MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b453272ea244b17aa18903818a2d1d73e9618afd534a55019834594535499c4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b453272ea244b17aa18903818a2d1d73e9618afd534a55019834594535499c4f
SHA3-384 hash: 4a43447f97cfd10399fa76d7c9925e7f88bb3904bd83234556d7f4cc01abf4ca093386f7b84b8278a2ead58099ee3107
SHA1 hash: 00cac745925010ab015062e4c8a99fe1a67073f2
MD5 hash: 374a23ba2f13c4c8292dd6e4c7583f74
humanhash: seventeen-india-potato-carbon
File name:9000292052 PL.zip
Download: download sample
Signature AgentTesla
File size:633'148 bytes
First seen:2020-11-04 15:12:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:pLUo4BQrFkiVlI68N6mcGpzgpUdsAw1d0S0qIZGyPvbGhnCws9OJ6gNqy4Nt:pL86eA83cWgpxEdPvbOA9kEt
TLSH F2D4239F82D744F6CF66FD56B93ACA737A190110E8B5297DE63C9EEC0202E23E406715
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-03 13:06:04 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b453272ea244b17aa18903818a2d1d73e9618afd534a55019834594535499c4f

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments