MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4432f75ba5ee37e8d0c5495bb7c3648e9a748806741f9bfd2548c80f67cfa1c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d4432f75ba5ee37e8d0c5495bb7c3648e9a748806741f9bfd2548c80f67cfa1c
SHA3-384 hash: 9d3309e3966d9ca563e31ca09106f2cae42e32c8ca2d71700ce6f2ce33810797963fbae25f0a9c8c286b7155bcbf34bd
SHA1 hash: 12dd805b52a4790cf937f7dc385ce687a3861ed7
MD5 hash: d5392ef04bef0d3e01b341d5a36c2a45
humanhash: purple-wolfram-undress-undress
File name:Payment slip.zip
Download: download sample
Signature AgentTesla
File size:346'576 bytes
First seen:2021-01-21 12:04:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:5irgHPHuc7n7ZFtsLOhBL39IV4p/1w2vxj4ezXlCZgSDGVBnRQYE3XKI5/DXroQM:5irWvusVFaLOhF9/5vxj4saKVBnsaI5a
TLSH 8B74235CE15F8B708E29F3661608C1C59BB4830743BCFA9AD35884DED24928DB7C96BD
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
136
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-21 12:05:05 UTC
AV detection:
15 of 46 (32.61%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip d4432f75ba5ee37e8d0c5495bb7c3648e9a748806741f9bfd2548c80f67cfa1c

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments