MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd963eb7079356f5bc07e775d784055f2e93fba7edf096898e9303a50895cb2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bd963eb7079356f5bc07e775d784055f2e93fba7edf096898e9303a50895cb2c
SHA3-384 hash: b6ad41ba1ea6d080213ec2ff55bee95f45c4fb582e84c258595e5a367e7e5dd8a9db089f6e4370ea1c3e30213fb0c809
SHA1 hash: 6c12470f3a91ff8d7ffbfe614acf6b234225d6bd
MD5 hash: c4ea0c4068e60ad5ef4f0544e7f49cca
humanhash: muppet-cardinal-twenty-september
File name:Payment copy.gz
Download: download sample
Signature AgentTesla
File size:756'954 bytes
First seen:2020-07-20 11:16:23 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:lQdFzzG3naY/AIBQ4x+8AHrdv2F430rtgp/fv5aGtYE63b3:YzzG3fAIBQ4MdF3ytgNv5aGtYDL3
TLSH EEF423D90301235A513F769352CCACA34C9BAD2645826D096F49FC94B9DBF339EAE218
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email
From: Account <accountdpt2019@superonline.com>
Received: from superonline.com (unknown [185.99.253.69])
Date: 20 Jul 2020 04:14:29 -0700
Subject: Purchase inquiry
Attachment: Payment copy.gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-20 11:17:53 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz bd963eb7079356f5bc07e775d784055f2e93fba7edf096898e9303a50895cb2c

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments