MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bc9a0d8c86644a7ded8e5da1ecc382a6cfd7dccef79305ea21cd3f27805d8f40. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 20
| SHA256 hash: | bc9a0d8c86644a7ded8e5da1ecc382a6cfd7dccef79305ea21cd3f27805d8f40 |
|---|---|
| SHA3-384 hash: | 11893d8516e2e4626562fd608d800c1ddf3209aa5effbd209e9ea6ccea0feb44bf72a5e8e9f5480249be045fbfd65d66 |
| SHA1 hash: | 2cfe769b1553cc0e432ee5c0f0e1bd40b2bf69cf |
| MD5 hash: | b02204e882190187b10f5cb419749d35 |
| humanhash: | king-mountain-maine-undress |
| File name: | PO-D1033857.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 790'016 bytes |
| First seen: | 2025-10-08 01:04:58 UTC |
| Last seen: | 2025-10-17 06:03:51 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:d8jOle64WEC7B+qpNgVCqHAJy+dRW+HTH9fA/ZaYfHS90W8JzXA/zkqWrP/UTQ97:d8jz64wFXgVHuRNCDf8hSA/zorPsTY |
| TLSH | T160F4229812ADEF03D8761FF45961C13217B47D999E37D9899FD21CEB383AF889020A47 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
27ccd3008a7db4971b410557b6f2712bcf80ac419be2a1861f3f113c52709cb4
9975b81e9f8b7bf220475765a809c03d9462b60f27a06de2b5d867152aca5dad
35a6c90aeed158cbca180d1b3116e6d07cdfdc41731243f01896bec972b99255
b897296b26ad15c42b2194eb6c75fd5a2b91aede9e7b9606acb1ae2bbe3e269c
6930fae092d170045ef16fe16ff486e4232e95ce5092a10c8d42f07bffa0f3e4
602ab5ca721cdfb75b5d4b314fb7eff7523a6e8da01ad8e43d5c97eed35b2127
f9753dd9a49324ecfd5646032410c8be95c18c59ac805d8075e5807704386bd5
239cf71611fe5e6a3c829fe323d0fa0286eafaffee69a8085cdaf203ed15f7e4
bc9a0d8c86644a7ded8e5da1ecc382a6cfd7dccef79305ea21cd3f27805d8f40
feff0fa7625cbc34999f6d5605506d981ec4ccfd031bf301a0622face17499d9
a9e6569e2420aeddd0f595a6205f7794862d6141ba69c640821819221be78d35
d8e23165183fec3c7ea6c15911586ea9dcbe553873f094ac2667d93bfe0487c8
806f1c1c9ab2b0b209c10e34f47a6cf121bed3d23dc2ca1660fec8fc3118872d
f75840264d34021cc2dc7c5c5b7c4caf93eb5b8098015941e889a84a7de2be90
9db5b9e86e71661d7769316f9ef1fb79b6478b00726b8be14c0b09f7be5b941b
1802fc33f4ace43af977ed8e064c4e6154d23c1f5c737b139ce87a9e9f1a0fa6
27ccd3008a7db4971b410557b6f2712bcf80ac419be2a1861f3f113c52709cb4
9975b81e9f8b7bf220475765a809c03d9462b60f27a06de2b5d867152aca5dad
35a6c90aeed158cbca180d1b3116e6d07cdfdc41731243f01896bec972b99255
b897296b26ad15c42b2194eb6c75fd5a2b91aede9e7b9606acb1ae2bbe3e269c
6930fae092d170045ef16fe16ff486e4232e95ce5092a10c8d42f07bffa0f3e4
602ab5ca721cdfb75b5d4b314fb7eff7523a6e8da01ad8e43d5c97eed35b2127
f9753dd9a49324ecfd5646032410c8be95c18c59ac805d8075e5807704386bd5
239cf71611fe5e6a3c829fe323d0fa0286eafaffee69a8085cdaf203ed15f7e4
bc9a0d8c86644a7ded8e5da1ecc382a6cfd7dccef79305ea21cd3f27805d8f40
feff0fa7625cbc34999f6d5605506d981ec4ccfd031bf301a0622face17499d9
a9e6569e2420aeddd0f595a6205f7794862d6141ba69c640821819221be78d35
d8e23165183fec3c7ea6c15911586ea9dcbe553873f094ac2667d93bfe0487c8
806f1c1c9ab2b0b209c10e34f47a6cf121bed3d23dc2ca1660fec8fc3118872d
f75840264d34021cc2dc7c5c5b7c4caf93eb5b8098015941e889a84a7de2be90
9db5b9e86e71661d7769316f9ef1fb79b6478b00726b8be14c0b09f7be5b941b
1802fc33f4ace43af977ed8e064c4e6154d23c1f5c737b139ce87a9e9f1a0fa6
27ccd3008a7db4971b410557b6f2712bcf80ac419be2a1861f3f113c52709cb4
9975b81e9f8b7bf220475765a809c03d9462b60f27a06de2b5d867152aca5dad
35a6c90aeed158cbca180d1b3116e6d07cdfdc41731243f01896bec972b99255
b897296b26ad15c42b2194eb6c75fd5a2b91aede9e7b9606acb1ae2bbe3e269c
6930fae092d170045ef16fe16ff486e4232e95ce5092a10c8d42f07bffa0f3e4
602ab5ca721cdfb75b5d4b314fb7eff7523a6e8da01ad8e43d5c97eed35b2127
f9753dd9a49324ecfd5646032410c8be95c18c59ac805d8075e5807704386bd5
239cf71611fe5e6a3c829fe323d0fa0286eafaffee69a8085cdaf203ed15f7e4
bc9a0d8c86644a7ded8e5da1ecc382a6cfd7dccef79305ea21cd3f27805d8f40
feff0fa7625cbc34999f6d5605506d981ec4ccfd031bf301a0622face17499d9
a9e6569e2420aeddd0f595a6205f7794862d6141ba69c640821819221be78d35
d8e23165183fec3c7ea6c15911586ea9dcbe553873f094ac2667d93bfe0487c8
806f1c1c9ab2b0b209c10e34f47a6cf121bed3d23dc2ca1660fec8fc3118872d
f75840264d34021cc2dc7c5c5b7c4caf93eb5b8098015941e889a84a7de2be90
9db5b9e86e71661d7769316f9ef1fb79b6478b00726b8be14c0b09f7be5b941b
1802fc33f4ace43af977ed8e064c4e6154d23c1f5c737b139ce87a9e9f1a0fa6
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.