MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bae9ebf2286071c5bc562644c8b056767705ee528e9fd52145db6adeec96c33a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 19
| SHA256 hash: | bae9ebf2286071c5bc562644c8b056767705ee528e9fd52145db6adeec96c33a |
|---|---|
| SHA3-384 hash: | a547ead5783ffb534cd33b1bd7465a444866b803aed2b26f93364b01764ffd40421156f84f12700de6fb35a73000d852 |
| SHA1 hash: | 0e1814f67c21b44e3e619d615fd8f3c2b281757e |
| MD5 hash: | 807723730ae1f37f11050bf5de28fab0 |
| humanhash: | queen-spaghetti-comet-oven |
| File name: | Payment_Advice.pdf.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'094'144 bytes |
| First seen: | 2026-03-15 13:21:12 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'013 x AgentTesla, 19'917 x Formbook, 12'332 x SnakeKeylogger) |
| ssdeep | 24576:F9fZLD1pciaZlhshnRd7oTBdLpAOKNgYvp2kAD739rnvVBx7MO7gQ:F9fZPHcT8RloTrpAvCYxA97vJX7gQ |
| Threatray | 3'572 similar samples on MalwareBazaar |
| TLSH | T1F735F1082767EC07C1B65BF148F1D27447F95E489422C3139FF6ADEB7A26B896984383 |
| TrID | 72.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.5% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.4% (.EXE) Win64 Executable (generic) (6522/11/2) 4.4% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.EXE) Win16/32 Executable Delphi generic (2072/23) |
| Magika | pebin |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
8b012d3d775bd32f503cb84a6889d786c06623eeb8c840bd8c03073971530f52
6a3368fb5ffab1283df539c6f17cb1244b563f5a3ad94d96adcde2dcadab66ae
8a9b90111fec106d68dd4c23b644b9bd7eb61a71fc67cd1e2cdfb9133224c379
057dd07c9fe02bf1560249258a6bbe88a39f8d02a1a754ff655ad83f99341669
f33b8ab9fca177f47dd8cf23417361f2ac63a0832ad322e32a141a3bc9a08287
a0f64f3bb700ae9170efc662301196fe5d635dbbc72985164537a87602d6bf16
494b7386dd15192888bf519e0f72d74597f20d03835bf567756096627df6325b
d3030deea9a49c1ae50e92acdad8799c9d082c917a419200f7b7462e13d2f67e
765e69564a235c9eac6d724c685066b120cfbdd22ccf40543b3f663427003e4a
4a4d0da0f8c4cd9a46178150f755a1348100b2c5b471874f8a898258c39a26a4
6a43cc3ab93e40b4b844ed68fa3ec383683d3835d7c743a38772022951aa6976
1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045
8c49fab426c3cf1cd3c39332b8f287c9049fa49db760f73c21e9241bfa574d9c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTeslaV3 |
|---|---|
| Author: | ditekshen |
| Description: | AgentTeslaV3 infostealer payload |
| Rule name: | AgentTeslaV5 |
|---|---|
| Author: | ClaudioWayne |
| Description: | AgentTeslaV5 infostealer payload |
| Rule name: | Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | DebuggerCheck__RemoteAPI |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | DetectEncryptedVariants |
|---|---|
| Author: | Zinyth |
| Description: | Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded |
| Rule name: | INDICATOR_EXE_Packed_GEN01 |
|---|---|
| Author: | ditekSHen |
| Description: | Detect packed .NET executables. Mostly AgentTeslaV4. |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many file transfer clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries and memory artifacts referencing sandbox DLLs typically observed in sandbox evasion |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing Windows vault credential objects. Observed in infostealers |
| Rule name: | malware_Agenttesla_type2 |
|---|---|
| Author: | JPCERT/CC Incident Response Group |
| Description: | detect Agenttesla in memory |
| Reference: | internal research |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | VECT_Ransomware |
|---|---|
| Author: | Mustafa Bakhit |
| Description: | Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments. |
| Rule name: | Windows_Trojan_AgentTesla_ebf431a8 |
|---|---|
| Author: | Elastic Security |
| Reference: | https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.