MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf44c19ab8acf05c3a655a0465eee24baf1c9c6196617a5b022a84bdec62caab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 18


Intelligence 18 IOCs YARA 5 File information Comments

SHA256 hash: cf44c19ab8acf05c3a655a0465eee24baf1c9c6196617a5b022a84bdec62caab
SHA3-384 hash: eec2a8a754a02498d7073833a9d630500401a9742c5eabfaa12ce0b442c5562ff47ad440c321bbad4a3edcebb8c63599
SHA1 hash: f54690a17ca7dffa67279cdce5f8ddee887bdfe5
MD5 hash: a6ebb23ea2c2e1b3b1deeebad13e97e8
humanhash: item-cat-neptune-zebra
File name:cf44c19ab8acf05c3a655a0465eee24baf1c9c6196617a5b022a84bdec62caab
Download: download sample
Signature AgentTesla
File size:929'280 bytes
First seen:2026-06-08 09:23:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'066 x AgentTesla, 20'015 x Formbook, 12'352 x SnakeKeylogger)
ssdeep 12288:hnxX55i8E0VN98fVc3gxpHnjeThajkk3CFEu6bmqcqxICz5ON/QA/OYRku4aVJ:hnNri8nVYfK3gzOajkk3Cmu8Vpo76E
Threatray 3'558 similar samples on MalwareBazaar
TLSH T16D1512892A0AD402D89B1F741C61D5B5233C8ECEF662D607EBCE7F9FF47AA501552382
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
snake virus micro smtp
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Reading critical registry keys
Changing a file
Stealing user critical data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 krypt packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-08T07:30:00Z UTC
Last seen:
2026-06-07T08:21:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Trojan.SnakeKeylogger
Status:
Malicious
First seen:
2026-05-08 10:22:11 UTC
AV detection:
20 of 24 (83.33%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: AgentTesla
Unpacked files
SH256 hash:
cf44c19ab8acf05c3a655a0465eee24baf1c9c6196617a5b022a84bdec62caab
MD5 hash:
a6ebb23ea2c2e1b3b1deeebad13e97e8
SHA1 hash:
f54690a17ca7dffa67279cdce5f8ddee887bdfe5
SH256 hash:
4858b267a3852e6ba018463496c67828b3f7e82c35623bcf0463e85c925dcef1
MD5 hash:
2afde05fc661f77eb84d616d532486e2
SHA1 hash:
3609f377cbd16567cce0cce533a0bd568ff25522
Detections:
win_agent_tesla_g2 AgentTesla
SH256 hash:
855c4c2b10e40b27db8c810915546cbcc1ee9c67c26285f1006e13e9aebeb4fe
MD5 hash:
124141286376115b621d3295ed03e2d7
SHA1 hash:
8fb9760f92c4fbeb253cbf2281e11a540855f3c3
SH256 hash:
caebf12cf2229d84b4fabdf412326d127d2d9fef20e6ec54198ace170e5110e7
MD5 hash:
0d7d14bd5d98367a66ae34fdaefefab7
SHA1 hash:
c6e7e12d4f2ff0a7faaa92d677b88633bcd8ebcb
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments