MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ae2aaeb2938cf4c777be4aa192e4994020609f5640add8e7296de9ff34eb227. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0ae2aaeb2938cf4c777be4aa192e4994020609f5640add8e7296de9ff34eb227
SHA3-384 hash: 979c1bff1862b8ef6c5a1f33bcf9b9afcaa687d6a2aa2ec4d281c3b3524b2c03cdb2916d3cdb3e4b50964d60c00bf8c9
SHA1 hash: c81f446422337416cedb324fcc678015983fdb4c
MD5 hash: 5f3e254e5431866f3827e8b49b7d1435
humanhash: eight-oscar-sierra-mississippi
File name:Product_Sample_List.r09
Download: download sample
Signature AgentTesla
File size:390'787 bytes
First seen:2020-03-30 11:05:21 UTC
Last seen:Never
File type: r09
MIME type:application/x-rar
ssdeep 6144:jmkNaYfmc9K4fmKSS5i0MwZ5V245XG+lsJpRT0aoJapTpNQJPuknlwX57P2r0Qn:jmkNvhKcvn5oChtNsrREJapTpOtu0wXI
TLSH 8384235A872BE76FB741B18BCC8CC854741D782577ABEB8C41347B88E4E439AC67A04D
Reporter abuse_ch
Tags:AgentTesla COVID-19 r09


Avatar
abuse_ch
COVID-19 themed malspam distributing AgentTesla:

HELO: lh018.interdominios.com
Sending IP: 89.248.97.100
From: Michelle Chou <rohan.jayawardena@multywaychem.com>
Subject: COVID-19 Supplies (Masks, Gloves, & other products)
Attachment: Product_Sample_List.r09 (contains "Product_Sample_List.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Heye
Status:
Malicious
First seen:
2020-03-30 15:38:03 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
16 of 47 (34.04%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r09 0ae2aaeb2938cf4c777be4aa192e4994020609f5640add8e7296de9ff34eb227

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments