MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85ef647415d595dbf38e4f7d9d9dd3d2c431c785814546218bd09c0900eb738a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 85ef647415d595dbf38e4f7d9d9dd3d2c431c785814546218bd09c0900eb738a
SHA3-384 hash: 7e2021e41af9696d07fceddd800dfc39459e9a43fbfdaa7eb197cec472e8893d9887ef7111c804eb9f00552d0688f889
SHA1 hash: 14a49d1fb6136a862ebe00cb489f9a02ebec81c0
MD5 hash: 07db514a9fa11d65e7110494f3952b0b
humanhash: white-foxtrot-berlin-tennis
File name:AWB & Shipping Document.Img.ace
Download: download sample
Signature AgentTesla
File size:397'539 bytes
First seen:2021-02-24 06:02:41 UTC
Last seen:2021-02-25 23:50:41 UTC
File type: ace
MIME type:application/octet-stream
ssdeep 6144:UhqdWB0Q0+AMCgi7sIz7p8zruhS7kdzyoMh+ws3iXcEXrjXqf/s:rsBAvK0S7kooM+pEcE4s
TLSH 6584236CAF5BD245582865CD14C59AAA57783AC80E9C5D0967CC0EF3F8BE40D1CE23B6
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
15
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-24 05:27:11 UTC
AV detection:
23 of 47 (48.94%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

ace 85ef647415d595dbf38e4f7d9d9dd3d2c431c785814546218bd09c0900eb738a

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments