MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ea85c13709273f9bbd3490b77e20e15f09f02516fb171fae2128959999d88e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2ea85c13709273f9bbd3490b77e20e15f09f02516fb171fae2128959999d88e0
SHA3-384 hash: 2517d20445372dec610b677815779cd1b5e9588bff4f5946938f741d99a1e99548cf6b09c0e9b2e1cf99371eb0998735
SHA1 hash: 39848ed18ccb88369d4695acd6ef070b43a7a714
MD5 hash: d5728653e48bf7ed8fa07db4e2f82912
humanhash: october-one-jersey-four
File name:BANK DETAILS (2).gz
Download: download sample
Signature AgentTesla
File size:400'375 bytes
First seen:2020-11-12 01:18:21 UTC
Last seen:2020-11-12 01:43:27 UTC
File type: gz
MIME type:application/x-rar
ssdeep 12288:5UzIay3YVyLzHlQHQaWvLbWmD2sT0L0tf:5UWc25QHQf/C5L0tf
TLSH 7384230049EFD0FE1651D4FD682CD45FE7B8AA947CC3DA4B3F67A63E509266230AC492
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
4
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Ymacco
Status:
Malicious
First seen:
2020-11-11 00:55:36 UTC
AV detection:
15 of 27 (55.56%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 2ea85c13709273f9bbd3490b77e20e15f09f02516fb171fae2128959999d88e0

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments