MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3bd345e6c29879a236d8a2538a35c3239f4718ea00337d05dd07330407c5cbf1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3bd345e6c29879a236d8a2538a35c3239f4718ea00337d05dd07330407c5cbf1
SHA3-384 hash: 2e90c9d8ee6a52afcb46e202b89536d54e4458a667d1322523e199c462c294b14b3a507c88a6bf1ab7542190d8aade3e
SHA1 hash: 24ccbcdd3da73f7c7bb043f4dd5258e833253178
MD5 hash: 6c7002db101710365b6219f91dbb26c2
humanhash: skylark-equal-idaho-beryllium
File name:0987500000000000000.zip
Download: download sample
Signature AgentTesla
File size:16'815 bytes
First seen:2021-03-31 22:21:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 192:/6/Og7lRjPmot0GG1R1PS4xLIp94DjNrTkMAY25zyBzakqKeum3PBbENBJXO7:C/9NVt3GL1zIp94DRTJ2LjKo3PBYfI
TLSH 6B72AF1AFC2BED0B6154F4706DA8F09957A1B23FD8473D6327D80CBAA8739902E44C35
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-03-31 22:21:08 UTC
AV detection:
11 of 42 (26.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3bd345e6c29879a236d8a2538a35c3239f4718ea00337d05dd07330407c5cbf1

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments