MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f574d1dbab7999f231424caf6e6e7a262acb34185dc69fa7420fd52400838c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5f574d1dbab7999f231424caf6e6e7a262acb34185dc69fa7420fd52400838c6
SHA3-384 hash: 43ec2159e05a102d6c892ab3172012c129327bc2d622ad440ca82db2080f05f16cb70c473d8c75f700f54c306a81fbf6
SHA1 hash: 282b36afa95e9a02ec4f22337504a5e641a12cc1
MD5 hash: 8a7a2c35d874e4cd26360eeb59ad3505
humanhash: georgia-mirror-winner-fourteen
File name:BOQ.zip
Download: download sample
Signature AgentTesla
File size:313'928 bytes
First seen:2020-05-06 09:37:52 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:bPQr4OJR00TrAM0Ak4t7UBhYYRGBF631h/xI61C/UdTTAQ3ZmD:zQr44zAFwO4ul9eY5TAQJmD
TLSH 0064235D3E8F7222192582DEE1262D06197393EA72C0976C254C9D3F52EB2DF5AC0CDB
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-VBS.Trojan.Androm
Status:
Malicious
First seen:
2020-05-06 07:38:11 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5f574d1dbab7999f231424caf6e6e7a262acb34185dc69fa7420fd52400838c6

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments