MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f56128a9a34cb436de763077bac5bd250cb8ab8596bc71d17d8bd3f8d0e5d9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8f56128a9a34cb436de763077bac5bd250cb8ab8596bc71d17d8bd3f8d0e5d9b
SHA3-384 hash: fff500057391bb351081175c8265007835725c488a36ffde55b4e0e435ac2d0c3e23ebc7041d4a6859daf21e7738b2e7
SHA1 hash: c8ee66e95f7dfc192a33ce912ce3a716cb33a532
MD5 hash: 2ba270e0fb049067606af1cf9ac3583b
humanhash: island-pizza-failed-arizona
File name:DHL Shipping Document.rar
Download: download sample
Signature AgentTesla
File size:373'614 bytes
First seen:2020-07-17 13:46:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:8tLrXXmT0PBMmNk3GCPxdCFIJ3BaX4dE2ns9bCB0XlUDDw2HNVi8QV5X2o/u:OXlPBMmG3PxdnndhnmC21uDwSV+jY
TLSH FD84221C0A845DB8D37A214735B363293F9DBAC3A36FB914B3574A891C50ACA2D3F91D
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 19:04:00 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 8f56128a9a34cb436de763077bac5bd250cb8ab8596bc71d17d8bd3f8d0e5d9b

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments