MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d2bc1981d95dd0ab6a38d29c6485b8dad25387509e215d37990d8ac3709b7dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4d2bc1981d95dd0ab6a38d29c6485b8dad25387509e215d37990d8ac3709b7dd
SHA3-384 hash: 603966edb3be19d8d66bde35dced5cec3d05074eadce5ab2688f06a6bd9c3b6117bc2e9469fdd58f21f56c7a7f4adecc
SHA1 hash: 11582163b415b492db6169c7fdc6bac717773aa2
MD5 hash: b3dae4486b563ebca03a9c8280348163
humanhash: hydrogen-utah-uranus-sixteen
File name:INVOICE.pdf.gz
Download: download sample
Signature AgentTesla
File size:560'883 bytes
First seen:2020-09-15 05:30:30 UTC
Last seen:2020-09-15 05:31:25 UTC
File type: gz
MIME type:application/x-rar
ssdeep 12288:0R939iaxyes4jThVLoMNrWP9kHYk6DXakYtgThFUO:m3Nyz2FNNrc9Ee7ThOO
TLSH CBC42345E11E8854180C1ACAF1D49EAE1D59FB0F41D3F8E6EA8A8014D3CA1FED45EFE6
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: JASON LEE <sales@hzafl.com>
Received: from hzafl.com (unknown [45.137.22.76])
Date: 14 Sep 2020 21:15:40 -0700
Subject: RE: Invoice
Attachment: INVOICE.pdf.gz

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Taskun
Status:
Malicious
First seen:
2020-09-15 03:29:18 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 4d2bc1981d95dd0ab6a38d29c6485b8dad25387509e215d37990d8ac3709b7dd

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments