MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b56fc042594702d9cb2eb4507b72fadc9af9227f0dd7b48a55ec412809324901. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b56fc042594702d9cb2eb4507b72fadc9af9227f0dd7b48a55ec412809324901
SHA3-384 hash: 511ba0dff5f404825a63eb56600ab76d753d34653175a33d725bc16c05302f47c8b572710a72b83373356b9f9601b898
SHA1 hash: d2ef6241647b1c9f15f2edc29e1e8344f158f22a
MD5 hash: e8ea1029953c5cb6588fcf9e704fb14b
humanhash: nitrogen-cup-ten-oklahoma
File name:file
Download: download sample
Signature AgentTesla
File size:583'129 bytes
First seen:2021-01-13 17:54:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:SE6mNw2ZiPZNWYEbf958qxFouln5QI5MRYBA7X:fBa2ZKQYE5O0FoU5QI507X
TLSH 58C423C831570B13A7A52869B4A2214955FEF88ADB3AE3B070512376D0D31DEBB35F63
Reporter fabjer
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-13 17:49:00 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b56fc042594702d9cb2eb4507b72fadc9af9227f0dd7b48a55ec412809324901

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments