MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 20


Intelligence 20 IOCs YARA 10 File information Comments

SHA256 hash: e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b
SHA3-384 hash: 98f44f82bfef066efc020942521414e149338c0865f585f8dcbbd210b9ec426acbe15b6b57c7f323c867b5f3086c32b8
SHA1 hash: e460dcd06aa048223ae7af29fae50ec62bded461
MD5 hash: eadbb13e5637bd2dcff47b65051ddf95
humanhash: november-item-montana-ack
File name:PO490102811.exe
Download: download sample
Signature AgentTesla
File size:831'488 bytes
First seen:2025-01-31 03:23:35 UTC
Last seen:2025-02-03 08:56:48 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'653 x AgentTesla, 19'464 x Formbook, 12'205 x SnakeKeylogger)
ssdeep 12288:N0UM8HHZJlZ97dsAQsd91PD+lw1VOgVZojY6k0YYSuk6gRZ6nqANm+MvjDun7:6UMqnjxQy1PiQZzojYwpfgmnqAo9jDA
TLSH T11E05DFD03B357319DEBCAA308569DDB593A11928B014FAE669DC378332CD212EE1CF56
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter BastianHein
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
501
Origin country :
CL CL
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
PO490102811.exe
Verdict:
Malicious activity
Analysis date:
2025-01-31 03:25:42 UTC
Tags:
stealer exfiltration agenttesla smtp

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
shell virus lien msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Reading critical registry keys
DNS request
Connection attempt
Sending a custom TCP request
Stealing user critical data
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
exploit lolbin obfuscated packed packed packer_detected phishing tracker
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Yara detected AgentTesla
Yara detected AntiVM3
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2025-01-30 16:55:20 UTC
File Type:
PE (.Net Exe)
Extracted files:
21
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
agenttesla unknown_loader_037
Similar samples:
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla collection discovery execution keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Checks computer location settings
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
AgentTesla
Agenttesla family
Unpacked files
SH256 hash:
2df08e3fcc7d363c6c3d4836f420088903c2853f8a6243e2d035c40899aecf54
MD5 hash:
fe9b94bc0027a4cb1c82a55191159292
SHA1 hash:
f28fce2bbff4aef4fcafdbe538eb7d26f0b3f061
Detections:
AgentTeslaXorStringsNet MSIL_SUSP_OBFUSC_XorStringsNet INDICATOR_EXE_Packed_GEN01
Parent samples :
c30918e678ef92471a950450fd052eb49cbf066fa37a42bcf9c70b4a7522f86e
c88c132a285ea816d2804c27249cc2c935865507f094c8e73c27f4bfe8a87cf3
40f520059151169261544437b55034ba75964151f2fb4e931b9c5f648672d70c
5f60065f39cfb14defcad05927bd60aad0f5dbca0977a88cf0afe78ff31d5c63
e15f9f1f3757325a4af0c327a602598d1f52fbaee85a0a1e370b7437ac3e9ebf
edc7431f81049c3df92735f6834e59da7a2b7fb3f1c9c7838d0ae4ebbdf86cd0
8c87e92f4606b57b1292de938a18cc24e181b521092b17800f8909eb9e135c13
e08afe506a39a4bb08a3e299b56382cf4c1ef488b723fb45525dfaac2451d2b9
21ea63d0aac1cb7fe26cc9693ba53b931f227bd26c333a622355ab218059fc58
8f4c439db759beb01af1ec4d073406792073028abf8fbca33867396a499ca70a
13e36dd78efbec69aab73c92a926ee54f892499fbe5174442ef912731352a839
4d2b3332bac8fc3295fb6941f27014b6655c4f854ee6efab83b33652cfb463ec
46247eae2879b89ccae5e98acabb802062b6f21dfe86eb604ef136c2bcaf4958
484794d12f8acdb2894d9009c17421bf0b5be491eb43273f35bdf56295b26ff0
96ab76c69460cc8d8a255ff6ba2fa73091856c0730aeab47cdffa43ab8249c12
2df08e3fcc7d363c6c3d4836f420088903c2853f8a6243e2d035c40899aecf54
2e258ed170965c8d26e5e284e9b6f0204b7be36b68dc0221d11f1a446e46e153
342761981c08642199e312e11dfb8584c39c36dcf0d9829398b5de8de6302155
f59249e0421edc3799b01d06dfdfd1877edb5bdf70d777e9aafbcf5570f641c5
2e1d8dd0bf1511be6665ac5739ae946357fd033b2e8bbac18ab1b9495c2eebfc
e30c2f0a1b9801273948018c318bee81a6a202f4c2411682186cd8abd1ac387c
9c5c25534452390522f00bd000ccef1275b398f83e60edd5c1243cd0666e8406
cf3190bc9c7c3db75b48b4e180a511bdfb62942591540f88ddae24f2fa3d049c
4072d54cdf2a168636a24c4063e56694d071dd91d4337f2413d762841d5ed1ea
71150325320f5fcc0563996a9cdf89217e8a743fe3a75e754fca5fda5c86cf67
e47231e1941487788c99975572fc9fdeb6a4948ce8cebde1e3def61ce628fce5
a159bd480f79fa31be7221debd26ef015e4ad69efed117d9b2892554c73f57f0
6819d0ef008f17b3bffc407cbc8e37c43eabfdc39bdb10029afb535f542e4d86
ee4ae0633d4f95d3611693174a516e4a4c20dddaafa737245fd8a7100a49b9e8
21a19482c7a1a678d0797850431815d7778aaf3c76218e154cd36f13062e378a
f8eb4a77eb29f42fb4ea1c255a1aa67fa622a9e5a8f7440cdf8ea8b5eb1d0ca9
169ad5c33acf7a4aae70046eb2ac4e8f60c62c236065c616277b827ea4ec00f9
e1a098790e575bfbdde1957b2287912df823590042759fdf8e5e2adc26857137
9dcffe8f3437c5c785db60eec5594c3b22ebbec969f02de1ba545b3a70a648e6
f84f0208e1ccce6876611ab8d7e4c92f4e02427e9a72283f5346f98bf6539160
4e10c6fe5d0f656aab6d41c6a359bdbf658cafad4866583c8872ed60ed3018ed
a942a5f750e75de35ee750458c6849bf62af8867469873c1ae097a3f6cfd2ff6
5e1482b083ef98d77ee7c436a9b074e942d605a9b4a6f6c93c0eb65c8b82e359
ddcacd894280453eff2a06fed2994e57b701477c7af50d538f43f5c40c37cfdf
b17e991349d87089f0a98094f780531ff8ee0b89a2446aeeecd61eb77b2c5423
f7e3d289131a067c332064bd6f6cb7d336f0fb0476af14eea1d1b1a7127493a9
5ca87353c4d37e66f76875a46235208796dd620ad3cb7cebc6b5e66be55b2913
2581c92f9d54cdec17c02ff7b814ee3f7411c4f7c5e6bd1e4ea95431a1217a37
4af0ad255ce753c34b265d5714681b436ef635cbfc8dab10349ea913547be805
4ac227785c3f1cdd4b05a9d2ebb94e88a4af65303833c4dbfc35113dc21c97aa
24565cd1781c0378bf33859bddd21713cf1b624d2ab697921341ffb2c995e456
9a71fbe977c8db9b96f804494901b49117db817bce171818140629a345b7eeaf
4d62deb9e012ee45a9b2d5c90a15955965957d3c8065b24efdde65a9c8a33b66
d7068c23337a266991d88993f5b73c093a8b864f8f90359aba2026c02a1d027f
56b1b13bbe42015f512de69de47af0abda07316f4edef30f2c1ebc4c5bde5bf2
5c08922622153fcfa1cf05af7f0bdf474c6f9990c4f529742516a03362675cc0
37109eb42fff729d1786ca4b676167f7acaa918a4abaf3bb465cfed6efa2b134
25a1241fa5efb1cedca9c984dce1f39ff7452b18e33b2368cdc830b7abbe3ea6
75d0f8641ab2d7d47457fa1f1eeb338b2aacb9e356a539d18780c273d5a37a0f
78fe38ba9a5ee5fc0156e1d2a7598597f0fdeb85bba64c86bcc36ed9d1d24bd4
fe2ae83c4440daa77bdb1c5951efe680fe1a2e41209ebeba1ae72792d9c9ae06
a07df7d83e05047ef95a78bd47023a60c53414cbf1d6cdb2bbba7ad762675a28
2363d23876a13f38f92ae169c04f2d12bb3ab6a027b4f46f144aef5a02ee0105
68729fae59820aa23f3229fcb7dd8a438d31e3635bf621a1f53a8086ffadbbf8
115fc6621dd995b238916ac8629521d718fb941f0b455f019c85b1a4174f47d2
05d703bba8967b2bbf708b1c91e364b99e6b2b8f18f59fa07c47d4da47e0272a
ffd7d83a9e5fae75ed025a5e148013b4d3e7da5817bc715e4e0451a535d5e507
e967eb5ff57e890dc8aa2bfc44a97c5016fd2c514590be458e21cfff334df6fb
8c7a2e6b92c3db88ad183a2a6da6f523be61e4268782fa03c7bd4143f614ece7
859ce543eead04b946a2d77d7d2a9342cfdfad1698fef1d442cb51fe6429eef2
ba38c374f40119a4acbdab2bc171043b87bae2d299b2628f2a02da87e851c97f
3bd2b14f49671769cc1b82ab8e12b1dfbfcd126a440a58e75feec717f036e10b
dc87604f1d5dc29d3aab245b6384d1886819e53b48118bbcf8df9fdb1b58dcaa
8ad4cfc5910c7367a8d9e92d4a1ebbb02b659abef458d8ee765ac09e3e46a484
493b28fea1ea39199b503c952ab4efaa8fd3ba5a5d5a2d9df0af21d031f3ea4c
348a670a96b8de07cb4c376807d33bd7badb5f747917dfec6f3fbccf7c966bd0
546569a42f00553d7fda79e6961779afadd95ea8e6a8738ef344275f2b642244
9388d14c8bf0df5eb6607f66666d959017e45e01ce0a22b32dc7796b10cd080b
4d25a079e5c17965e6f79e9f47e122aec5b86b5a963525e6c1886d8c7d532e9c
d90ae55888f77f6914a142f25a20a441f6947cc4074f17cf8ecde99d41273525
7fbb218c97b61a5da84737c2b149277bc2d2c06601d891704d16924005379a2f
3372a33e02069a1a01adaf93b869ed66bdc06cb5b886e57c6f81e0243d6ec3a4
b27978ed194861aefac16772c229ff70288f71cc59611679eae88035a6c0191a
269e25fc0e57a2a1cbb6e3f01936142b4c6e8807d7e33960e5e8baf38ef3b631
420e0d791c2e5de27eb45cddb00321f7ba3fb3c2a735bd98d440345d01a7bec8
cf0640554fe636e6ad2983b7c61a4a62e3d368080bef6084024e23e7dbfe9715
7f24d1a1ac882a4e9da16afa9f05464cc7b4a59aa42edd8855543a10319f5be4
03d70e61c415e7a0e2ec76c31cdaa056d05ba4a0c5424611df5b5b69c1415ff9
963574e90ebf7786aaf6a17966441068baeadbce658ddd2f19af9a9f3f34c7cc
42db38678ebdd31dbcab40014ff3b96a8b263f77e8484901226defbdfbb8eba6
ca43a036727274823265311a9995eb0c70e288bd44c5655a0d231ebf108a30a4
836e1a1a93d29eeef8a26fd8001cb5efe017c899bea5c4d404db74cc7e6ea563
165005cb8423f38beba5461a10f3cf5fb69304013b5033463265c5457e48b76d
99da41b6e12ed59550b34c28d2a84eae0a31c5395bd589230a368891d9053159
9ee9ae311878a9fc88d891aeb7282d9633a90bb4f3a8688216fa3e12e4f33bbd
c015ba3cf24ba3b9a60b53b0f36fcf3368296c4951967ce63b3e6a6cfb3e7472
7a67d110bc1f15c95d420969b5ac6a78ae1d3c6d0f7d4e913af4a7db142a461e
4c325803ce0762bebcec3327635377a360e221480c99e1a95b708ed224b22cea
c071e52c0f19cbedbad1c026a30b9a2d5f6268c8e9a742c802f322bff7fcf372
62c012d00a605e319f4b61150151a4d811b80472e91ebc4bdebd5d98035250d2
efad3269d3bd9b9dfea3c1553dde89ad411d4dc850ad2cc9268e291ed3af1c6c
76ee39157442dc28e64f089260ca42ec5374ae2fccb99d0940b9717e48e6dc86
11013cdd71339c3aac7041ef80912c8c03786f5967d58c539af0d560687089e8
2791c4da37ccfaabed34d36c65d373650dcfa6db4cc8f2990d671e1c01cd74df
3420372e13d30995161a73ca1b87f59273f2e9986e6763b87527d91ed53df8ce
137e0a944efefef514d0595cdfade088a59eb12404a1469e76cd024ebdb2d1f1
aa31c3c2ad5f799d3b7d964c05c4a066921ef60aee8b3f96b4c95ba38518c692
8d8331f4dc08f7610760e59020a52423569dbbc5e7b03efe8026917f4905d19b
b612dbe8660225d074563250626237783bfdeedf5bb38d5af1e2789690787fc8
3591cadebdbbaee9e75158d085435cf81ba8cdfc5c92b050275f9b490ee60998
2abceffc33aa61d03182eeed898d402dcbfb1ddca4d1e6ee4b0b0482aa4f3b8a
e834cc0db159080a88d07c5e1c843905f7eb1f3b0b48ad1c5377f159fcb5e5f0
5b2d21f50ea195e247b45b8330c18acfd0f71e146fe40489ee8301c7045daf04
238525043acd0e92e92f6317fdadcb469dd26ef5cd7460e0188a673165ebef84
a43a6421f9f5f7ac6ce878ceff99e594fadc983275f4f2f464341e5564784c70
e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b
4b669a9882308c41461e55b5c429cad387b139f10c73bf23bf4181a6b42544f9
5bf7b4330d2d77e12de0b43fbf876300a792e27fcd01021f02215a918781f61b
128eff6584a219a06cf80b831dcda899a96695f279e039dee81ea862aaadebed
e25b37773835f8846b990e84b23d62fba6130042452a4f43d4a8b3a6ed0c25ad
6a3d938b7100e9c39f7090db739cdf40f4f8e951bc39ead4d7b96c59c387df4f
e9b903a7b8f21807cb8025db679ffda1a2d8aeaa8de550259a7dd287493c8bcd
7dd6e7353eaa5327ca69dff1d7e598b3f36240aeab1efcbda34b295d9418ed15
cece3161c3a7ca97caaa49e774c6811e1f378cdbfe9fb37e17f953da7f8ebd08
36dc014cdc1ee051b88eab111948730fdaaa261506d32e2013a34a2aaea0e647
4bb06d5adcee687a9935287829f07670fc03579b1761163926f8f92c72173295
dd8dde439f81fa4a6c927468424e86bd039b0e7d20ce6bd0b64aace0a4ac17cf
fcf8187bb21250eb6f8bb655b18684b374c6135a2696c0f026da4dd65ea82e5e
ae818fd422d1eba54edfdbb1043f749b9931038157e3db1675d7c17fff3d1169
f532b6d77041027a94bfbc117759218899faad1441e4f60b57197d0a687b9240
2218994e51c15b1b3b403073b062c895bae9704a3255347fcd07d5a0dc4f217a
ef0d48f4ab28cc338fc29affea2e019f1aa34a54c4220b19a13f57f73f9f81a3
a21e5885c3e892eb1f2adec7d093935fa7746ea10ca638b3a00a73d67caddf7c
767aa72294b73ffbe525ee35fccfd5939a9cf6d1128717ac159ee9b9f9adc759
34df432fffd0dff5f4a974f12dd75d405816892e113100f34ed1b3bac7358ffe
fd21ad1a514c00f3cdadb7b6cb1a0414ae3ba4ff3a822a6a1d44857fd65bb998
SH256 hash:
ffb97d9798a95e8bf0762ef3261ec76c3d510e2e12fb1e53a433c184c02dbb10
MD5 hash:
0cfaf885e248d58f7b236e6efdf716d0
SHA1 hash:
b25d9f8855fc09d2aec9882e5d8605e28108eb43
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24
Parent samples :
cabc5d9c4521d4ed396a616015bc0ce4f0a23e287a7dfbbcff504b1235ac4aad
f0e65a838c01e4741493c605aab2232854d22a14d913374a2c61f083b35d7aa7
98a11f5e0943f5a8e0475b4c7d87b5f67a1d39f7c44e564d86df4ebd687686f8
a7a1f53264ca6adf45c493ccf8db7da322b51c094a305ffff264db5df146edcd
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
496183edd167fc6543a66bfc47c6a486eacf7fcafa9149d6d78c590e6d6b3be2
cff8bf19e834f403b7914c1fae20c0089b2a75a29a769c1e46aa3bb234171d1b
19ccabe99d3c6dd06c2c9f3659a7f196afcdaf84af869e573cf3545df80b997c
84c1d9c18d8e90a6e7531688800c148405426d2dba70e7218c9ee34fcf076e9a
06d1d5e5a8e641a62df3b3282dc437d24d48a31cc60f691c760023429788ec6c
0ecddd957a515d3d3ddc583b3f451d56f56273cfc844c13a8cb0b78d10b3c52b
6601f8f872a1514a98b8166c3ba55d63db44d5e9310d00f91ccf770e24742feb
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
5dbde839c07b34a42667935da05d18dbf85e630126ee3c649383a44aaa9b6602
3b1b0c6e463108f7a2f9d683fd69ebb175b10e5662b27cc7e8511fca4157f407
eeaf38c14ff27a1c50d173c3ce5c5803517d8015cf1e6d777c0eaad1eead4af1
6208e1d4a0b694b7d2a70d312f8472b2c2acd0edacbd5a2344199672d7dd84af
c53b13442d16e522db35af6431d5a3d9599206db9975245b9ca90c43d4c4645b
f42de693aaae005ec4dcf3514621f8573b422f3a3ad1bb1af370acc7c5cba233
28a65019d2736dd82fdb229c9e6f5ff053c25e095d118ae03359238f44ba22d7
fcbbc6c9a426352d6a329d9a0a055cee18d66ee62835e3d00499e4ca52761c1c
7c3a286e6c2a9e2b50a81e67dd03ba27e6dc6fa7bc87f45d0e51056252823cc1
8ed16a383adea236fea0ef757127aa5449e223ef29617e0b584286183143234c
4e591799b96dc33af9dba4b19fcb173c9c79da52b645ef063e0f6734b999a91e
d80246672d337713cd5dbae257d6cd81acdbb3b4328141a1bec0a735b9618d71
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
4ef83ac7a3bdee1a742de8de749c5afa4747acc20f8937301dcba291d1ef83d7
2f71acafcf825697cf29e5f93681f9c7128d49fee3e04a20dd506042102734a4
13fd36bd0ad2ef303ded0dac6b7cd6d4326ffebb08ff914eb44a6e75c52e8289
282a05d5e79cd8a8fecb470cdde28f483cc6fa7d70785f6e6e5e3de3dc39a979
89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b
a1333650518e3e435421e28233c84f8a5a1ca03607c5289a01da3f86e4046565
771077ce6d2c6eab4908e19af87680fba3491ce6aa9cf976d82afae3a7cdfa10
17c4031831d4166a50a72b65ebdb2a4825645a3314ba5907f46329b9da9b2a06
55864751fb6be8d2789f4e3789bd2794a9e7cbcf39d472f6a4da1d4ca2f50758
12bd2e88e60fb4e93881164b51c270121034f7ed01bef4ae0741abd8e532d77c
1efe29ca00c9e7c69c46dc8139204716a36b6074647f3ec4fb06e2ac6576d496
4fa5ea6373a2464ae2a7f499d1e19cd27f6506df81bcbde80567b79d7e211520
dcb2bc8fe4ca10f50062e50786e71539aa41240448d652876c96ce970be79162
001abbf49585db1553929901f5cfc1465e504fea17f6ffe78a344892aece146c
0873358f1252f19f17bf03e959386d2c39ceb8b90b7a73d0de11456082c2730e
0c2b52146f60798b2d069e7c660be0a95a9d7a970d75ac489a1dea7e97e441d2
f8259be27bc5c5ab89b1f8101535489f28799ae8c1251fb00aa9ec1d6389343a
e48808b99478ddce1a031afa8094dfc6d4d5002bd012e278e741b5b59794044e
976d5e9ce2356934688e015c90497c08d5334715c5d2235d5d13af314565d3d0
8f41896e69d1f83408cf68e4d6fc56849a6ee6b86145e7cc68d6caed660ac582
a14ecc9756de5e5e89e2f12839750c554f9d6b2e45773475d096d6db1fd92c04
061bc2648b58846a4dc7cc468cbf1b4bcd2be744502ea0775b705b04ef536dfe
60ebf1dc0d303257b79432e0713134f71fc044aa38f2dc85e55d20442c01add3
ee55e7f496b05d9bf98cc381e621483f549f9452d94d6ce32d4f3b59c67bec57
609bc44c18519741abb62259b700403e05cc0fd57b972ef68ca6ae8194d27f2a
4bd0336e60490dc8ede45e9ac7aeacad032fb72e1c4401552a9d4d7d52c09054
34444d4292fb1f61fad6019625d22b9b88868e8af67aa0a84f1319ce8d571f01
a9173bd9c5fcd609d03021f9e23634542691b79a791c4855fbfa248a940eda14
ca4c4cc60005ca88e582734f5f0232099184cbce1effc270fa761367b9029bd0
45aa9c752530b71775bbc59a49604fe2f8f10a3c98be4e3d789d307eebf69b9a
447174dadd9697274ba6e102647bc6847d816b63d91bd0f35d29c5c3a3401ef8
dbf83094e42dc231fe1a1b00f3fe1e4cbfaed8757afdb3d5a166e91d3b3733ea
b3d2c06489759b1433bcf9aa38c9ba9dfb400bbc4ff1deedd960f3c3dd606518
b7ffe514c90485438c522430e88937fa81bc965e74161025eb18f8c1a85275d3
490c785be9863eb038433c2a125ec62809a8bbb25f4ddba21f72772e034f577f
6c2cf6bf017b8e9c8731b0b0bc1ddfd20c14e381d5282832d5646ac29158cf73
c2aa6c735713c7b8141a6f98467fd4a41e72c536dc2d92c591e47b06ba2666b3
079e89bd883be60d3ff2dd26ecf457b181003d8317366f87995663dec23c7252
56a1a9b139520b6c51ac67413d6bd6db87771d1af9d6994290815ad99dd89102
c38b465d0723cfba8e741705451d5b4917f09640664adf5bda6c0e48026c6b3f
467d77d35a6fc815ecbd60b0b320d7ca06e0f8a340c2c3285de4c0430517f8e7
4336ddb80f3875340305306f98bd57efcb38a2182153d71308957167a295c070
d0d2ac5af6ecfdf27de6c45ab86d521294350c5a64942cd15bb5d9a1ae23b0f1
b30e339a7ecbbf9ea338c915cf1e3f8e6b6740b314ef1d08e38b1694e3446163
737981c73007c1fd4dc3cf2d9a5c79cb004fe48bdf3cba06b4ead50b3a57af13
389d68ade0d98fb86548dc560ee291397729e0474a0fcfd3299c9d534e6f1234
205e98d299b32e102e3d6fadb9659f713601f8f713be02cec1ec0f437d3be075
b8a1cbfde7cd26809f6a8a90d88d09c0558fb2417dca15d7edd5e3eac3e07073
6cdcf78d540c146fb0319b5539d1bf930c2e59c42ea8953066c648a0b65ae460
a91cf2a4699e93a3101762f542bf47b51d8ac09f8e78eaa2222c36807e0c0e72
565dd0687c5447e3714250520bc29577e6516b8bc597067ca0dff05274896b4e
b35f831b82f4648f91b37d8b8799cb26d30b069a52cf12e14ba9b4c06e8fb571
9a71da6c174ed01e2bb5fddd7bc7d2ff7e6a988b8deecd05c6935373192573ab
8b25b0ed0e18bb24684d10bb3afccf6e6290c95e89a79733914117e2c7b46b09
6a19ede919d3ef32c74ddbcefb4bfd3ef61ba2a86739978ed337639193678edb
0cac75f1f61f9fcca09695de695e469d62f7e73147ba678f7d6dcb4eea80389c
75db64719f3225f1e42a86bb7cca56871f757076f81c42802e22a83629ac4fbb
a50041a2a0cccb573e80cb188f35785613ac38230cd4d0031f738855446cabbc
c2d06459896ee441feef919813800bc4f9c382ac08e28103bea73b675e556ab3
27e9c5e774bf0946e99a7f34d14ded33ca1c236765fbcfda83e234d70d15c652
5b2a4d07425414d3e00bfe400df7cf20526f32e9b29f4b7eefb07ddc38720a15
a883ec7d3df1913ccd847c0ab5d521170adb967cb09cd5b3845e04b50aa4240c
b8dbf3db5d56d847b13c3e517dd9e9e396038948ea1189e7f57c419f493c368c
36c3f143edb273d0d6cd6738e0357ddc19b86857de46871ba96bcb1a8256b1ac
35bba0cdd40a31e401d3e668676f3e6b5c51ea9bd4850e46a6fb0b391862838a
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
774b328fd5904bd0a7d3954bf9321948b43dcc3091db995c27fe47e360d2b7aa
16a43aa836bfc334a9c67a4a6cbd25aa461b9332b7dbc5271afd75119c2a3521
42a78ab84a5fc43e1b379a2968a32f272492c860f0602649d25374d521b4b83c
a689d2c7fa2cc3712ff115a0dce0cd90c5d55c92bc87e7f24dcd05ad4a38db63
6f706398207b1fd3a00de5f859dc840cf8e100175fdabe260ebb96db5980f03c
10a5c29d6a44de5b996598f71820bff8c29cc6b5229d2c7ec0664b601d81068d
640cd2bb3f4726760684d6e3a5e56e28e37860c7d377fd18e1f428d31b47a468
4c9850cad6a1efce3f23362ff3f68fe5fee556e3e344e867f16ac821701e90ad
629e839dca37071336e2ffd8bd9250443eea5a18cc317a0edc85a3d4aa59cba9
6c8c1ce5b36a379f6fd545629aa03270575b179e4194c31f6db163bf06de6cc6
000131c03f015a78307daa5d0d21c2fc6b286f54a51b5ad14b237433e77b3ea6
ef9f3bb8a6695a4ac654b7218954695432faf87784d5c78f8d237a4532a466cb
fa3e852fa9dde2dde0c1e2254f81059f8c2f1088596e0fb9aa2e37583c26ead5
42bf798312044d50fdcd35dca04eaa7bf628fd71e876fa6fa33b95e593d7526a
94fbf90615b1baf84da26854c9c7b72115eaa12eb8392d898c7689f433980120
8b0f47fb5a7f509e14dcbc3eb94ed4d09602236123147012ef174701470ccdd3
10b78bea9f7acc71be5868fb39e4941c06ec08c4b0ea25b0957ec6b63fe37e20
1e1cda620f33f8a4e039351b55ea841fb09e0212ca2dd44cbbcd52fc88ef8f61
a8c8535f49c3869518e9d62f95086e5ac36526ea61d4203aa8d2077d33ae9faa
31c25e01cbaaeadccfa1321680bbfd51c17b876859be87fff22b2db8ee1e117c
e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b
6dab8b138cc6efc4956d434d6992307f17faadc887bb3829e950daf8bfd5f46d
14ce31b551f4f39bca04ece6143ac80a3943a957d9a6056c88b6857daf60b784
683e3979cc09db086095cbe840901b82951df941ed461f89a67b98bd0ffe5ff9
342a6c5178eacedd99cd66da3bd81e767d0aa311441ad2089b087def3f5cb088
36b2c227683d3aea101fb59edb33edb1ba28ec0753a32a5ce42b1959d6716965
88b2b7e8b37a44b6b3ed65362a01936ff5500ae073ccde2c6a5c51b0afc05d94
3600d33c7e14a371b391e1e949a16454a26014007dca981bdcd177dbd234f797
1e90ed469f2242b4882864a20ab1357789b1851f14074cc97a263ddae613a53d
b58a7d4bb391ebe2243a86ea92641445e98a4da3e51abf3d2c905fb8ac0dd9dd
19c81289b55d23365b8c4f7c6f951063b3aa05c10a4d8025dedd0893903fcb59
c95f3abb8db4e2a88ca3d533b42608b4d466d70e1e92fab9d234e6afb6ffe011
7fc8b3746ac1a4ce5a1b211f56034656c4017aef413aee72b0884ad5f0a94054
676528e924dfe6e5e119f33ac5e7e8ee5661f871759e4b32ac27b0a1d243e329
60bfb47f60c7f0a6aa8185734c85849995f497117e38ba2c2e9fdeb1330b0cf1
12cb84b318ee85c5d7b4ec15d5f6fb2c26a43f93c68e98c6f40c2e2b17bcdf65
5dc75fc4ff5d018e6f56ed3f2676781e2ae1a341a878ee5ef36513376b75a310
0d6a9673eb3db83be393b8e85fceb372b5fbad79ce1c56bd92ea4b6b3166f657
cf8609a0bf3ca9ed3e5e39abab534229213e4df0316cd0478032cf59e0f2f3dd
0531f60ef00a3998d4932da7000a10630fae4b355cb81db091008f3899e039a8
0b9d81ffc7bd0ddeed01b5a0adc279cd4a79003ce9253fc7e096fcdc63ec371c
004de56c87ec09f1022747d6713c26328397dec1a683f76aa178a48da776c82c
543a5190118c546db54b03846c3927a4cefc69809b5854fdd0fecf1763dfed2f
ee6be21c96c562717375ac6d428d00777826ddd74a59b8a1559eb353950f5d93
5c7dfeaaab049b0c4a2b6fe06c7d6d8d54202ab9b5ba637b73faa01bccb5debc
0f5ddd1e5c66b90c7a37c276228ef498be1297d5cf3823afd72b0ad08b08987a
e0f397c466a112a3c04c99cdd5a1fbacd2131a90d520d5245f5d0a2336e53233
8032eec5f8978a6eb901f96583472cc3bef407b41a3357ec253b8204305b69b2
b9581e9af28f052e463acd6117271db974830bba5a7ba5825068596947e872bd
0fdc25f5430a61cd969c0bcb2e5ed6965d4eb4dc73374649eeaf5a6b77498d6d
SH256 hash:
0301f3e569c6dd0d6419d6cfef1ce16a849a764569f6d623e5eca754f0abdcff
MD5 hash:
e0c71643ecc070e616562addee865505
SHA1 hash:
12cc5fbfd38aa779d2a547ee4ff9aaa5576e2df9
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b
MD5 hash:
eadbb13e5637bd2dcff47b65051ddf95
SHA1 hash:
e460dcd06aa048223ae7af29fae50ec62bded461
Malware family:
AgentTesla.v4
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTeslaV4
Author:kevoreilly
Description:AgentTesla Payload
Rule name:INDICATOR_EXE_Packed_GEN01
Author:ditekSHen
Description:Detect packed .NET executables. Mostly AgentTeslaV4.
Rule name:MSIL_SUSP_OBFUSC_XorStringsNet
Author:dr4k0nia
Description:Detects XorStringsNET string encryption, and other obfuscators derived from it
Reference:https://github.com/dr4k0nia/yara-rules
Rule name:msil_susp_obf_xorstringsnet
Author:dr4k0nia
Description:Detects XorStringsNET string encryption, and other obfuscators derived from it
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:Windows_Trojan_AgentTesla_a2d69e48
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments