MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1f7ffb0a6a58be3ea87b8604e61ea0bc5372cfdeabf8f92efab2371e42e45338. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 9
| SHA256 hash: | 1f7ffb0a6a58be3ea87b8604e61ea0bc5372cfdeabf8f92efab2371e42e45338 |
|---|---|
| SHA3-384 hash: | 9d46f78fb0e9098ef3c134134ed7e7c7b8bec6b825e94035abe20b1249fe8e1a4f4bcccbf9cfb54092831a7d3b39a95c |
| SHA1 hash: | 06f3ee169180266cf6b4425eae785dc6295aa7ac |
| MD5 hash: | ede339007fe74df17f40383dbe239e0b |
| humanhash: | cat-quebec-purple-paris |
| File name: | 1f7ffb0a6a58be3ea87b8604e61ea0bc5372cfdeabf8f92efab2371e42e45338.pdf |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 240'684 bytes |
| First seen: | 2023-07-30 20:11:51 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/pdf |
| ssdeep | 6144:l03ahoiZy+vUsHvfenYBJq+xTmRclWlV3MOuEz7wn:63ahoeZHOYCaK/VcC7wn |
| TLSH | T13F3412E011F5C7118A5550B39036EFF8D1D3B4E6CAF0D78A59832B2D5A69E340B7AE0C |
| Reporter | |
| Tags: | AgentTesla pdf |
Intelligence
File Origin
# of uploads :
1
# of downloads :
432
Origin country :
USVendor Threat Intelligence
Detection(s):
Result
Verdict:
Suspicious
File Type:
PDF File
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Verdict:
Malicious
Labled as:
Phishing/PDF.Agent
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
1%
Score Benign:
99%
Result
Verdict:
MALICIOUS
Details
Document With Minimal Content
Document contains less than 1 kilobyte of semantic information.
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Clickable URLs found in PDF pointing to potentially malicious files
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Document-PDF.Phishing.Generic
Status:
Malicious
First seen:
2023-07-30 01:08:48 UTC
File Type:
Document
Extracted files:
5
AV detection:
13 of 38 (34.21%)
Threat level:
5/5
Detection(s):
Suspicious file
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.40
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.