MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2df8a239b107828ad33ec081e3a441052204397e26ce42595169f64a8128b5ed. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2df8a239b107828ad33ec081e3a441052204397e26ce42595169f64a8128b5ed
SHA3-384 hash: 3ea10970d36d183f24f07e1e978f5e188a419a2bc08b40f12d2f4c96c4affb9900f4f76e1564bfbbfec16a17e21480e4
SHA1 hash: 8823b071ad58328e6a7b0a9fcb23ed81664dc035
MD5 hash: 3858024d57d75c35785a75fd4c3ddfd2
humanhash: virginia-pip-montana-lake
File name:PO NC1.179926.040620.GZ
Download: download sample
Signature AgentTesla
File size:376'405 bytes
First seen:2020-04-07 11:52:15 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:s7tsaUsCTjgX9ihAQpTMLl1zkHULsnlQB8ntNGi2wQrsW2VZEfmTqGeEQQM:sxsPLhAQpTMLHzkHgs1ntNGrwU2Q2qGo
TLSH 258423C9B2193C6A3EBCF900750D96F0DC291837C8793D7CAE6D38604C7566C646AAB3
Reporter cocaman
Tags:AgentTesla gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Npe
Status:
Malicious
First seen:
2020-04-07 12:35:59 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 2df8a239b107828ad33ec081e3a441052204397e26ce42595169f64a8128b5ed

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments