MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ef40abb0b6574dffc704f280d7a0f78f4f98b660c9ddfee01f7089452ce9900. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3ef40abb0b6574dffc704f280d7a0f78f4f98b660c9ddfee01f7089452ce9900
SHA3-384 hash: f5b13a5ace2829f7dc5f9f52d778980a81456795b54b2a7c43a0872ed1713e0415604dd166829dfe4b0881ea457762f6
SHA1 hash: 7f996f1765dc378100f564796caf750bafbb48e0
MD5 hash: d0dcedcd89e72f3ca9939ad28bd44744
humanhash: sad-venus-equal-kansas
File name:MV VITTORIA - CTM.zip
Download: download sample
Signature AgentTesla
File size:712'059 bytes
First seen:2021-02-16 06:38:16 UTC
Last seen:2021-02-17 20:38:42 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:TBQ7kqyxY0GA/BsQA41+B4cHlvCJkSre0GWTbgZGJdxyXNvG35OFK1:TBckqJcJw413cHlv000G+bgsrEXVG3ky
TLSH F9E4236B104B8A154A5A3B30CE65B90D22C35522AFF9E503DF7A7C952D32B7C81D3D2E
Reporter cocaman
Tags:AgentTesla zip


Avatar
cocaman
Malicious email (T1566.001)
From: "Evi (KLBS.LON) <Evi.Lepida@uk.kline.com>" (likely spoofed)
Received: "from uk.kline.com (unknown [103.141.138.131]) "
Date: "15 Feb 2021 19:21:43 -0800"
Subject: "MV VITTORIA - CTM "
Attachment: "MV VITTORIA - CTM.zip"

Intelligence


File Origin
# of uploads :
3
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Pwsx
Status:
Malicious
First seen:
2021-02-16 06:39:11 UTC
File Type:
Binary (Archive)
Extracted files:
25
AV detection:
6 of 47 (12.77%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 3ef40abb0b6574dffc704f280d7a0f78f4f98b660c9ddfee01f7089452ce9900

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments