MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 45147f389dfa3b33425ff2ca1ea3122f00f27b0062e883aa8674b7d94de11c7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | 45147f389dfa3b33425ff2ca1ea3122f00f27b0062e883aa8674b7d94de11c7d |
|---|---|
| SHA3-384 hash: | 768033eb1b6a80c9a1905d1e043d4941f3be76859309683c61da84820e3eb7c6bebef872f5bad1837b94e6a706b05fe2 |
| SHA1 hash: | 287132105183574cc3847437c89a0112ffe5468e |
| MD5 hash: | 82088176dee90d8a00edc560bed16d9f |
| humanhash: | lima-orange-colorado-fruit |
| File name: | 090099393993003pdf.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 479'279 bytes |
| First seen: | 2020-07-28 15:51:25 UTC |
| Last seen: | 2020-07-29 00:49:40 UTC |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:aBCsaGPMacRo6oeM3M2N/fhnvlLGkMwn58SCl0oAia:aB+LacR9oeMcqtLew58h0Dt |
| TLSH | DCA423126F121903F551DAB17FAD4B00F606D743E80B4A7B41D853CE6BAE9E0FA792E0 |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing AgentTesla:HELO: kolarik-leeb.at
Sending IP: 45.137.22.48
From: verkauf@kolarik-leeb.at
Subject: Invoice Copy
Attachment: 090099393993003pdf.zip (contains "090099393993003pdf.exe")
Intelligence
File Origin
# of uploads :
5
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-28 15:53:05 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
21 of 29 (72.41%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.66
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.