MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcb32ddbf347a86c90ff65cbc24eaa34224bd0220f6c4c54742e458c6c434bbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dcb32ddbf347a86c90ff65cbc24eaa34224bd0220f6c4c54742e458c6c434bbc
SHA3-384 hash: 83bf81c7b143ef8b47295fe45896110b2e0f0cda72b86824ed430327d246bc2f87d13ea6b72fc5c482a38c0b5ce57a2d
SHA1 hash: 5d4ea290fed2802731ae1a53e640b67664f365cf
MD5 hash: 64a7191cea9d7a8701495f4fb1e01d8f
humanhash: utah-stairway-timing-football
File name:PO# 5109220310.zip
Download: download sample
Signature AgentTesla
File size:387'064 bytes
First seen:2020-07-03 05:00:47 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:LUBf9OdqV/rh/cEBypNcm5w3fld20jL+fogvJQSmNhvdCeFAYPZ0:wB8dqlrhLBsHqAogvJQSmb4Pka
TLSH EA8423FD9146D1EF4D7D8B6B09F9992871A33CC968F4910491EA67DA3DC229C1B10F0C
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Avemariarat
Status:
Malicious
First seen:
2020-07-03 05:02:05 UTC
AV detection:
19 of 28 (67.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip dcb32ddbf347a86c90ff65cbc24eaa34224bd0220f6c4c54742e458c6c434bbc

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments