MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b3594cfca6e6969c22f7528a6fc5f537dcb8a8762f8101dd0613572123a31ca9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 5
| SHA256 hash: | b3594cfca6e6969c22f7528a6fc5f537dcb8a8762f8101dd0613572123a31ca9 |
|---|---|
| SHA3-384 hash: | e040a1b94f443fbf02510306db1ec18a783690edea329746a8363f8b4272e51e1d0718f9f8eda03964abb18208392be6 |
| SHA1 hash: | d6787fff2e719832289f7a8aa291b2b21465a2b0 |
| MD5 hash: | a8e678eb374939856ef6bf1f1deb5359 |
| humanhash: | bacon-ink-six-green |
| File name: | SOA.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 849'113 bytes |
| First seen: | 2021-01-22 13:17:26 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:O6zJD3zR8DKww7MKoo7UQC68MLHATYXt0Cyjk7oYkrCE0VJlFMbpwf2kXATNBOBM:OCZ39NwICYtXyjChFsm2pTNeBhUV |
| TLSH | 1305330C9AA7319468F2563E7F3BF12D4F631637197403989647D790CB3A9B68E44CB8 |
| Reporter | |
| Tags: | AgentTesla |
Intelligence
File Origin
# of uploads :
1
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2021-01-22 13:18:09 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropped by
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.