MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a47ab11b8bdc7875f9ae5f4df800767673b4f18d85cec9411ba2d83e6a4a404a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 2 File information 2 Yara Comments

SHA256 hash: a47ab11b8bdc7875f9ae5f4df800767673b4f18d85cec9411ba2d83e6a4a404a
SHA3-384 hash: 331e567aa515302f61fe92116134c557b8b048b3a8beefbbbf9e2f63c305adf71f6753e9d1aa27f5dea682ae7c10d3bc
SHA1 hash: eab122b5e52a07542b4be3a0741cbc61d32d0123
MD5 hash: d6680c4e46758a298daab7476701f075
humanhash: cup-rugby-leopard-lake
File name:signed_19272.zip
Download: download sample
Signature n/a
File size:400'303 bytes
First seen:2020-06-29 21:35:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:7pnc/ktzGb2h0eNmVl6q3Y6N0NiJV1zEXyI25oqw:7pMlstNmieYkmiJfWyfCD
TLSH 8B8423BEEE79BADCD05C71BC0940D6BE43A7AAD4D16C94860C798D0D0A951FCD247788
Reporter @jarumlus
Tags:AgentTesla

Intelligence


Mail intelligence
Trap location Impact
Global High
IT Italy Low
CH Switzerland Low
# of uploads 1
# of downloads 32
Origin country FR FR
ClamAV SecuriteInfo.com.MSIL.GenKryptik.ENGK.190.UNOFFICIAL
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/a47ab11b8bdc7875f9ae5f4df800767673b4f18d85cec9411ba2d83e6a4a404a/
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Agenttesla
First seen:2020-06-29 09:26:29 UTC
AV detection:26 of 48 (54.17%)
Threat level:   2/5
Spamhaus Hash Blocklist :Suspicious file
VirusTotal:Virustotal results 12.12%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

zip a47ab11b8bdc7875f9ae5f4df800767673b4f18d85cec9411ba2d83e6a4a404a

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments