MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 adeebc489ed24b4e3e8ca7d0db2a4fe9bfce24c7c7675d67d57712afce862a72. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 18


Intelligence 18 IOCs YARA 7 File information Comments

SHA256 hash: adeebc489ed24b4e3e8ca7d0db2a4fe9bfce24c7c7675d67d57712afce862a72
SHA3-384 hash: 71da0e4a042acb1999dbe85bff9c0a0273fc0e0c5e5e9bdbf01f9be346472a97afd14604a603eac13aa5dbf8569c765a
SHA1 hash: f552949839070e678e2951d0f4b17a3f01843f91
MD5 hash: 7c50d1c040f046fe6c3043316fd944e9
humanhash: zebra-montana-arizona-avocado
File name:INVOICE BILL OF LADING PACKING LIST.exe
Download: download sample
Signature AgentTesla
File size:661'000 bytes
First seen:2024-03-25 13:11:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'205 x SnakeKeylogger)
ssdeep 12288:u5s3/5jUZ+FbiOPZHBztNXxwmK8kQ3OARtGEzWya5Xl8RgY9KZDll5d/3dUxuuct:SwBjU0fPfhwwk2+ECyahY9KZDH3dUxun
Threatray 771 similar samples on MalwareBazaar
TLSH T1D2E42365736D258BF76D8FB0AA7260018B32B8855C04E48D6E1D10CFA5D93C36E35BBB
TrID 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.0% (.EXE) Win64 Executable (generic) (10523/12/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.2% (.EXE) Win32 Executable (generic) (4504/4/1)
1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
File icon (PE):PE icon
dhash icon c496baa4ecbaa6c4 (14 x AgentTesla, 3 x Loki, 3 x Formbook)
Reporter James_inthe_box
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
484
Origin country :
US US
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
adeebc489ed24b4e3e8ca7d0db2a4fe9bfce24c7c7675d67d57712afce862a72.exe
Verdict:
Malicious activity
Analysis date:
2024-03-25 13:14:12 UTC
Tags:
stealer agenttesla

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Reading critical registry keys
DNS request
Connection attempt
Sending a custom TCP request
Stealing user critical data
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade overlay packed powershell
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Contains functionality to log keystrokes (.Net Source)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Snort IDS alert for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Uses the Telegram API (likely for C&C communication)
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected Generic Downloader
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1415097 Sample: INVOICE BILL OF LADING PACK... Startdate: 25/03/2024 Architecture: WINDOWS Score: 100 42 api.telegram.org 2->42 46 Snort IDS alert for network traffic 2->46 48 Found malware configuration 2->48 50 Malicious sample detected (through community Yara rule) 2->50 54 14 other signatures 2->54 8 hiBTcXqLv.exe 5 2->8         started        11 INVOICE BILL OF LADING PACKING LIST.exe 7 2->11         started        signatures3 52 Uses the Telegram API (likely for C&C communication) 42->52 process4 file5 56 Multi AV Scanner detection for dropped file 8->56 58 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 8->58 60 Machine Learning detection for dropped file 8->60 14 hiBTcXqLv.exe 8->14         started        17 schtasks.exe 8->17         started        38 C:\Users\user\AppData\Roaming\hiBTcXqLv.exe, PE32 11->38 dropped 40 C:\Users\user\AppData\Local\...\tmp449B.tmp, XML 11->40 dropped 62 Adds a directory exclusion to Windows Defender 11->62 64 Injects a PE file into a foreign processes 11->64 19 INVOICE BILL OF LADING PACKING LIST.exe 15 2 11->19         started        22 powershell.exe 23 11->22         started        24 powershell.exe 23 11->24         started        26 schtasks.exe 1 11->26         started        signatures6 process7 dnsIp8 66 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 14->66 68 Tries to steal Mail credentials (via file / registry access) 14->68 70 Tries to harvest and steal browser information (history, passwords, etc) 14->70 28 conhost.exe 17->28         started        44 api.telegram.org 149.154.167.220, 443, 49706, 49709 TELEGRAMRU United Kingdom 19->44 30 conhost.exe 22->30         started        32 WmiPrvSE.exe 22->32         started        34 conhost.exe 24->34         started        36 conhost.exe 26->36         started        signatures9 process10
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2024-03-22 18:19:35 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla keylogger spyware stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Malware Config
C2 Extraction:
https://api.telegram.org/bot7112308801:AAG42J2EeGI9ZvqS3CRrqG5QJGUg-ye_i0s/
Unpacked files
SH256 hash:
975d5c095a6bd20d20d1553f0ad36795517087712bdc2a18fb8516665539242e
MD5 hash:
53106229a87e970b8befe76d9118f647
SHA1 hash:
f4965d92934d4acff7ad5f4f9521a1b8fb584798
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
37899fda8cbf74882ae5d68bcd1de525005edfb8b5b87edd42fd86c458bb998f
71ae98c7e6f3e776c17594e8007ecf47ea0209f0ca1142515e4958c02267bed9
5f834237db6598266c1127b74062bd1d92150daf483ccdb0b37f1d306494a5a4
296d5ba75c695171bc26ce33a02e4b16818bddcfdb7688011d741fb78d3dab18
fca4e12e29cf37dcc23a48f671c5dd7f8f4d473bba7754091ca1287d2b124205
d334afd3da3c629abf0772c5be572d1d7b252b9a1ad2fae0e1809d04635f3e4b
bd9a2450499f87561deff9f7862b4ca34b5afb27089b8ae90578f7ed28054808
0a2d5142d03f0dd333f371e089c5f0d5fe8c3169e4ee78d7ca23b1472b2f7b48
27aca3b944c0bbd1b6d020de7a9ef916ba170e017ba63304adfef012822cf20f
7beb85da1bc8b1c935309f219347d8534a77ba114ca4217bd60f98b4ad05836e
a775277953ea0daab3cbec4aa2b37c5e0052172c05f7d4d0e8c39894c58fabe0
771c49d7430b930313e8af81f4b89fefd3d6b6450fceab630b125a6a6d4cf11c
8d5930353d2239c66b566cb6725058657d642d766549d493f0118aa495c95106
aa33486e9090a3807a894ba0c8c918668821875e0df7a15574ea412489673e3d
f6eea72845ed2286d5faf76e537b1e94081c2fea7be4772c5f63a04e6a847795
cb348e8dbd6c518a9ad671a9fb235cea3eeba8b7036fc5498f6b118d4bc3060b
90f4e7731fc41021b7ce9f9d15704c9849cf3215161585721a370745f7392e71
d85a4e28a6003aaf9cf0a6c0bf3f5bee31eb82f39930f8ecec7657dd24093c49
00d1bd4fb6f0afc0345136a810f410fb2c1740fd8adf0793e3cf6597f9bc7447
53cbb972306a7569a1762feaa5df42ad66de898691b4cabcf1c2c35526361d8e
fb73c562937a21c54247a51c05d0e616148301cfdd24b1619f0e13191a3ab687
fc9a9c10b989fb790466a432945be2a122151bd634013222bfd87469a9f4d584
a898ed790cde47b79f0c27f18406d6e290178bea8c35788d5ac22622cfadf2b6
ad048fa92eef59c07432e25c1afa2af4853be0a301e3ea64910352373fdea51c
5762147a28aaed979353975b6f7e2d31d71fb827af0dafb991b442c30e161caa
1c98180948dc869d00e1fe42476559fae2d76e95ce809c47736aca2ed6c20970
4af0ad255ce753c34b265d5714681b436ef635cbfc8dab10349ea913547be805
b21d51bd3eae9c07144b4d2527d732227a775c18e42812eea7a6f3a84c4d3a2d
86cc6304f5610bd7836b6706c2fe5d5c1fd88ad5de23927e41a1848dddf744e1
35283152bb31940827ea64cdef4baf0f332f38b348d83dd3c34364b97f6d3d87
9dfd52d9008fad9915a2ce18b0f9e9a2dc6c513f7396d049a82faf97410950c1
2c86d6d8fe9b19bd2f24d6e424c90b9a4bee255cb10e8319427d689d32dbfc60
d24bd0ebc242b94f043fe80e7f6a48d20566689f31c55aa1ec910a2877ae9e28
b6d91bc05bcc51b0a9e9f6e605493168b1a78ccd6f234030d05461e12544cffb
dce7d8b9beeb107ab7520818cbba375962e1c6e8ace6020d1a344446498260ac
a5810d5e9262b17b5506cbfc546421debd1ddbb593ae8440c2b39793044200df
a25bdcab7a38affd0798e5d674341724726c866e7cd7348b3d75bdb47ccca230
8094dba1e87d004dcade1f0c8c15b78af99e3568d7912fa7b85cafd1e88bc83b
e1ce37159aa3f3e141d622216cc4994b7fa4014e8b094b56f34916bcd838b872
c7a16881f8c69d16a9b0bdcbfdd5c4aada81eba19521d1c03ee7f6005f7d6629
adeebc489ed24b4e3e8ca7d0db2a4fe9bfce24c7c7675d67d57712afce862a72
454e87da084f762d25dcb7858795f6bb6cd549cc0f1435177121b0eb66c17743
SH256 hash:
7b0339131e633a3588bd36ace536a4e88e9ef40a25b57235396ec2b55395be2b
MD5 hash:
2fdb192ac352962f6ef578a3f985469b
SHA1 hash:
8010fa7cf56724799c4cea15f710938872c33923
SH256 hash:
7cfce9d4374f24d233171eaff3aa995d700542bf0a9fd54f183745647f450c4a
MD5 hash:
aacd3a7a18721a1a5e2aac83bfedc3c9
SHA1 hash:
2743a9077e031d648c206c00bc0fa38f9e0dab38
SH256 hash:
fd6f93a5f59924f44d69817eeaf7db18718ed8f53f0e6cd5998cd17178edf404
MD5 hash:
27f90c0996a7e40de07700c1014435d3
SHA1 hash:
01c24458af445055cbcdfc2012d2c6fb315a1e18
Detections:
win_agent_tesla_g2 INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients Agenttesla_type2 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_EXE_Packed_GEN01 INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
SH256 hash:
adeebc489ed24b4e3e8ca7d0db2a4fe9bfce24c7c7675d67d57712afce862a72
MD5 hash:
7c50d1c040f046fe6c3043316fd944e9
SHA1 hash:
f552949839070e678e2951d0f4b17a3f01843f91
Detections:
INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments