MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 18


Intelligence 18 IOCs YARA 18 File information Comments

SHA256 hash: e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d
SHA3-384 hash: 14a1680ef01b0de6bc8a48775d49025a941a1b66b2171aa89a882dc2347f7dd37594f2eb7b23d3789aa141b774cdba68
SHA1 hash: 63e2a27477464dd47be6adc8bebff726baf05934
MD5 hash: 4ca4bca71255da3556cf6a8f2fbce88d
humanhash: march-floor-stairway-table
File name:RFQ No. PO414501New Order Inquiry.exe
Download: download sample
Signature AgentTesla
File size:730'624 bytes
First seen:2024-03-13 07:24:20 UTC
Last seen:2024-03-13 08:24:06 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger)
ssdeep 12288:MHwgZPR0O5cY5XQ8lwWg08LsUIHZzDCEyItTIUuJJ3NJH3TYQr4Brt5vHQt1fYAw:0ZPR025XQS8LsUI5qCNI74QrwRHQHYmV
Threatray 842 similar samples on MalwareBazaar
TLSH T17FF42388A175AF33E425BFF3AC73F5B05B323763B599C96E099471C466F8B00C166682
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Reporter lowmal3
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
363
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d.exe
Verdict:
Malicious activity
Analysis date:
2024-03-13 07:25:24 UTC
Tags:
evasion stealer agenttesla

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Moving a file to the Program Files subdirectory
Replacing files
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
AgentTesla
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Check if machine is in data center or colocation facility
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to log keystrokes (.Net Source)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected Generic Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1408001 Sample: RFQ No. PO414501New Order I... Startdate: 13/03/2024 Architecture: WINDOWS Score: 100 42 mail.wecaresvc.com 2->42 44 wecaresvc.com 2->44 46 ip-api.com 2->46 52 Found malware configuration 2->52 54 Malicious sample detected (through community Yara rule) 2->54 56 Sigma detected: Scheduled temp file as task from temp location 2->56 58 15 other signatures 2->58 8 cjsumKJ.exe 5 2->8         started        11 RFQ No. PO414501New Order Inquiry.exe 7 2->11         started        signatures3 process4 file5 60 Multi AV Scanner detection for dropped file 8->60 62 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 8->62 64 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 8->64 70 2 other signatures 8->70 14 cjsumKJ.exe 8->14         started        17 schtasks.exe 8->17         started        38 C:\Users\user\AppData\Roaming\cjsumKJ.exe, PE32 11->38 dropped 40 C:\Users\user\AppData\Local\...\tmp7349.tmp, XML 11->40 dropped 66 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 11->66 68 Adds a directory exclusion to Windows Defender 11->68 19 RFQ No. PO414501New Order Inquiry.exe 15 2 11->19         started        22 powershell.exe 20 11->22         started        24 powershell.exe 23 11->24         started        26 schtasks.exe 1 11->26         started        signatures6 process7 dnsIp8 72 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 14->72 74 Tries to steal Mail credentials (via file / registry access) 14->74 76 Tries to harvest and steal browser information (history, passwords, etc) 14->76 28 conhost.exe 17->28         started        48 ip-api.com 208.95.112.1, 49705, 49709, 80 TUT-ASUS United States 19->48 50 wecaresvc.com 103.138.106.17, 49707, 49710, 587 ABOVE-AS-APAboveNetCommunicationsTaiwanTW Taiwan; Republic of China (ROC) 19->50 30 conhost.exe 22->30         started        32 WmiPrvSE.exe 22->32         started        34 conhost.exe 24->34         started        36 conhost.exe 26->36         started        signatures9 process10
Threat name:
Win32.Spyware.Negasteal
Status:
Suspicious
First seen:
2024-03-13 06:50:28 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
14 of 23 (60.87%)
Threat level:
  2/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla keylogger spyware stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Looks up external IP address via web service
Checks computer location settings
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Unpacked files
SH256 hash:
c10c9b0882bac6f788f48b4dabe3291b14e639e650f2b9fcb0bc174ac92ae02b
MD5 hash:
7c7fb6daa78beb69128991ff893143ed
SHA1 hash:
c01bb99984b12b84129db80eae1d5d8341a358e2
SH256 hash:
b71208861384226004766dd5592edbb76a9604f93e5dc8d75a2424e767bea1ac
MD5 hash:
22e99efa3d44c1ec354e377b8e27faee
SHA1 hash:
9287e5db8d85112a1986f8e9928bcddfffd01b0c
Detections:
AgentTesla win_agent_tesla_g2 INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients Agenttesla_type2 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL INDICATOR_EXE_Packed_GEN01 INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
SH256 hash:
092a0935fe86ce7a62f42f5f0f614da6ea8c7df02a03e7c59b02651afb98232f
MD5 hash:
b2daa4c9b3e8093f53fd2aef210a3364
SHA1 hash:
4c54db4c22af4435ca12085e3f82b6ca0486390b
SH256 hash:
e6b25e7250cdd5f75ec51545b9105bdf202d880898ec9c4cd75c131d9262e1d0
MD5 hash:
0c01ecddd3880a71ee7b626706813efb
SHA1 hash:
37eecee4ca36bb984095155b6a3a2e640f452e0d
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d
5cab510258dae33c18cd23924daefd7501ff7203ba9816704a2b0ca66508c56f
0aebca1aecba63aa6205a90f467e4c6ffb86efd928bdd7e3d7ba453eca8ffc00
af69e50524ba63cfcbaaa2de4d15434743f2f34239ad34228e4eadde55bbeae6
fc8a9c0e62e7e7df74d0d59bed35d720aca7a47021f8c55bc1bcc32fb3075a94
6a7c6a729d852d01d74832748b6571bafaefcd0bd12aced32e4fa88166af8817
9ca2b5622a36e207a1d11a748f637920d4f96d88e34b2dede0840bcce07f5788
4b39adbf8d3a4e2a5793014b4af4a4cb98d3a71c4a565dd20dc3a69928a84c72
037c7011889e43ee7456a314fbfebcc3d7abbd96aa509a34babc0d832681013f
664db26a69e4b1efb10289189887c35558bf7ca966eed02f97e523fef83f1205
fcac462e70c7009c1c8dbc15dffea8e0b8ff141fc94a95581c306d995a2748d2
2b3114ee08fb8a720819c749b1cbd68f5c8119073f34db958849b1d3eb1bdd9d
bdd4ba2aedeeebd368997ceb0a5c0372959181a08f1e5aefb4b437609630bdff
f4cefaa54034c3cfd9bf223520e2a5876ec1d161cb4a68b6b7d3e9fe892b087f
24c2781350cbe7b9de07fdd597275c2e2dde39fea4eaf007d00610044376de1f
f79941668c6679c1f5770816ce7b68a2d518caa7d7218299f7a1908cf338297a
88737e32661e323c947753fd7c8ca1abd141e7c917dc12730a5d6634be6847fc
ea8e979a9bf6fe2e8af35cedb5d639091629a2ce626f1339c7a0a48e3cc39ba2
8ecf19dca7047302513a5818cb79bcd6c4b278f92904ed1fcc7f559c72e0de7a
e9ea79b9129140cbc495137ea1c09c0686d5a5d33c43cfd1217ee2aead41237d
312783562439afa6feb4e46153051e5af5e7c15f139bac75a25afd38caaed1ce
1875aee9f50a8e2389a125c2f77998685ee0d7d7d20b7d3f1ecadf841564e654
7a20de1b4a4cd2e217be33f3297d2b38d7e7fd69ee216d58f0400160e41ff3ea
55571fa3b9f2d9a7d71c1154aac73dc3826860eaa7be12cceda40d4566ea4ce1
242ea95cfe48aaa9fca35f358ac8431cd1bd730b1ff95543a4f9d9e768115d3f
d5a0f85ffb3ee297f57ffb96a77288de2a564c5cb337b5c6c7b01da8e36545d6
285dbc8362784007c8e0a4060f48bea0818563129e5c824d34393f2c714c1a9e
ffb10236e7f77499f767e9e703c9e0a6d0b3777ff6ae06e63724f23fc7e3ea29
610224addb5b75398e556cf9780a9ad26891fa1754cbda12637903560d15dba4
959d491cbde6323dc2bf7c377a9c1e0940b988f51a3efcc0f1bd526cc0d210b4
5ca87353c4d37e66f76875a46235208796dd620ad3cb7cebc6b5e66be55b2913
d5df0f56b1209034e89de624a5ad652d070035c15f24d6b3559c34540c725b9c
590f27260d772e044dd8819c937658e02ab15050b3bf6cc3dd054c808ed3c201
89e60f82a944bb55032e88f1dff4d13242129b0bf2a3ae39aeb93904a665d4f4
8d4a83437f552b1737a406be9d9b5e4f4919a1adbf8e13f8261411d7390d604f
201cffe8bf2c15a804167c67d2a095ff655829395cb54b5c3d3c4d038efde920
224ff64e59a1b2bf45b02cb11df4f0556de0bbeb7929d37828de1c1bb8ff8772
ab5501455d6b22f8e26dd31ed265879ca6c0d3c6677793738f49360628792991
5f7a3e9cfebdb626e00af8155e710df40bab01bc5b8fcf77163cda86d23cae3d
86ea784bb86a20eff340835a0cf862d6a4a5b2309ead2c00006b65c2d8f5ebd1
0c18d82d30c57f4eb7b9ce8f7bb367b114718b077b7fd7bd838f57399c5921d0
ee591c0b19049eff4e311686e26557c5da6818438c319ed6f0df6274a56c5e05
48b161190679dd4c509ab89a5dfdfac0bdf6b557c0d77d9e4f698acf057acef8
a1a5145381a87900950867d3e6632aaf89fdedb9c898bf44fd7efbea077ab224
800fc3595eab3d807dd8199ba639d1bc6c0bdf5f1f47cf3a95c649b61056bc1c
4850a766fab45d5947075658d9c6bbf4b970f0d05b082c1472b93d9a7fa3d093
f2338f728798c729c37b627d5d75bf8691a482a4b9cc4b67ae5a5ba4b45b0c85
3d648905c51d97e4998f5e24312dae37f77dbe94279847f6a124894790881082
SH256 hash:
e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d
MD5 hash:
4ca4bca71255da3556cf6a8f2fbce88d
SHA1 hash:
63e2a27477464dd47be6adc8bebff726baf05934
Malware family:
AgentTesla
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTeslaV3
Author:ditekshen
Description:AgentTeslaV3 infostealer payload
Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:DebuggerCheck__RemoteAPI
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:INDICATOR_EXE_Packed_GEN01
Author:ditekSHen
Description:Detect packed .NET executables. Mostly AgentTeslaV4.
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients
Author:ditekSHen
Description:Detects executables referencing many file transfer clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SandboxHookingDLL
Author:ditekSHen
Description:Detects binaries and memory artifacts referencing sandbox DLLs typically observed in sandbox evasion
Rule name:INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID
Author:ditekSHen
Description:Detects executables referencing Windows vault credential objects. Observed in infostealers
Rule name:malware_Agenttesla_type2
Author:JPCERT/CC Incident Response Group
Description:detect Agenttesla in memory
Reference:internal research
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Windows_Trojan_AgentTesla_ebf431a8
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/attack-chain-leads-to-xworm-and-agenttesla

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

Executable exe e97625746360793777ab1d7dc32d4259332c7f3c81a441eb7850234aabfdf23d

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments