MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4f365f9895e6d8dc8975922386052ec3727a9f24ff147559f54d529e447c0b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 2 File information 3 Yara Comments

SHA256 hash: d4f365f9895e6d8dc8975922386052ec3727a9f24ff147559f54d529e447c0b4
SHA3-384 hash: f9a1651eff4253809e1569a66e58d17a355793a654397f996b0f1b7e414516210c43e608ced509c33be71f275a8ce166
SHA1 hash: 355a9fae7eb5042e02680d4d9138f55681e3d203
MD5 hash: 971b524b2a3ae1adf97deb2456c8a15e
humanhash: mirror-seven-uniform-timing
File name:New Order.exe
Download: download sample
Signature AgentTesla
File size:398'848 bytes
First seen:2020-06-30 13:03:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744
ssdeep 12288:ZZyumETfzuOhW3BtFqf992ERxWnN058vA:ZZyumAqOUg92ERQa
TLSH 09840231232A9736D6BA9B7074B250100FB6BE1B6220D35DBE90B4DE2577B405AB1F63
Reporter @abuse_ch
Tags:AgentTesla exe

Malspam distributing AgentTesla:

Sending IP:
From: Golden jewelry LLC<>
Subject: New Order
Attachment: New Order.rar (contains "New Order.exe")

AgentTesla SMTP exfil server:


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 28
Origin country US US
CAPE Sandbox Detection:n/a
CERT.PL MWDB Detection:n/a
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Kryptik
First seen:2020-06-30 13:05:05 UTC
AV detection:21 of 31 (67.74%)
Threat level:   2/5
Spamhaus Hash Blocklist :Suspicious file
Hatching Triage Score:   10/10
Malware Family:agenttesla
Tags:spyware keylogger trojan stealer family:agenttesla
VirusTotal:Virustotal results 18.06%

File information

The table below shows additional information about this malware sample such as delivery method and external references.



Executable exe d4f365f9895e6d8dc8975922386052ec3727a9f24ff147559f54d529e447c0b4

(this sample)

Dropped by
MD5 9b855149dc47552b34c8e9d4f1bbb33a
Delivery method
Distributed via e-mail attachment