MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d1b17c48704e0eaac3dae719e3400a4b88c7b8cfc1fc3ee9c0eeb157603d0a4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 9d1b17c48704e0eaac3dae719e3400a4b88c7b8cfc1fc3ee9c0eeb157603d0a4
SHA3-384 hash: c61aca90017b4f8225737ae614d5aea1b5059030703f20e468951b74be5c3eaaf6f7a6c00418e0b3e2b8b4e6fe217cd8
SHA1 hash: e668fbc0bb3b6ae54625ab22dfa981df4a267b42
MD5 hash: 691a0ec1b3eb5baa84012a33d4d99e09
humanhash: tennis-equal-august-july
File name:INV-2462624543.zip
Download: download sample
Signature AgentTesla
File size:803'958 bytes
First seen:2021-02-11 16:59:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:C9+Ohxj7R9n2tuvJWa8S/vheG314+m59Q9icvEuNYrWvCiaSOYIq:6J7Rpyu8tG3139iKJNYrWCVFXq
TLSH 4705236E60C952FEBEDAA16504F6833924D350FE1E0267B949609F52ECB40F93DC4CAD
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-11 10:06:05 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 9d1b17c48704e0eaac3dae719e3400a4b88c7b8cfc1fc3ee9c0eeb157603d0a4

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments