce
b091bf4326241b1053f88a1a47618fee3f87ccdce873a9bb79e653670b7e4948
8d693225be9e1f824c20f3bc2f71a9c21e87a2b32bca274580b7abad75ecacbb
d02530a2bac21b47a1ecaafc185ddb11680c9a90d0fcb2c52b7b081b952f1cd2
01dbf52c9a79ce268fa7b5ab876ab6c8a8e6d5d5de70ccfacd11ca169e83908a
5c11be9fa69ed199fb4004a1fb7cf649d4f7e469b43c7b5f73f4867cecf89d18
7f2fea83dd18d529a6a6440334240fd6ea6cb4a84d4bfe1ab3213c894a7a51d0
0eed254ba5c7e7cc2b6ac08be4b1a450d453b58ed58d5b23caed7fb0db89961a
9dba8d99de990b1900e024e45a32d8ed2ffe06018ea422a92eb4a9cca56144e4
2b55e6baa2cf6110fb403cdf32cf7b9c06684e06a53a417b9f0bab73fb9c6747
71cabc7f66e840c073f576ee3051b7e4eb355bc28065a10eb06e5ec737d08221
61c11d170ceb320bafd7872824de7ce33d10fdbb5ef585e67487f9afcde5e207
4e77677a9a29e465f030c9a9695533c8dbde964ecc66585a0b9f26a1548ad3ff
0172a0a250dca4e77360389ca9a6ee4dec2f306bd056265c9a42de7af49481f4
cf672b77bf6d5faee34f9ebaca90fef0222b422db31d4464ec73126a15736c3d
00972929b3e57240b86f2812aca237acff75e09d18a55bcf575d22a2beb5fc9f
8e57e2bf33cb22ceaf6596ce060680e8efa099bdaaafc2383b1d31b24b0fca58
6d306743daac37b3fcc6276d1e507f504833ffb8db0839808c016a339a64cf85
7bacfc4148055cac9beba5517630e42a46ca8689bc8e6fd1bb25831e43e58582
e28cbe3c81e959dd96ca36cbf3585b4523ce4d75c989ffc16d756f71b3d2fe54
2b6f9aaa250051acb504eb782e963ef4bffca581d26d7c632b405f130ee5e09b
2b99095636ec250358f5abd47474a374de96f743fc2fadb89642401301e6b670
ef8e672ff4f30d2630ddebcf804c67d572e9979c949e4803654572479f486db0
e50bfa53e75f7c54582c2609f3c59db91bb47590a43a49e95e5458a6ae97ad4b
d6aa67de9b98880b2d666debd047112535c8527642220a81b72d6246b1eff210
0c263290cd7f3c225d5f7b2ba488ac5d9927b03411c566fd81b73bbee827c46c
0ca7d41fee3a2830bf3c46fad06e838fa2f3a362a3f62f58f1b3f0176146ddc3
937937444fbc2f971d32996dc728c166315195b25b2c0aa4befbef762b93ea35
46a870926fb693596e4fea1ff6ed4bd228d8cc63a9e285997ded48b1484ab3f5
8736f4327bdd2098d35ca3ed5c2733f3a066a434804b846277047ef097e09c85
68539ce65162c2526ee390f706b68e249e05e0453f2e5138dd77a9d5aaa9b54c
1e0ec921f531219f110e8bf1e1e5b5d757119ea7e2f1d885bfa234007548c95d
6474b902f837575873e3b356ef0939eedccf0cad4b07a82fc5b7aa80d3b46339
d9c3810761942c6191a8e2dfb22b2178d6970bf474a908a4af1bc80b3022a774
4dbdafb1f38d8d8f55f611e7e6985b3975658a8b0b652d80c432eff73812e21d
169ad5c33acf7a4aae70046eb2ac4e8f60c62c236065c616277b827ea4ec00f9
79658843a0028941539f3b437a8d262c78b15e6e58f4b1f7b96bf357b06fa84f
326f39b2d29896b3748625b4bab991da83ce7583b35dc0ed984455c77f24057b
18f9d778efc5dcb90c7ae7ccaacdfd8b9041295447759c1811e99a5d0a48dcda
a9ed7edf5b5cecaecdf126bafc6c85d3ca918363d874f3c33afc07131bc43c4d
26f693ee7807e9a341eb9936519194f587d1bd2998fdb734d36cd62b9a46b8b1
d34e493e8e0dfa5e9a04ded3565e2ed4d60473148e63aeb3fca9a7f62dc90900
70369453cd6e8481ce8f2fc4fa4074fb998a27ff6f91bce6caeab0ecac36493b
781fecd030f2f437a89dcf726a45e3eed218043316b35e80770a20a6f4bb62e4
c569fe7d3ccb9bf36356f829d5ab7de3ba4261d3beaffef1e690d8d197919c71
221df9cb593d75416b887497288cdd49ed654c164f1a752671301228a97e2282
97a3313357020aa0cda6addb7bd2015cc52f67dcde4c75f4d89f9f4d76f17b04
3e90bab5c79be10c283f3752091122910f7c5b9f35428a37eb0250d244d01f94
SH256 hash:
abd4a743c4aa8fb625f1af14edc51606fc1b8e1a15396d9db706c1fd3cf41395
MD5 hash:
bfbfbe3d395b944474c79432ef47b433
SHA1 hash:
51780ce1ca221f893441330aef6ed8ba2d9d7fc6
Malware family:
AgentTesla.v4
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

Executable exe abd4a743c4aa8fb625f1af14edc51606fc1b8e1a15396d9db706c1fd3cf41395

(this sample)

  
Delivery method
Other

Comments