MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1489521207b240fd4462b9937f2590bb2c4a61d228b246fb80e84e6196758a2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1489521207b240fd4462b9937f2590bb2c4a61d228b246fb80e84e6196758a2d
SHA3-384 hash: 89978ad763156fb27d7f16f19c5c0e29f7bbb4e3fae8fee8fceb620874f81c457e34d43f7fb199c52e3773c28fe55d2c
SHA1 hash: 5e52f83231b6c354c2981be40702ea2bb711e0aa
MD5 hash: ab5342fbc983807f170fec893ffcecc6
humanhash: stream-louisiana-west-alaska
File name:DOC.zip
Download: download sample
Signature AgentTesla
File size:396'580 bytes
First seen:2020-06-28 00:11:34 UTC
Last seen:2020-06-28 00:40:32 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:AaVWNiqBS5a3ptIaAWj/3gRM30iPHGBGTzHNHU3Frh63XOZFWDUUvch8c8hRLugk:BUEqBW1Yud0mBGTOUeMo8hRLui5hE
TLSH 1C8423136EBDFA84DC01E16C04E7AD991FB14DC2593C0D999FE2A92CA7AC250CC6DE07
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.SchInject
Status:
Malicious
First seen:
2020-06-27 14:47:34 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 1489521207b240fd4462b9937f2590bb2c4a61d228b246fb80e84e6196758a2d

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments