MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bd6f2b6c65e5e3b5385eefbb2cb768e4f145106885dff956cf56815134550df9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 16
| SHA256 hash: | bd6f2b6c65e5e3b5385eefbb2cb768e4f145106885dff956cf56815134550df9 |
|---|---|
| SHA3-384 hash: | 576fd3cc864458fbbccfb5e8a2c1e586943085798ea0b4c3b509e328c9dfb830e4db32a4bd4fc559b982f41719d07b66 |
| SHA1 hash: | 140793cc9721aae620cfa86773ef66adec446ff7 |
| MD5 hash: | 3f1e7c218e389d146a7e07daf48730ac |
| humanhash: | fifteen-charlie-echo-tennis |
| File name: | Cevre10.24Enstrümantasyon.xlsx.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 650'240 bytes |
| First seen: | 2024-10-07 08:26:11 UTC |
| Last seen: | 2024-10-07 09:35:25 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'461 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 12288:1f09Zi1C/T1CsckFRYff1TVxHeeaBkqqJTpqZp20wB14xj:1FLckff1TjHeeaB+gp20wB14 |
| Threatray | 1'777 similar samples on MalwareBazaar |
| TLSH | T165D4236C968DDB21D2892B73109520496BFE060FDD76D35E3CD114FE8D9BB240698F2B |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
198ff208a336939bc2623042646023f39ef7d0d39f1eb7ec4fe27ac3caef404b
ed8a3593d056c5afa99fc4331390b42645b3800fa98e5b5e0089f7e3260ba283
28cc41b32461784fcf2bcb6d66d4ad44cdf10edd2dd8d2b2712e901d1d44ce99
21b046d70a17b53ef0fe65babaf531affca080ff22a167f5c38393f6534a47d6
aa667be19c861a59464088524698c0097d5d8a461bae61f3c5c99b4fcaef4838
88fc5d96ebc31042f41c8d80e87a1d6b8c4fabe33f11717dbf417f969604af70
72629b026d1626923f7d3280d0dabb7c1a9ee869b7ce9ec2f02c949544c8326f
a2cdc2f4fcad4c6b982674a1b3b86a0f7bcdb7c8f18c1183799d70777c726859
f7d4eed71f2bdb8ac845990506c335bb64af5877df1925794b000d4a7cf88b84
aa607c36d804e2544b7816ca4cbcfaba72506fbe5f801e7f07d5a9719c9bc633
c7ee9124f10a69564f9f096cc641aaf1c005a5270c8b62781ab71ced91a941d2
6841176c0e46732c3886f7908a5adf77a6d6ce1327268a9fcb7f2c0262132e41
bd6f2b6c65e5e3b5385eefbb2cb768e4f145106885dff956cf56815134550df9
ee68537c1249686c83087d4771e9d5b6b6888a48fcdaba7b450fc7541e0331de
7a6d0f4a00f827cf525de3d0028ffc70e2114315bcddd1298a719ddf74eb98d6
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTesla_DIFF_Common_Strings_01 |
|---|---|
| Author: | schmidtsz |
| Description: | Identify partial Agent Tesla strings |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.