MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43d43c758e017d70b63a76aed64dfeaa28b4414f972d73672d7f7dbc7b7dba06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 43d43c758e017d70b63a76aed64dfeaa28b4414f972d73672d7f7dbc7b7dba06
SHA3-384 hash: ba088842d25ae71877105e886cc59837235153af3de239b83de53783e9b590dbc467f943394af5631b4d5df6a9563fb6
SHA1 hash: e2e81eff8d12f797a06c6f9bf7e377ea8444d047
MD5 hash: cffbb1b465d2b942360c0aad4c8e21cb
humanhash: helium-nine-eighteen-cold
File name:Payment Confirmation.zip
Download: download sample
Signature AgentTesla
File size:737'188 bytes
First seen:2020-08-31 05:24:33 UTC
Last seen:2020-08-31 07:45:01 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:t0o3ICbkK1dJ0YYasYfqKMrOAG1wPr44zXQOng4cBpKTyp1kVKqq9q4nz8214c:tD3I6kKuYYmfUCf14r8yZNnhqMOz82ic
TLSH BAF423DF8D5E8423561EB2BC3DEBB3A3505BDC7285A29D86841C746091CFE24277BAD0
Reporter cocaman
Tags:AgentTesla zip


Avatar
cocaman
Malicious email
From: JENNY ZANG <acorrea@televes.com>
Received: from televes.com (unknown [209.58.149.99])
Date: 31 Aug 2020 05:30:57 -0700
Subject: Payment Confirmation
Attachment: Payment Confirmation.zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Smartassembly
Status:
Malicious
First seen:
2020-08-30 23:19:19 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 43d43c758e017d70b63a76aed64dfeaa28b4414f972d73672d7f7dbc7b7dba06

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments