MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a42fd588556f3e2c80557a02ef0e1874a4848bcb0a8f492d2f4ebe6b1262eb79. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a42fd588556f3e2c80557a02ef0e1874a4848bcb0a8f492d2f4ebe6b1262eb79
SHA3-384 hash: d346b3d26c34ba3a35251cf5f0fe2a373be30e96fc62f3a844eef23ee4a97abe5742ea5c32b96af043196e03df993bcd
SHA1 hash: cc8bc0dd0779f188f240e0f9094e6b8df042472e
MD5 hash: 7e875dfcfffdeeb0abb594d1e5e627ca
humanhash: zebra-cardinal-maine-green
File name:NEW URGENT PURCHASE ORDER PRODUCT LIST SHEET 003847 pdf.zip
Download: download sample
Signature AgentTesla
File size:676'275 bytes
First seen:2021-01-26 14:12:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:8BZgJ5QbLIBPkllbgdd9HV3buP9BqLkyMYc18SzMEk5uFqpDS:C05QbLHllbC9HVrU9BqAyM3tJk5uFZ
TLSH 41E423B5A2CA53EADFDA4C09542C83710EBBA44B4E3E40A23686134F5A7729DF14DD37
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-26 10:50:44 UTC
AV detection:
16 of 28 (57.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a42fd588556f3e2c80557a02ef0e1874a4848bcb0a8f492d2f4ebe6b1262eb79

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments