MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c6dd0b18295829d752936a1f5a6a1c1d8f984dfcb78eb084ba629f3addb5462. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0c6dd0b18295829d752936a1f5a6a1c1d8f984dfcb78eb084ba629f3addb5462
SHA3-384 hash: 7ce169b2117aeee82234dce5fa712b7927314bcb882a485182ea6e33a7caa9add5f4aea71dbbc9366c77bd0a21044c49
SHA1 hash: ac46dc56afe883163b2b31535d06b28ba3190cd8
MD5 hash: 9bd41b297db712beb2fa7c7688fc3072
humanhash: arizona-wisconsin-colorado-lemon
File name:PRODUCTS INQUIRY.rar
Download: download sample
Signature AgentTesla
File size:381'872 bytes
First seen:2020-06-26 23:06:30 UTC
Last seen:2020-06-26 23:24:25 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:BWwer6jwrpwkLvdlrUR1KPbB5o58oj1iSGDTjazObWqjHr0dHKBVzOmI9A:crGwrpwmE1KPbB560xTHN5zO2
TLSH B58423F0917B1EE6537E4598C5A22EC26F134FB71654FD36BD9A2A3908FFD80112868C
Reporter jarumlus
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 23:08:05 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 0c6dd0b18295829d752936a1f5a6a1c1d8f984dfcb78eb084ba629f3addb5462

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments