MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 878bec279ee1ebc8a5305147c1cdf034ff32f29e3a2409c900805f5e38f5c7c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 878bec279ee1ebc8a5305147c1cdf034ff32f29e3a2409c900805f5e38f5c7c4
SHA3-384 hash: bdccfbf662893f7f304a8b0c7d1b521e1f193c46eedba571087a439ff01f22c49be70f0313785aabdc8683c6073fc65c
SHA1 hash: 791d88eb6bd884b7bd9fa1646c35a6b46b218e52
MD5 hash: a7e2967c017c8ffe4afbd65c5fd85684
humanhash: nine-football-magazine-freddie
File name:Request Quotation(1).7z
Download: download sample
Signature AgentTesla
File size:579'750 bytes
First seen:2020-12-17 11:53:17 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 12288:TcrmrZir5Gs4d+bfldxWSAFBshlsFJUlO7KWclzylbAbm8T18Ka:TcrIZirZ4I77ISAPs05n2z6Abmz
TLSH 5EC423764A858440F8CA2F75CAED5C382FB00B1BF9CA4BB570694DBED95C0D963A04ED
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
204
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-16 19:10:00 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

7z 878bec279ee1ebc8a5305147c1cdf034ff32f29e3a2409c900805f5e38f5c7c4

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments