MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afb9ecb6f16a306944146b82afd63096861b75de7a953d4aeb53084123b60250. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: afb9ecb6f16a306944146b82afd63096861b75de7a953d4aeb53084123b60250
SHA3-384 hash: 84c7c52277ee5305e37431c1e98143d32a6f41f36f514334e680c0366e649434c2ba8a2becff0158d7687efe8840ebcc
SHA1 hash: ee269899dfa9590cf8a599107558d670ea5f3202
MD5 hash: 8dd58ab6c80aaff10b3accdf9760ccbe
humanhash: missouri-iowa-pennsylvania-early
File name:SHIPPING DOC.rar
Download: download sample
Signature AgentTesla
File size:840'168 bytes
First seen:2020-10-29 20:03:06 UTC
Last seen:2020-10-29 20:10:50 UTC
File type: rar
MIME type:application/x-rar
ssdeep 24576:9pbBn1QHfi8M6Bw9OIuxnyCZeZAAWvNhZq9q:93yHtDZeZAbNXq9q
TLSH 2C053300CE33CE5F56CBD5CDF060540A0F58E708F2F9AE68864A197D9DED0BA78DA994
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Woreflint
Status:
Malicious
First seen:
2020-10-29 13:49:42 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar afb9ecb6f16a306944146b82afd63096861b75de7a953d4aeb53084123b60250

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments