MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12675917f5ffc5b51834978a2b654a7d31e3ea57f8105a80f12eeba2d3bdace5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 12675917f5ffc5b51834978a2b654a7d31e3ea57f8105a80f12eeba2d3bdace5
SHA3-384 hash: 3d8d68ae6c7f92a589c09d060c5e6d618865240ddcac7ee490045aea1adcfa31be31c6d1d768c550d34593c783ffe9c5
SHA1 hash: 2421987e084b35a18a9690660319c51b15dcfba2
MD5 hash: 4295f501ea0b4666486ea4830c3a1387
humanhash: failed-fix-high-pluto
File name:ScanCopy_RFQ 223201200.doc.gz
Download: download sample
Signature AgentTesla
File size:359'315 bytes
First seen:2020-07-23 06:30:06 UTC
Last seen:2020-07-23 11:28:36 UTC
File type: gz
MIME type:application/x-rar
ssdeep 6144:omdTGE3pUfN1stt7ejzycXmjRx8yno5cElHAKROY7zKLOC5Ylchf+OXg:oUiEqf6JYzycXmL8ynOHAKRBKLT5YlYU
TLSH F17423F2529374CFE751927DE54337B24FA03B6CF3620108EB25579752EC1EA688709A
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-07-23 06:31:05 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 12675917f5ffc5b51834978a2b654a7d31e3ea57f8105a80f12eeba2d3bdace5

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments