MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8330697047d3c08dbc7d3dc30716f19e6d1d0e8300b547863437e611541d4399. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 2 File information 4 Yara Comments

SHA256 hash: 8330697047d3c08dbc7d3dc30716f19e6d1d0e8300b547863437e611541d4399
SHA3-384 hash: 87b630b73834d56851362c52494cf1de78fd8fde6b4c519da7367bd570b6e157dbb111a4a1cf76f950789fd491f037f1
SHA1 hash: 996eacaa42a6fbef7ce6fd28a58f6c847e59398e
MD5 hash: 8ca9040c240cfbb309ec9c2c85fb066a
humanhash: kitten-failed-michigan-island
File name:PO8434223.rar
Download: download sample
Signature AgentTesla
File size:498'138 bytes
First seen:2020-06-30 06:26:00 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:aV8bHdfkChSLn4VaTLrZ+nBA2VOzk5NA00Ff2:H9f5ismLrKAAxJC2
TLSH 66B43345F58F2F84F69A89E682109881712B44E82B9B4C8C26FDE7D33401196AFFD5DB
Reporter @abuse_ch
Tags:AgentTesla rar

Malspam distributing AgentTesla:

Sending IP:
From: SUNBELL <>
Subject: RE: URGENT ORDER FOR AD2428WCCSZ-RL,DS26LS32MJ/883 PO#8434223
Attachment: PO8434223.rar (contains "PO#8434223.exe")

AgentTesla SMTP exfil server:


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 30
Origin country US US
ClamAV Sanesecurity.Malware.27363.Rar5Heur.UNOFFICIAL
CERT.PL MWDB Detection:n/a
ReversingLabs :Status:Malicious
Threat name:ByteCode-MSIL.Trojan.Agensla
First seen:2020-06-30 06:27:06 UTC
AV detection:16 of 48 (33.33%)
Threat level:   2/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 15.00%

File information

The table below shows additional information about this malware sample such as delivery method and external references.



rar 8330697047d3c08dbc7d3dc30716f19e6d1d0e8300b547863437e611541d4399

(this sample)

Delivery method
Distributed via e-mail attachment