MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3033f64d16ddd91859aba158fbe68357df39d0acb48c5a94da117bc9ba8186f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3033f64d16ddd91859aba158fbe68357df39d0acb48c5a94da117bc9ba8186f4
SHA3-384 hash: c33fd68588aee993f8686e399559698e212b0fed49e9e1b19252d961964210d62943d25bb36b196e81a1e68963ad0222
SHA1 hash: 4ef04218c6f84a4d0cb05a191c70d3a5ffe6dc97
MD5 hash: 1fb37c47f7f2a7470ae9754e429bb1cc
humanhash: potato-seven-juliet-december
File name:SOA.rar
Download: download sample
Signature AgentTesla
File size:741'440 bytes
First seen:2020-11-11 13:52:01 UTC
Last seen:2020-11-12 00:39:59 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:J5j5Ht5PFISizv2F/lmLWFSswyD2WYx2vGRFAOtbkuJdsIkk1LohJnnTfVxYyoyZ:J5jRtBF6zeCWvDI2vGjAOFkkvkWefVxt
TLSH 1DF433BD4BA6912C6FCF5A80BE3DA257B87204CAF285BBBD44107974207C791767630B
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-11 02:20:29 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 3033f64d16ddd91859aba158fbe68357df39d0acb48c5a94da117bc9ba8186f4

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments