MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f0fc680959045193fb61601e48a527dec4aa9af18dcd85b8c27a9e7d21b7231. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2f0fc680959045193fb61601e48a527dec4aa9af18dcd85b8c27a9e7d21b7231
SHA3-384 hash: 2ef8f9a2043f048d794077021928017de940a2faf9b10a5ff2db7fd7932ea611c926ddadcf1a89a23679335c24e28512
SHA1 hash: 6ee52646f9db3adcddb3c78bb8114227fe3343ae
MD5 hash: d21f7fd68fbcba3ddb50f3da31375567
humanhash: enemy-three-uniform-kansas
File name:PRODUCT SPECIFICATION.Z
Download: download sample
Signature AgentTesla
File size:822'837 bytes
First seen:2020-11-07 22:40:55 UTC
Last seen:2020-11-08 06:21:57 UTC
File type: z
MIME type:application/x-rar
ssdeep 12288:iWvaPL1ZMbcxpidS1pviUbr12ED+O1cw4SX1Mrql1MIWlA2uq6TqTU9gNjDNOZ8R:liPL0HdSTJrMwZXClS2Ns6Hu8ff57
TLSH 6A05232C653E7908D2B0DD600A7A0F817F8ED7A7474E8B7F58D6044836FA5D46326A3B
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
114
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2020-11-07 22:21:02 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
14 of 48 (29.17%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 2f0fc680959045193fb61601e48a527dec4aa9af18dcd85b8c27a9e7d21b7231

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments