MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e5296b1cf10d1109d50eed7d8d04681ab1cd2b5f8f4c67559205f732979e1ffa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e5296b1cf10d1109d50eed7d8d04681ab1cd2b5f8f4c67559205f732979e1ffa
SHA3-384 hash: 9d4e47473dc2f758a575fb2a5a61affa6b38d586d0ef6f210018730b6622a550dcb26516b548361f0e8ded6a3e6157b8
SHA1 hash: bced7cf4344984cd03a00765822701fb5b6215cd
MD5 hash: ef075d6061e2e18872452a083a6c7250
humanhash: hotel-pizza-wolfram-sad
File name:ef075d6061e2e18872452a083a6c7250.exe
Download: download sample
Signature AgentTesla
File size:994'080 bytes
First seen:2021-02-19 10:16:08 UTC
Last seen:2021-02-19 12:16:31 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:3h0nEGn+Tmks0njxoOG/mJYERIXxytUK1Kpmcw2s/jmEBACUookDgfWll2TzX3/v:g
TLSH 072510652F9F525CBCE3850EE5427D672E4DEB0D839B64E1093AE381FB030113D56EAA
Reporter abuse_ch
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
136
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
e5296b1cf10d1109d50eed7d8d04681ab1cd2b5f8f4c67559205f732979e1ffa
MD5 hash:
ef075d6061e2e18872452a083a6c7250
SHA1 hash:
bced7cf4344984cd03a00765822701fb5b6215cd
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AgentTesla

Executable exe e5296b1cf10d1109d50eed7d8d04681ab1cd2b5f8f4c67559205f732979e1ffa

(this sample)

  
Delivery method
Distributed via web download

Comments