MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5003fc3c5ac4e5b37a81a30bf74664bc5f3212d5fdecee0d3e809b412e51316c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 5003fc3c5ac4e5b37a81a30bf74664bc5f3212d5fdecee0d3e809b412e51316c
SHA3-384 hash: d61458fb89f629b306e28b27d2ae6c1d1b2214e35782f0cddd9f14015ab08f0cc7d41edb33059917a60c89a6b05ad022
SHA1 hash: b2d02b9dcd24ab7bbd5ba5adc46ddbe69f329d79
MD5 hash: d2f6d3fdbaa8b9e11ef2a9ceaa2ca657
humanhash: hawaii-edward-hamper-fish
File name:Swift-Copy.zip
Download: download sample
Signature AgentTesla
File size:524'293 bytes
First seen:2021-02-08 13:36:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:8d5UPN+nbR28c/JV2XvsbUVssAc8rw3yJ8gIS9j3ci:X0TxX4cBAc8rw3EJ9jD
TLSH 7FB4236CF604D5238B20F62EE06D17E6A334DEA0B9306F193FD986A2556C237116E1E7
Reporter fabjer
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-08 10:26:10 UTC
AV detection:
15 of 28 (53.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 5003fc3c5ac4e5b37a81a30bf74664bc5f3212d5fdecee0d3e809b412e51316c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments