MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 65cf63b950f32653a891754d6b52686a4de351a3aeb1324907d3b7c4cc7282f7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 65cf63b950f32653a891754d6b52686a4de351a3aeb1324907d3b7c4cc7282f7
SHA3-384 hash: 87027d7ded79e8bd79d56fa640073d4facb7d704bac5f9614a17d15812c9289c1eb004ddf65a2c198c1c10d7a3e8c15c
SHA1 hash: f26bb84555eb01073294e0c9b9a9659e377ca695
MD5 hash: 2cd5dbd4dc815734edf7be4cb6b68ae0
humanhash: oranges-edward-east-juliet
File name:NEW ORDER.zip
Download: download sample
Signature AgentTesla
File size:509'053 bytes
First seen:2021-02-17 01:08:41 UTC
Last seen:2021-02-18 05:28:39 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:f3QT+2UNiASP5Q+M635lH4cVEuhc1Jupj6Y+MuzqLWUrqNQS2B1S:LNiASxQMjH4cVVNpj6Y+7zXRr2B1S
TLSH 52B42313FB490B5995C90663327CDBB9DAC493BE9ABD012D4F99B307BA3326B44099C4
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
4
# of downloads :
104
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-02-16 06:27:30 UTC
AV detection:
5 of 45 (11.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 65cf63b950f32653a891754d6b52686a4de351a3aeb1324907d3b7c4cc7282f7

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments