MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f90b33b7a7cf56b98f584bcc4b49b41c2d35ca37d1a0f382e1239857d34e65fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f90b33b7a7cf56b98f584bcc4b49b41c2d35ca37d1a0f382e1239857d34e65fb
SHA3-384 hash: 398161c59487bfd985a2e0ce5df6d0f822b7329cfe8a27334904916ec2f63a407c314aecf12f1bcdf0d7d30024699980
SHA1 hash: 116ca86a24b0eee1f8058e867cdeb9c58fd78674
MD5 hash: b74c1564ede5ce70f78bf379f2241b30
humanhash: washington-wyoming-uncle-autumn
File name:Bank Details-86543123456.zip
Download: download sample
Signature AgentTesla
File size:434'003 bytes
First seen:2021-03-01 11:10:09 UTC
Last seen:2021-03-10 03:20:18 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:4pe1+L9I/qzMfIpVJ0NSvC9PwNARzeXwhNbjUoYSk:oemI/aVJc9INAFE+lUP
TLSH 58942379AA21C977C3A7D5E63A90F808231B934D0E7CD36B1A00D72D11CAE5EC7DAD49
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
12
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-03-01 10:05:54 UTC
AV detection:
7 of 47 (14.89%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip f90b33b7a7cf56b98f584bcc4b49b41c2d35ca37d1a0f382e1239857d34e65fb

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments