MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e38724644ed4643ebcdea6b0ae8345bf094d9f6e6d81b0acb244f96a3129077e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e38724644ed4643ebcdea6b0ae8345bf094d9f6e6d81b0acb244f96a3129077e
SHA3-384 hash: 8d633bd6b35cfc9e7488676ee0cc0bf95ec00d56fd5ed921445cf57223f04aad488994b0caeefba8d076de4cc1000f07
SHA1 hash: 4426a01bbf8c6670fb884ea6ed87923ccbcd025c
MD5 hash: 1d89655e3611bb3ea501f60433beca36
humanhash: two-oklahoma-finch-alpha
File name:e38724644ed4643ebcdea6b0ae8345bf094d9f6e6d81b0acb244f96a3129077e
Download: download sample
Signature AgentTesla
File size:483'932 bytes
First seen:2020-03-23 16:26:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c127345c03c7eb109783c6cc61e16834 (5 x AgentTesla, 2 x RedLineStealer, 1 x RecordBreaker)
ssdeep 6144:wMVvXALwo+TVPHJb+5/24R8g7SZIEIB622B01hw3IDU8nIxxBcNPMrBsOGKXZY35:09UPHFtNcSZIEmtxnIxxbrBsOccKr
Threatray 262 similar samples on MalwareBazaar
TLSH 14A4E113B2C08072C57389341AF9D7B2AA7DB9201B145E5FC7995F6D2E301E0773AAA7
Reporter Marco_Ramilli
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AgentTesla

Executable exe e38724644ed4643ebcdea6b0ae8345bf094d9f6e6d81b0acb244f96a3129077e

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high
Reviews
IDCapabilitiesEvidence
GDI_PLUS_APIInterfaces with Graphicsgdiplus.dll::GdiplusStartup
gdiplus.dll::GdiplusShutdown
gdiplus.dll::GdipAlloc
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::LoadLibraryExA
KERNEL32.dll::LoadLibraryExW
KERNEL32.dll::GetSystemInfo
KERNEL32.dll::GetStartupInfoW
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::AllocConsole
KERNEL32.dll::AttachConsole
KERNEL32.dll::WriteConsoleW
KERNEL32.dll::FreeConsole
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleMode
KERNEL32.dll::GetConsoleCP
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryW
KERNEL32.dll::CreateFileW
KERNEL32.dll::CreateFileMappingW
KERNEL32.dll::DeleteFileW
KERNEL32.dll::MoveFileW
KERNEL32.dll::MoveFileExW

Comments