MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8a55f7905464d9415a0428cae8fc86d43b892855600d65599a40aec328a17ee5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 2 File information 4 Yara Comments

SHA256 hash: 8a55f7905464d9415a0428cae8fc86d43b892855600d65599a40aec328a17ee5
SHA3-384 hash: 50761f5d95c28359310b6085270e8c5786671a6a43690f35365cdae7063b932c948f33aec3e5ec3c16208bc38c3a17eb
SHA1 hash: b263912782d856d28b39f12d749bfd82bfde4c17
MD5 hash: 0a92b490120805982b1b10058cfe2af8
humanhash: bacon-wyoming-north-orange
File name:signed_19272.zip
Download: download sample
Signature AgentTesla
File size:399'488 bytes
First seen:2020-07-01 01:33:01 UTC
Last seen:2020-07-01 08:30:41 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:1UyNPw/240qB1HZObvWz97nf5av9GEXWk:fNP0B1HZEWTiB
TLSH 1A8423A2B9774B5D386BC2B8FEC10C5A54F2D32048E27AAD874B07D1F84BD41E4B6746
Reporter @jarumlus
Tags:AgentTesla

Intelligence


Mail intelligence
Trap location Impact
Global High
IT Italy Low
CH Switzerland Low
# of uploads 2
# of downloads 24
Origin country FR FR
ClamAV SecuriteInfo.com.Trojan.PWS.Siggen2.51183.23367.5194.UNOFFICIAL
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/8a55f7905464d9415a0428cae8fc86d43b892855600d65599a40aec328a17ee5/
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Kryptik
First seen:2020-06-30 12:53:16 UTC
AV detection:25 of 48 (52.08%)
Threat level:   2/5
Spamhaus Hash Blocklist :Suspicious file
VirusTotal:Virustotal results 18.75%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 8a55f7905464d9415a0428cae8fc86d43b892855600d65599a40aec328a17ee5

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments