MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1789b7ddd6bf454449b22870e25defd033d15f851e6f51f1cbcb6ce1ed236194. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1789b7ddd6bf454449b22870e25defd033d15f851e6f51f1cbcb6ce1ed236194
SHA3-384 hash: dabb1583507618a9552c25a1fc775bb0c08eecbf7f1dcb503085ee158d3fddcba627eb267983cb4434c58ee5941407e1
SHA1 hash: 867ff3c4efb66caaddf0647e0331411ed971693d
MD5 hash: b3ddc0900ed5d22dba1a02464213dbfd
humanhash: nineteen-cat-utah-queen
File name:listed product.Z
Download: download sample
Signature AgentTesla
File size:772'494 bytes
First seen:2020-11-05 10:33:25 UTC
Last seen:2020-11-09 07:33:42 UTC
File type: z
MIME type:application/x-rar
ssdeep 12288:nJdioVY9sGO73B/u8jyg+I0bX1qJvVSixjlygOssISSYl:nbV3lR/ygubX1qrVlyO3U
TLSH 63F423D6963802A18716C299FEFC9B9C5AAC31FE15F44C64D804EB348270AF7C196B4F
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
4
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Androm
Status:
Malicious
First seen:
2020-11-05 10:00:11 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 1789b7ddd6bf454449b22870e25defd033d15f851e6f51f1cbcb6ce1ed236194

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments