MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c9c44182868f91d736d02f2ef8affbad3ded1952ec30dc38dc5322a6daf80668. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | c9c44182868f91d736d02f2ef8affbad3ded1952ec30dc38dc5322a6daf80668 |
|---|---|
| SHA3-384 hash: | 13249c447cf05e4c145078ec899dcc8199f60773181661ff1c0a7c19ff487a3a6528e0f29481c5f75f0caa97ba8706ea |
| SHA1 hash: | ab49f07797776813687d6c1d294901e5cecc8b77 |
| MD5 hash: | fad93009675a79c98c375d8c437c44c2 |
| humanhash: | maine-undress-oklahoma-five |
| File name: | DKL009202007.gz |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 439'020 bytes |
| First seen: | 2020-08-05 06:31:50 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:Z2xB1aKPabV+0FVi65/RB/LQJT/ZtJil5x2/FXnXGfKD/WYU6vD2BfWuhSctSgTP:gtyxPI8vqO2ZXGfe/RvqNW4SgT6xzk |
| TLSH | AF94237B69B0E5EAF08B6C49324D94C87BDA7546ECF2E397F5C70988B028935C436172 |
| Reporter | |
| Tags: | AgentTesla gz |
abuse_ch
Malspam distributing AgentTesla:From: "Rph: Syed Mohammad Imran" <info@assag.de>
Subject: QUOTATION
Attachment: DKL009202007.gz (contains "DKL009202007.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-05 06:33:07 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Suspicious File
Score:
0.45
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.