MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6de0042f975538ac83786aa28a34a342379b58e2379aa9b7d4689140bb6bdf23. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6de0042f975538ac83786aa28a34a342379b58e2379aa9b7d4689140bb6bdf23
SHA3-384 hash: a95593eb924560c35ed19837fada4d2169d217356277de0e646f1edec3c680eaa119d7fa4bd4d13702a70c4ffefa3d6b
SHA1 hash: 43967251387cd73600292c33061c97c6fe5e054d
MD5 hash: 36a61475eecf60e3ba90eb5ccb7dc942
humanhash: virginia-juliet-orange-failed
File name:18 05_00011004_CGS4250954pdf.zip
Download: download sample
Signature AgentTesla
File size:428'381 bytes
First seen:2020-05-18 04:33:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Ap6fmTKTtzscRyrJKrX65x6mKshdyW+bPEp+K2vL4gpkQ7e4bllUfDI+hC563WLG:U6oKTVpJX6+mdATvEgpkQxQfLQhG
TLSH E29423F3407264FB9329685D552F8FAD89106A13B6DB1F0542F36B23C8C4866E17B4DE
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-18 04:35:24 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 6de0042f975538ac83786aa28a34a342379b58e2379aa9b7d4689140bb6bdf23

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments