MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 daba3f01e6f2ca65e4e6191621866daafbf3cbf5325d15ca3d9dcbf71d061ab5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 15


Intelligence 15 IOCs YARA 5 File information Comments

SHA256 hash: daba3f01e6f2ca65e4e6191621866daafbf3cbf5325d15ca3d9dcbf71d061ab5
SHA3-384 hash: 990bb9f95aa2b2360fc6c957bc7a4a7eef0fe7eeaf20f9a9a43520dcd9a4cf6f339703a7607dae05fe24eda0a5d3023c
SHA1 hash: aa029408da44349491731bad2a6bc726447ea820
MD5 hash: 83f412e872598e61f6f99fffd7878b67
humanhash: uncle-july-massachusetts-cola
File name:daba3f01e6f2ca65e4e6191621866daafbf3cbf5325d15ca3d9dcbf71d061ab5
Download: download sample
Signature AgentTesla
File size:1'334'784 bytes
First seen:2026-08-10 14:15:28 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'190 x AgentTesla, 20'337 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:2V/zGwRYf5DbQ5uhAvzEfCqF6Z5U+/+tOZem3x:EOfFb+XaCh9/UOk
TLSH T199551214A354E713CA9567351AB0F2B927B81E9EB912D7025FD8FEEB7932B024C14683
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon e09a981c04820182 (4 x Formbook, 4 x AgentTesla, 1 x PhantomStealer)
Reporter adrian__luca
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Launching a service
Launching a process
Creating a file
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
explorer lolbin packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-12T23:29:00Z UTC
Last seen:
2026-08-10T10:57:00Z UTC
Hits:
~1000
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-13 02:45:42 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
25 of 36 (69.44%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection discovery stealer
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Family: PhantomStealer
Unpacked files
SH256 hash:
daba3f01e6f2ca65e4e6191621866daafbf3cbf5325d15ca3d9dcbf71d061ab5
MD5 hash:
83f412e872598e61f6f99fffd7878b67
SHA1 hash:
aa029408da44349491731bad2a6bc726447ea820
SH256 hash:
7a09d4c71af5d34d449fc0ba91c8993492828bc5d6a1a3300c3f27df63c56e28
MD5 hash:
acbdef84097e8e77e2fa56219b88e479
SHA1 hash:
1d0de023f006931d010e601ff392b6621279ddba
SH256 hash:
bb9d42dccaa99b188cd5840910520e657071c75e125df6b35ebe2a0829a2ced1
MD5 hash:
6b69500e31384ef269dda1019db02ffd
SHA1 hash:
9d23ef50b263a4355e977041ce2d2520ea4e1d26
SH256 hash:
fcfc657b95c5c25e120a39e3f409ad241ccb0513747d3ad181f23564b16ddf4c
MD5 hash:
655efb3617bf499d3736f7ec59f7d04f
SHA1 hash:
db1da0ecd578b59364e41d4ac267cebc52cbcfda
Detections:
triage_net_infostealer_wsh triage_vidar_infostealer
Malware family:
PhantomStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:test_rule_vldslv

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments