MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc7c80cecd3050d7a710b2a6795e2c8dc02031c70a36fd4bb892850192718c95. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: dc7c80cecd3050d7a710b2a6795e2c8dc02031c70a36fd4bb892850192718c95
SHA3-384 hash: 62e9879eacd6c72daa1540cc7ff222b436edd63299756486801f698a26b6796dac8d61a6758b32d57e669b260cd3c0a2
SHA1 hash: b2932e2b8e7d2f528686b5c4175a406fa05e0cf1
MD5 hash: 5512d3512550df8907620f92b88152dc
humanhash: mountain-charlie-nineteen-glucose
File name:Product list, HS Codes & EUR1_pdf.uue
Download: download sample
Signature AgentTesla
File size:61'829 bytes
First seen:2026-06-09 08:06:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:XZVBg89lsoyBYmpJYTDo/GJVbQC/ACx3c2OSD+ltFmreICoR7vttHtavACb2bcun:uQl2/4DwGJ9T2SDSe6ICSvt3PR11jX
TLSH T1EE53E0147C8AE9907B9ACD6E0C98E40CC3F6CAC0E9BAE14F6007681B4C75DA745BF579
Magika zip
Reporter JAMESWT_WT
Tags:AgentTesla ftp-fibrasanchez-com Spam-ITA zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Product list, HS Codes & EUR1_pdf.hta
File size:4'025'887 bytes
SHA256 hash: e28fd6808318372522dcb8a7961c38b4ec81db38893d4a098b21b0a7fc90e244
MD5 hash: f39a616469254c04bfacffef89f7137f
MIME type:text/plain
Signature AgentTesla
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
stration shell spawn lien
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade repaired
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-09T00:36:00Z UTC
Last seen:
2026-06-10T03:40:00Z UTC
Hits:
~100
Gathering data
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: PowerShell
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Badlisted process makes network request
Family: AgentTesla
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments