MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 57937794fb95166659703b275620affd15c17d2b57895c192c253befd913be2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 57937794fb95166659703b275620affd15c17d2b57895c192c253befd913be2c
SHA3-384 hash: 6c3d5978376ba6287d99415eeeb506018991ebc632d1f6cc054ade9453ec14984440b7731104453a124406f42acebd05
SHA1 hash: dda5d37dd04c0baa9277c44ad21f46cb93380f56
MD5 hash: 1de6f1e70a2450b5175851a315c6e96f
humanhash: echo-bakerloo-bluebird-maryland
File name:AN_FSOFCL2020052211pdf.zip
Download: download sample
Signature AgentTesla
File size:405'281 bytes
First seen:2020-05-22 04:05:57 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:mIu9rjURWlnrlMEM0akvwemKLY4CpM3u+UsIYxSoxMbuqP4JOhuldmTvy9wOpF+d:PArjyq5M9RxN8MI5IYxS7lIzaKrp1/Jc
TLSH 818423ED7E21318896E46802031D63670E7D153992038FB52BB7398C7C58B9AF5F96D3
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-22 04:35:24 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 57937794fb95166659703b275620affd15c17d2b57895c192c253befd913be2c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments