MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac930cb0c22a9a20144cc740b3f02cf4f59b47349102708e7954a327e5d42302. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ac930cb0c22a9a20144cc740b3f02cf4f59b47349102708e7954a327e5d42302
SHA3-384 hash: 45c81c4d06e6f2fbd12c2723639db72586d41c654e3cb396adb156d1868d370427ab3d13847523d8d5652bc76d39a9bc
SHA1 hash: 817f2043307a0ccbc83a1a2e388257c68cbe6675
MD5 hash: 7cc1018d35442394f55e9187e4527a3a
humanhash: speaker-fillet-kentucky-river
File name:SIGNED AND STAMPED INVOICE.pdf.rar
Download: download sample
Signature AgentTesla
File size:370'038 bytes
First seen:2020-06-12 08:48:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:46r2Z1KfGhqvSi9KRh/48c2eeRh/qioeo+wPFrKYoBMw7SaMLsiYWGpV2Mwrv+6r:466vgvSiUr62dhxoeG1LQZWGpVpIvN
TLSH BE74234ECE5B8997ACC27506C3A7885AB6DC389ADB083ED96C72428174D51CFE1C35CB
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-12 08:50:09 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar ac930cb0c22a9a20144cc740b3f02cf4f59b47349102708e7954a327e5d42302

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments