MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e13264de403e804d6214a0dedc6c01d8e8fc9de6f9c4fc1d18e08fb4656a4a6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9e13264de403e804d6214a0dedc6c01d8e8fc9de6f9c4fc1d18e08fb4656a4a6
SHA3-384 hash: d0e963ef763d8c4fc2e46fb0c47553dc242d78dcdb7c0ee6633e939ecee1e1b7ee9b0bf787a888831a53f3d61b840478
SHA1 hash: 90cb5d04fb44571c0fae6cbb690dbed3344b9cb6
MD5 hash: d59773dda7f71413a64369c8ee0c36a7
humanhash: victor-fish-johnny-sad
File name:Original Shipping documents .pdf.z
Download: download sample
Signature AgentTesla
File size:371'854 bytes
First seen:2020-07-16 03:52:30 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:eYOZWl9XNB7hNM3NWkfRlYDUBUBCNVmUTGVuK8O2Qd/FCYRVi+gIeqGjopyGYiUs:eZWl9X1+9WkfRl1UQNAUTIu7Z8FgBpjI
TLSH E5842313F5C3CE19AB12271CB1BC94F832AA514AC7D4EE9E905421F5C9E3CDAEE68354
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Masslogger
Status:
Malicious
First seen:
2020-07-16 03:54:06 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 9e13264de403e804d6214a0dedc6c01d8e8fc9de6f9c4fc1d18e08fb4656a4a6

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments