General

  • Target

    Built.rar

  • Size

    1.4MB

  • MD5

    a2325b5dc491b035d57092c0fa31a608

  • SHA1

    d8979481d98036dc930085610aebf78ec7d13934

  • SHA256

    d3ca102b990985518abf51ba8d71af250d10d9a017cfda853bbd71eafec3de0a

  • SHA512

    e60160e217d2b819cc2dd785d290f00c8cff0653da69fd97a07a814eee01e51c96f8520cf839461fb8e09647e5b290c451ad58576719b37bd91a23f1eb3b4929

  • SSDEEP

    24576:de6//cCUVuWxOKqeK8QieMm+0chebtEmmxg5EzyPiBWccTkd7+Cbn94YjU:d//ECCuaOK28QieMm/cMxEmwyqBIayC2

Score
10/10

Malware Config

Signatures

  • AgentTesla payload 1 IoCs
  • Agenttesla family
  • Unsigned PE 4 IoCs

    Checks for missing Authenticode signature.

Files

  • Built.rar
    .rar

    Password: 123

  • Built/DoxTool By R_0.exe
    .exe windows:6 windows x64 arch:x64

    Password: 123

    6a91eb82bfd19d2706c7d43c46f7064e


    Headers

    Imports

    Sections

  • Built/Guna.UI2.dll
    .dll windows:4 windows x86 arch:x86

    Password: 123

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Built/HtmlAgilityPack.dll
    .dll windows:4 windows x86 arch:x86

    Password: 123

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • Built/Newtonsoft.Json.dll
    .dll windows:4 windows x86 arch:x86

    Password: 123

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Built/RestSharp.dll
    .dll windows:4 windows x86 arch:x86

    Password: 123

    dae02f32a21e03ce65412f6e56942daa


    Headers

    Imports

    Sections

  • Built/System.Management.dll
    .dll windows:4 windows x86 arch:x86

    Password: 123

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections

  • Built/osint.deps.json
  • Built/osint.dll
    .exe windows:4 windows x86 arch:x86

    Password: 123

    f34d5f2d4577ed6d9ceec516c1f5a744


    Headers

    Imports

    Sections

  • Built/osint.pdb
  • Built/osint.runtimeconfig.json
  • Built/runtimes/win/lib/net7.0/System.Management.dll
    .dll windows:4 windows x86 arch:x86

    Password: 123

    dae02f32a21e03ce65412f6e56942daa


    Code Sign

    Headers

    Imports

    Sections