MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0d0e3f9a28df777219c7d6b73a45cbabba0de1b42878baab0ef1eacf5378c53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e0d0e3f9a28df777219c7d6b73a45cbabba0de1b42878baab0ef1eacf5378c53
SHA3-384 hash: 3f40ee597062460cf85af0903104b7cd12831ddeaab68fefd4b77481fdea17a9e77f7e0a833729fcd3d2a07a414dd7fe
SHA1 hash: e4edc6afb1116fd4a3e017c90a093cd5448e7559
MD5 hash: 5d3a1586b35c940d8cac02963e0d814e
humanhash: maryland-nevada-edward-virginia
File name:E.exe
Download: download sample
Signature AgentTesla
File size:1'133'568 bytes
First seen:2020-04-14 20:40:27 UTC
Last seen:2020-04-27 13:56:03 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 24576:ZnRDOjeT6VxS/RKBS16ATUAVMbWXEQwl5beU07X5HTolER1YBRl/A4/ElRb:Zn5UeTcS/RKBS16ATU4MbWXpI5beU079
Threatray 10'525 similar samples on MalwareBazaar
TLSH 103545BB4E6550C2F37A3AB90CDA7D8BD3B055EE3D8067C6D19C5BE928522870786730
Reporter Racco42
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

Executable exe e0d0e3f9a28df777219c7d6b73a45cbabba0de1b42878baab0ef1eacf5378c53

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments