MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e94d3dbac302cec8077e7c26c41eee04bb85cd85132571896c2688e9581906eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 15
| SHA256 hash: | e94d3dbac302cec8077e7c26c41eee04bb85cd85132571896c2688e9581906eb |
|---|---|
| SHA3-384 hash: | ae63ea489e788ea32bca067c10cbc6079504952d3ee63ed97c26d816fc98403b134721071bf44df145053ecbd8844d92 |
| SHA1 hash: | 183c394def77743e83a668a86835745306a70286 |
| MD5 hash: | aed3d2c35a9b8f5f0b48f632505f2621 |
| humanhash: | two-beer-red-may |
| File name: | Payment Receipt.exe |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 699'392 bytes |
| First seen: | 2024-06-10 06:15:36 UTC |
| Last seen: | 2024-06-10 07:18:19 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 12288:03XS2iNStcYo1AlmY6f90k4NTrL9EHAQIY6Cmu3cWkFbYsJs9flL5K27dm:0HS1Mc7OmY6fOkiTrL9YIYZ3UYfd5/7 |
| TLSH | T112E4230677B99B31CA3223BD9968036013F4765A32A7F38E1F85E2CF25767444942BE7 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Reporter | |
| Tags: | AgentTesla exe |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
341314b72f568feae0b065d49222be752ff92e3d25399a93d9bfe5f15036c65d
0220e969f9fd1e5cadd143f94dc7fdfe26971096227ff4005a8bf96bb316c4c2
97d42ef1fdf9118d5c3243aa8fb834fe4e638578608df42cdcc0f1fd27261fec
e94d3dbac302cec8077e7c26c41eee04bb85cd85132571896c2688e9581906eb
55609db05b1043ddf05d059bd27df6dbd6f2d2a27dee393adf5e09f24abdc1a3
c1797b46a71297b18f605474ae99f1397a965cd2fb18a646f1c2c4eab4144333
c0283fbd112b82707e6d545310fdd185ad9a2e45e6376666a3688d887ef5fcff
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | AgentTesla_DIFF_Common_Strings_01 |
|---|---|
| Author: | schmidtsz |
| Description: | Identify partial Agent Tesla strings |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.