MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3594cfca6e6969c22f7528a6fc5f537dcb8a8762f8101dd0613572123a31ca9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b3594cfca6e6969c22f7528a6fc5f537dcb8a8762f8101dd0613572123a31ca9
SHA3-384 hash: e040a1b94f443fbf02510306db1ec18a783690edea329746a8363f8b4272e51e1d0718f9f8eda03964abb18208392be6
SHA1 hash: d6787fff2e719832289f7a8aa291b2b21465a2b0
MD5 hash: a8e678eb374939856ef6bf1f1deb5359
humanhash: bacon-ink-six-green
File name:SOA.zip
Download: download sample
Signature AgentTesla
File size:849'113 bytes
First seen:2021-01-22 13:17:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:O6zJD3zR8DKww7MKoo7UQC68MLHATYXt0Cyjk7oYkrCE0VJlFMbpwf2kXATNBOBM:OCZ39NwICYtXyjChFsm2pTNeBhUV
TLSH 1305330C9AA7319468F2563E7F3BF12D4F631637197403989647D790CB3A9B68E44CB8
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Spyware.Noon
Status:
Malicious
First seen:
2021-01-22 13:18:09 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b3594cfca6e6969c22f7528a6fc5f537dcb8a8762f8101dd0613572123a31ca9

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments