MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3033f64d16ddd91859aba158fbe68357df39d0acb48c5a94da117bc9ba8186f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 5
| SHA256 hash: | 3033f64d16ddd91859aba158fbe68357df39d0acb48c5a94da117bc9ba8186f4 |
|---|---|
| SHA3-384 hash: | c33fd68588aee993f8686e399559698e212b0fed49e9e1b19252d961964210d62943d25bb36b196e81a1e68963ad0222 |
| SHA1 hash: | 4ef04218c6f84a4d0cb05a191c70d3a5ffe6dc97 |
| MD5 hash: | 1fb37c47f7f2a7470ae9754e429bb1cc |
| humanhash: | potato-seven-juliet-december |
| File name: | SOA.rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 741'440 bytes |
| First seen: | 2020-11-11 13:52:01 UTC |
| Last seen: | 2020-11-12 00:39:59 UTC |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:J5j5Ht5PFISizv2F/lmLWFSswyD2WYx2vGRFAOtbkuJdsIkk1LohJnnTfVxYyoyZ:J5jRtBF6zeCWvDI2vGjAOFkkvkWefVxt |
| TLSH | 1DF433BD4BA6912C6FCF5A80BE3DA257B87204CAF285BBBD44107974207C791767630B |
| Reporter | |
| Tags: | AgentTesla |
Intelligence
File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-11 02:20:29 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
AgentTesla
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropped by
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.