MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b1bc0333eac12e680f5a1b4deb09e03385d9bbc78c54253c3920d61cf5079a14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b1bc0333eac12e680f5a1b4deb09e03385d9bbc78c54253c3920d61cf5079a14
SHA3-384 hash: f2a182e90c51f95e3801b7d3e905896de3b4e6d8f0b3dd0bce5a9ee75b0f46de65e0de96c89369b70eeac4aad02711e3
SHA1 hash: 9368312340b448e8e504b9a0747fc0d45d3823cf
MD5 hash: 5dd683341b95fc0272bf6be58f268c01
humanhash: friend-delta-triple-pip
File name:Payment Slip.Z
Download: download sample
Signature AgentTesla
File size:460'722 bytes
First seen:2020-07-28 13:11:34 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:dKdw8mv7y5QQJTy/Q4sMa11g98/kmEYLSD20w2sJ4gnrHbxGZdVusSvqUGy88LXp:dKLyOae+Du8mJ0w2aXxGZD0JLXfR
TLSH 29A423F52652C9A54383A90F497B3237A5C66D2C4CCF2FCA3EF0D39AB114E27456CA49
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-28 10:41:08 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z b1bc0333eac12e680f5a1b4deb09e03385d9bbc78c54253c3920d61cf5079a14

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments