MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d2949465fa251a2a3322a5040aa09fa91a7c17ce5b4d92c4cc2d302530b2182. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4d2949465fa251a2a3322a5040aa09fa91a7c17ce5b4d92c4cc2d302530b2182
SHA3-384 hash: 09d6571881784e746bf631edc32e2177e72f33733c7dec32a36e94221e1e7a6b3208510b7ff10c904f22210306acb91a
SHA1 hash: d69c53f4c082f44b809f7acd521a834885186f0c
MD5 hash: 3e9b31bece3226d42a22402867a3608c
humanhash: ink-west-dakota-one
File name:PAYMENT SWIFT COPY 133253378.pdf.zip
Download: download sample
Signature AgentTesla
File size:426'258 bytes
First seen:2020-05-17 05:45:38 UTC
Last seen:2020-05-17 12:56:36 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:UV0/nAZTGGldfvci/vmfQv4IjzvoH+ocgBEELu:USnAJdWfQAIjzK+RgK7
TLSH 929423683EF4B81DAFDCAC50146D9B8A71D3C802CE98D83E6DA4404AD74A77B19F7852
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Mbt
Status:
Malicious
First seen:
2020-05-16 09:45:35 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
23 of 31 (74.19%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 4d2949465fa251a2a3322a5040aa09fa91a7c17ce5b4d92c4cc2d302530b2182

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments