MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0d989803ab5dcd272dcba7f79e19386a8ad264b0a2fddbc8ee03525a2eaef67d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0d989803ab5dcd272dcba7f79e19386a8ad264b0a2fddbc8ee03525a2eaef67d
SHA3-384 hash: 5251968fef58baa7c67aca37dd8ca1408b3bd80cb33f3e8ef935758856a79222733c1efb336c4446bc7d346a86ed1e18
SHA1 hash: 687c341cb309971997f7c1dd8346257b785a10ff
MD5 hash: 57185da5b7e11698c450f6f13cfc06d6
humanhash: batman-india-saturn-video
File name:Swift Bank Copy #156065.pdf.zip
Download: download sample
Signature AgentTesla
File size:489'217 bytes
First seen:2021-01-26 19:04:24 UTC
Last seen:2021-01-27 00:50:38 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:1myArgACymF2YoP5vBHdsbpJ+phj/iiy68MHGZ5fh0LzmQ6e:ZAFh7v78ryV/iUwV02QN
TLSH A2A42348F7D42796A4C4E5AE8BC91C2C696FED5D4BF2F802734BA161734C76B30E0998
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
5
# of downloads :
159
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-26 02:56:08 UTC
AV detection:
19 of 28 (67.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0d989803ab5dcd272dcba7f79e19386a8ad264b0a2fddbc8ee03525a2eaef67d

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments