MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f3557e1832ad21e66af00230337abd85127773aedcef3fe9ff4bf273e8ceefd0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f3557e1832ad21e66af00230337abd85127773aedcef3fe9ff4bf273e8ceefd0
SHA3-384 hash: 0bf257e18e5a1c6c7369e383252c3fb6d139b1df1f5bc3c45dddf432779dc70d6412b24427e2cd83db1823739c364ff3
SHA1 hash: f6617029da35403bd5631f2112e10e4c4b6746d6
MD5 hash: 94041b90425f5df80d55f407d64f637d
humanhash: neptune-tango-high-connecticut
File name:DHL AWB INVOICE.gz
Download: download sample
Signature AgentTesla
File size:431'629 bytes
First seen:2020-04-16 11:15:07 UTC
Last seen:2020-04-17 05:16:19 UTC
File type: gz
MIME type:application/x-rar
ssdeep 6144:pfU2LOK+r/qBbrN5CIU0wL1dZAPIR8pCxLrC+XLB9NzD8qtcjWlZbeRazh:pf8K+r/qxN5NtGkIR3x/Ld9NYqac5h
TLSH 569423E3A5C1738677EC263DAB3D0FB36D84E59353AB5F6A08B4437DC2A0859D40A742
Reporter cocaman
Tags:AgentTesla gz

Intelligence


File Origin
# of uploads :
2
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-04-16 09:28:15 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
21 of 31 (67.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz f3557e1832ad21e66af00230337abd85127773aedcef3fe9ff4bf273e8ceefd0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments