MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 06a7a27bb885699c587413d9c640c761b27f6745a76902175cbd8a45420a4f21. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 06a7a27bb885699c587413d9c640c761b27f6745a76902175cbd8a45420a4f21
SHA3-384 hash: b45005eb1b7b9f65af41954a22d9d08132f0b526198ddaf0c98c9f895417da75895cc14ccdb912c289e6a76b7595149b
SHA1 hash: 0b8aab42adfba56bde705b657a587774f35b1859
MD5 hash: 242b70e0daf5d7043cc9525cd6dd206e
humanhash: pizza-single-don-arizona
File name:PO_287104.zip
Download: download sample
Signature AgentTesla
File size:345'429 bytes
First seen:2021-04-02 09:01:49 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:oD4m8mGXaWXrivTM7aZ/XJroWKmG1ImQACbZB90nk55bPwfqXz7kAsydaG:oEt8vBrdKm/ACF/0kvAqcpu1
TLSH 8374235B6A2C0353B3425DC687C3F1BED6BD8E417455EB82E0D820977669EF38B40B64
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 06a7a27bb885699c587413d9c640c761b27f6745a76902175cbd8a45420a4f21

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments