MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1f7b48840eee9799377106f7f32324a51a6fee37126609cd87deb58a49746e4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1f7b48840eee9799377106f7f32324a51a6fee37126609cd87deb58a49746e4f
SHA3-384 hash: 31364d97562742601b6ed846b5a7b91900991b9c20693c1910b8ed647a7aa41c669fe1f3110d479141149ed7d488eb3d
SHA1 hash: 9cf016ad8a351b5e232d8d7d614ce5fe95be25e3
MD5 hash: 474a81aa700eebac9638b8499c73bc89
humanhash: fish-undress-burger-lion
File name:Quotation.pdf...zip
Download: download sample
Signature AgentTesla
File size:766'507 bytes
First seen:2021-04-02 09:23:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:+EcBtif+vev1tEd0a6NPX8ZSqa8BOffaiCNPRvWvgc3+NDtjtfP5/tqpVrhzioH/:Ww+veXNNMZF5BOfyiosvutxhF2Vr5idE
TLSH B4F433F109F4C1AF2A9222BBF56D9EEFA850B1515939135208D0B7027319BFB1CB686D
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-04-02 09:24:09 UTC
AV detection:
14 of 46 (30.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 1f7b48840eee9799377106f7f32324a51a6fee37126609cd87deb58a49746e4f

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments