MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2427694fef216f4cecf78df68a12b942587082910e96053610fd2ebc26973e2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2427694fef216f4cecf78df68a12b942587082910e96053610fd2ebc26973e2c
SHA3-384 hash: d4e68ac8604466b135584a1e8b88c6b7ccbc1b9071394a07491accac389aa394575b21157741980789cc5fe3e825026e
SHA1 hash: 4d83281a5fd9ac6cbd504afacb2c75d5c0607080
MD5 hash: 2b9b5aa7de82655a2d6cc08dc1d5f114
humanhash: six-alaska-mockingbird-tennis
File name:Informationsaktualisierung.zip
Download: download sample
Signature AgentTesla
File size:401'217 bytes
First seen:2020-05-22 06:02:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:9HfjGpvFdFp8Rm3qMpcFSR+HHOdqyaYqCACaQDW/y5yj4tS/oZr1AmwXEFSxyapf:RfjiyKcpO0NIW/yHkoRGmwU6UST12y
TLSH 2A84236C40C762B7F34351429F21FAEB98BCE64C3C5C9649423A9461B918E396C75CDB
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-21 20:41:07 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 2427694fef216f4cecf78df68a12b942587082910e96053610fd2ebc26973e2c

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments