MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36e711bd7928199c2ebdc92c20556fdcd7d4bfb1bfcc58539c7a588dab534443. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 36e711bd7928199c2ebdc92c20556fdcd7d4bfb1bfcc58539c7a588dab534443
SHA3-384 hash: 5a58fdaafdc7ddf37c9e5235fb901e6caa7f2fbc89f1f2ec85433e9bfb275b2b35d61b2ae27b5e3fd5afaf99243b8c91
SHA1 hash: 955f681e73f24845e4405891c153619884d5ebe2
MD5 hash: aed79e15405ba1e34b45482dc99bc331
humanhash: oven-pizza-lake-social
File name:purchase order.rar
Download: download sample
Signature AgentTesla
File size:502'189 bytes
First seen:2020-06-11 05:14:32 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:i3wUd+u967B5KNZv8RB12pOl9oG/MGlIDE4OHGV2B4u7QsyS0:qwuP9OPKNZv74YQZHbBLXyS0
TLSH 5DB4230CAAEA119918107D6E6DEDC8143E5D1BE8C721BFE963038EADF2094F516F53D1
Reporter cocaman
Tags:AgentTesla rar


Avatar
cocaman
Malicious email
From: Gloria Brooks-Ray>gbr@novigensci.com
Received: from novigensci.com (unknown [103.151.124.95])
Date: 10 Jun 2020 15:26:27 -0700
Subject: Re: New Purchase Order
Attachment: purchase order.rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-11 05:16:08 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 36e711bd7928199c2ebdc92c20556fdcd7d4bfb1bfcc58539c7a588dab534443

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments