MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3505de25673dc6e3b191cc88c0244b2739c710aeae0410ee15a081e16a504e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d3505de25673dc6e3b191cc88c0244b2739c710aeae0410ee15a081e16a504e8
SHA3-384 hash: 845a6956b61afc409b35705b37092b0184e3da0ebf0e8a1149329c46db5174e16d6ed1165261e4dce66cfced7620b4ce
SHA1 hash: 5343b287fc852bf7da489f935d8a862f5caa5f05
MD5 hash: ce90721c3d69fd65269a6ffb5410646c
humanhash: papa-missouri-speaker-west
File name:INVOICE.zip
Download: download sample
Signature AgentTesla
File size:405'383 bytes
First seen:2020-05-12 14:15:49 UTC
Last seen:2020-05-13 04:30:33 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:+9yz59XSswdHulU+4HZ1D96DKo4nMWxuZJZWzEqRLL:+9yz59OOO+QZ1D96DKo4sZnWzEqBL
TLSH DD842369D9F46D1B0407273B25D1EC43B9320E9280478DEE3AEDD1D8CA4E01FF9A9499
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-12 14:35:39 UTC
File Type:
Binary (Archive)
Extracted files:
9
AV detection:
21 of 30 (70.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d3505de25673dc6e3b191cc88c0244b2739c710aeae0410ee15a081e16a504e8

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments