MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 24cbd26edc92617093f92f4bd1755c3023a4990094f0887b07bc5f7bd8c0c6fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 24cbd26edc92617093f92f4bd1755c3023a4990094f0887b07bc5f7bd8c0c6fe
SHA3-384 hash: 9f17e0af8c6c795ef51a7c3fcd9462769a370d161ebb422bb015d5ccfd2b46e3b517531c22cd84811ffae30b0bdae59c
SHA1 hash: 5cae3514f62bcc252962aa0742c35fd20a57d28e
MD5 hash: 74a39b194a6efe408f894d5c0d03eedb
humanhash: aspen-single-michigan-salami
File name:Scan_277382816.gz
Download: download sample
Signature AgentTesla
File size:372'386 bytes
First seen:2020-12-22 10:47:51 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:J7ugYOLLmq326luxSA4TA9K+5rXbSiO7XPXaP6N0H5fwMZkBCCCkDYjY1Hh0:J7ugYOLSq33eSAB9Key7CP0e5fWwCCk+
TLSH 9784231172B63BCA3D8BE82D4D199BA3F89A4E0F8178D1CF1798734242355DB6E50CB1
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
279
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-21 10:12:38 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 24cbd26edc92617093f92f4bd1755c3023a4990094f0887b07bc5f7bd8c0c6fe

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments