MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0efabd010a8437445a3c96e2dca344892c098a30004a8c09c6be479fc4c95fa6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0efabd010a8437445a3c96e2dca344892c098a30004a8c09c6be479fc4c95fa6
SHA3-384 hash: 1fea9d914c88b0cdbd90d304500f57d2fef084760069752b46d4a55e974aa698b2640681cc9de573f0326a52d8df7d34
SHA1 hash: ad0e881bbc8126e0e55d513fa5629aaef1324b31
MD5 hash: 26ace2d776e888d6ba838ba12f29dba3
humanhash: quebec-nuts-friend-glucose
File name:overdue account letter.rar
Download: download sample
Signature AgentTesla
File size:456'456 bytes
First seen:2020-06-10 13:19:01 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:Qls5q5lkmedv53myLnA8XBl6HXoBtufGVrn4z:QlsiPyNmsnrBAYBccr4z
TLSH FAA423385CA22E21BD4ED56F4EBF5BD1BE5A912831833A0EC4770585A6CAD8734C07DE
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-10 13:20:06 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 0efabd010a8437445a3c96e2dca344892c098a30004a8c09c6be479fc4c95fa6

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments