MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d30eb3a1fcbca345659c66a928c4029b052e16d0237332d2cf0a933faeb82f1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d30eb3a1fcbca345659c66a928c4029b052e16d0237332d2cf0a933faeb82f1f
SHA3-384 hash: e605289642351602b68eaf739fbbcfa328cbe3754a91985cac5cc0636e79886deb5d919d3e09dfe800ff7b6f7d771064
SHA1 hash: 824fd1f50acee173c93cebb86d114bad344702c4
MD5 hash: e19468ecad9736ac3a195d5b59effcaf
humanhash: jersey-fifteen-high-freddie
File name:e19468ecad9736ac3a195d5b59effcaf.exe
Download: download sample
Signature AgentTesla
File size:1'885'936 bytes
First seen:2021-02-04 18:03:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 6144:j2cPNAfYCxx6xlMKJSxkw4RNIItpddRYiaffr88kWZKv7mvsc/wRvrlnHM7X1HxD:j2j
TLSH 5D95A6976F0F60899C77C5EBC2F369AEDE89BA781077094914E0D7A3F2570849F04EA1
Reporter abuse_ch
Tags:AgentTesla exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
n/a
Score:
21 / 100
Signature
Machine Learning detection for sample
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-02-04 18:04:07 UTC
AV detection:
12 of 29 (41.38%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
d30eb3a1fcbca345659c66a928c4029b052e16d0237332d2cf0a933faeb82f1f
MD5 hash:
e19468ecad9736ac3a195d5b59effcaf
SHA1 hash:
824fd1f50acee173c93cebb86d114bad344702c4
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AgentTesla

Executable exe d30eb3a1fcbca345659c66a928c4029b052e16d0237332d2cf0a933faeb82f1f

(this sample)

  
Delivery method
Distributed via web download

Comments