MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9efbb72099642e78f20f59ddf55a4fae21f2b680a6dccb57f3f05be9548efa6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d9efbb72099642e78f20f59ddf55a4fae21f2b680a6dccb57f3f05be9548efa6
SHA3-384 hash: 87be4f404c5a2c962df55bff5ff1520c9e59edb0b12a44249cbf1b2587b8af1480dcb54fd61dc88e7bb1fb1dbf4640d1
SHA1 hash: 16bae8a6b540cef3884cea9bf9f1eed8c6caf98a
MD5 hash: 7a81303edc5f7b9216c907dd01342b4e
humanhash: sierra-beer-nuts-kansas
File name:items#lists.image.jpeg.zip
Download: download sample
Signature AgentTesla
File size:431'960 bytes
First seen:2020-07-27 19:45:38 UTC
Last seen:2020-07-28 10:21:31 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:4Qi6uCsBGar2fMRx+U+YaF69FVxLrUMw63H/N8zqSyn9YkB1FQNebM3HuyJBRQYZ:4Z6uCsyGvaA9Ff7wc1cqFb1F4uyXRpbn
TLSH CA94234D6D5CFBBFC76935FA9D8A36048B7B9077A980A4244586C05402DEC3AFC670BB
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
55
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-26 14:53:38 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d9efbb72099642e78f20f59ddf55a4fae21f2b680a6dccb57f3f05be9548efa6

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments