MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 476de54b5de9af5f45faf864bd1a46802e58975f98e38c1624b30832a7695cd6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 476de54b5de9af5f45faf864bd1a46802e58975f98e38c1624b30832a7695cd6
SHA3-384 hash: 8adaf1b724a676443bdccf2877ab6303e3c0f7a1a78bfa450ac90184795d8d16378dc95cdb37f4b4bcb20dc52e2c962f
SHA1 hash: fa6f5a46624d6289b13ce7fecc270c70e3f3509a
MD5 hash: a76bcb468f153b7c8352fad0995693dc
humanhash: saturn-fanta-hotel-utah
File name:RFQ pdf.tar.gz.exe
Download: download sample
Signature AgentTesla
File size:542'720 bytes
First seen:2021-02-23 06:38:39 UTC
Last seen:2021-02-25 06:34:11 UTC
File type: gz
MIME type:application/x-tar
ssdeep 12288:vszdMMY06fVvkpv2axVQ+NsfUZhkdbduLJsDAE:OM8kWIax1hZ2b0LKZ
TLSH CAB4AE21229C9B0EE03EBB795114114F43F1A61AD727E68FBEE901DB7D56F408B32A17
Reporter cocaman
Tags:exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-23 06:39:11 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
8 of 47 (17.02%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments