MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 03bb8812747e7a0ed9af91bbe0648df05af8527be5f5d3fbc98abcb7d9bf4267. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 03bb8812747e7a0ed9af91bbe0648df05af8527be5f5d3fbc98abcb7d9bf4267
SHA3-384 hash: a6afd9cb51c4a935455e1b109b1fe80d16cd82b4abbbc0c7cf41893328eee02aa1e5a4988be3be3caf03b62b532b38f1
SHA1 hash: 9bf6785f5159bd0266ddb330aa56488e1071933c
MD5 hash: 43cdcf48c9444a8ce25f9988c3a0b085
humanhash: helium-orange-princess-asparagus
File name:Payment_Confirmation_Slip&_InvcDocs.rar
Download: download sample
Signature AgentTesla
File size:169'990 bytes
First seen:2020-05-15 05:58:03 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:FIMInP5GayWyaVW8uS6mqnYkdvXhCUQfF1t2wCfdMwE2wsLLaSjLgxzoBRo:FbJWyr8uS6HnYIZCUAF/mVzLmCLou+
TLSH 45F312FD8A20726CF19CC66EA236801C5D7DC9D351334FAA7065256A20F81CDB776F15
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Autorun
Status:
Malicious
First seen:
2020-05-15 06:35:31 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 03bb8812747e7a0ed9af91bbe0648df05af8527be5f5d3fbc98abcb7d9bf4267

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments