MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a68ffbaa89c4c11e139a54d98a864618a131f224fac495eb6acdd0c1461b0acd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a68ffbaa89c4c11e139a54d98a864618a131f224fac495eb6acdd0c1461b0acd
SHA3-384 hash: 6e0630a750ef753d5b31e1429278aa8ea7f327c63a5c6cd67ebd37ec7f797d1a5272a2f263784315e6f1c45356a237b6
SHA1 hash: 44a254b6fdb98e9cc6cbf5f8ad7d961da602db1e
MD5 hash: a0a44818c63e2187cad3a3f896d76c95
humanhash: vegan-green-apart-connecticut
File name:Payment Slip.zip
Download: download sample
Signature AgentTesla
File size:518'582 bytes
First seen:2020-11-10 14:12:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:GqNg9+zHmIbnLMxh8rxSGP79kYenSL5Pie85LJ+JfnQI/a:/Nbnah8YGJEn3DWne
TLSH 06B423EBA4D52C109A345B8D5CFA03CAE1F4A51CE679115C7B3F01748A7EA3FD248B92
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
187
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-10 08:05:55 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip a68ffbaa89c4c11e139a54d98a864618a131f224fac495eb6acdd0c1461b0acd

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments