MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b53a882fc87d037002401e58db022d2d9436c4e591b9f8b6817286267074295. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4b53a882fc87d037002401e58db022d2d9436c4e591b9f8b6817286267074295
SHA3-384 hash: adb6ed9ec20d0c1ef93fb13a4c8824155e229376e34bc9a89d8c79b92f4c8e51efd9dc6c5b5f2cefe4712c04c921d1b3
SHA1 hash: 3b1c5069569a07db40c1eadcdb406ee6a8cb2868
MD5 hash: 40ee0db5c87d78a3afa486b5b5dfd9a0
humanhash: pennsylvania-august-video-mango
File name:RFQ.zip
Download: download sample
Signature AgentTesla
File size:403'080 bytes
First seen:2020-06-01 11:33:11 UTC
Last seen:2020-06-01 11:46:10 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:iSJbgQ/9APqStjGDJ4EnJdu74XvWBQr7fuzNUnvf1ZS6cY2IdEh4Gik5xPk6XtRJ:ia1ASn1DD84/H8Unvdvd6PDHDoUPn
TLSH C28423DAC6DE843064E082F39BC03E5CA4D209D621FB6D191225BCF7ADE445A33B95DB
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Genkryptik
Status:
Malicious
First seen:
2020-06-01 03:24:29 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 4b53a882fc87d037002401e58db022d2d9436c4e591b9f8b6817286267074295

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments