MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 00287663fec630b39f462b4843758b2d181995827979080c6cf79ec7a619e7f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 2
| SHA256 hash: | 00287663fec630b39f462b4843758b2d181995827979080c6cf79ec7a619e7f5 |
|---|---|
| SHA3-384 hash: | 92f53d1d1e459969f707417ee934a1a245a668af8ccce3177040c371bda7555f3808524b7b0864dddd9ac6d90ff80e8e |
| SHA1 hash: | f120407d429b5f8c2fccecbe541c345947652ddc |
| MD5 hash: | e13a962b4ac5990292f07fe9c6bbe398 |
| humanhash: | massachusetts-colorado-batman-kansas |
| File name: | PO# M26804.z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 441'087 bytes |
| First seen: | 2020-05-28 10:54:08 UTC |
| Last seen: | 2020-05-28 12:27:39 UTC |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 12288:85MhsXhQNhkxE7EA8XOU4FaufkcIyk/9h3T/krJXJyUO:8YsXhQgTXHcauMcGgN0UO |
| TLSH | 809423B86CCC744CF4F6B9695C4C507FC559BE8091C80986CB783BBF567E8A90B94E82 |
| Reporter | |
| Tags: | AgentTesla z |
cocaman
Malicious emailFrom: =?UTF-8?B?6auY5qWgIEV4cG9ydCBEZXBhcnRtZW50?=<ac.general@yandex.ru>
Received: from yandex.ru (unknown [95.211.208.58])
Date: 28 May 2020 10:23:02 -0700
Subject: PO# M26804.
Attachment: PO# M26804.z
Intelligence
File Origin
# of uploads :
2
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Gathering data
Threat name:
Win32.Trojan.FormBook
Status:
Malicious
First seen:
2020-05-27 19:13:27 UTC
File Type:
Binary (Archive)
Extracted files:
276
AV detection:
19 of 31 (61.29%)
Threat level:
5/5
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.