MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 45147f389dfa3b33425ff2ca1ea3122f00f27b0062e883aa8674b7d94de11c7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 45147f389dfa3b33425ff2ca1ea3122f00f27b0062e883aa8674b7d94de11c7d
SHA3-384 hash: 768033eb1b6a80c9a1905d1e043d4941f3be76859309683c61da84820e3eb7c6bebef872f5bad1837b94e6a706b05fe2
SHA1 hash: 287132105183574cc3847437c89a0112ffe5468e
MD5 hash: 82088176dee90d8a00edc560bed16d9f
humanhash: lima-orange-colorado-fruit
File name:090099393993003pdf.zip
Download: download sample
Signature AgentTesla
File size:479'279 bytes
First seen:2020-07-28 15:51:25 UTC
Last seen:2020-07-29 00:49:40 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:aBCsaGPMacRo6oeM3M2N/fhnvlLGkMwn58SCl0oAia:aB+LacR9oeMcqtLew58h0Dt
TLSH DCA423126F121903F551DAB17FAD4B00F606D743E80B4A7B41D853CE6BAE9E0FA792E0
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: kolarik-leeb.at
Sending IP: 45.137.22.48
From: verkauf@kolarik-leeb.at
Subject: Invoice Copy
Attachment: 090099393993003pdf.zip (contains "090099393993003pdf.exe")

Intelligence


File Origin
# of uploads :
5
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-28 15:53:05 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 45147f389dfa3b33425ff2ca1ea3122f00f27b0062e883aa8674b7d94de11c7d

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments