MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a22e5b38bddff6099018f19982aee558ad776c3c41e4b96c3bc0e18dd16b0917. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a22e5b38bddff6099018f19982aee558ad776c3c41e4b96c3bc0e18dd16b0917
SHA3-384 hash: c2a9f76a802eb287df9190788957f3d5afe0b62333c70bd21fa37471c492ce9b7a14f329ac52a9c79276a7c9801e7be8
SHA1 hash: 0377962ab31b2581437acf769084f320d2e70799
MD5 hash: 2a2d3af1065561b4403860a3986b7e67
humanhash: king-kilo-wyoming-diet
File name:vessel's doc.zip
Download: download sample
Signature AgentTesla
File size:519'197 bytes
First seen:2020-12-09 16:41:42 UTC
Last seen:2020-12-09 19:33:12 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:3KxGkFLOyXzdiK406yBq5irFGhQvxo98xJUzj3U7NqkxYXb:VkOgwF06pwchCoy87UNqkxYXb
TLSH 9EB423C171E073E1BED81367C422E3291977E97088E2EE67116A70F196273781F6CE5A
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
5
# of downloads :
168
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-12-09 13:32:29 UTC
AV detection:
22 of 27 (81.48%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a22e5b38bddff6099018f19982aee558ad776c3c41e4b96c3bc0e18dd16b0917

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments