MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 235b3e73e5812044f0a64a578e5c30cc5181633be97e917bacf4e7f798cec597. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 235b3e73e5812044f0a64a578e5c30cc5181633be97e917bacf4e7f798cec597
SHA3-384 hash: 175beff2944f8ead86a778728308ce61980e0769b0e6ef28a6ea0778d378c7a618b9cbe32ca2bcb5ce05cec5b3875c20
SHA1 hash: 188652217ea846d7499ade918ed8bb71343b9e7e
MD5 hash: 2a42c504e51f6a8481dddf9cfc269125
humanhash: double-ink-william-four
File name:OUTSTANDING PAYMENT STATEMENT OF ACCOUNT MARCH TILL DATE pdf.zip
Download: download sample
Signature AgentTesla
File size:509'780 bytes
First seen:2020-07-01 02:24:32 UTC
Last seen:2020-07-01 04:18:29 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:81m/XfvhFUhrqGIBgxQtP80AwsdEmvLBv3nZOeX/64shq2iDF8AWB:88/Pv0tqG+SQtPIw+EEv3ZVpF2ieDB
TLSH D1B42394ECF72939567C8EA37369C4B2267D5874E0D504F64DE20783F7A22FD88D21A8
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
5
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-30 18:56:35 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 235b3e73e5812044f0a64a578e5c30cc5181633be97e917bacf4e7f798cec597

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments