MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83f59d228a20c78769ee1fa2527f4c7a7ff79079c55ae68eb1f4cb1c82737546. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: 83f59d228a20c78769ee1fa2527f4c7a7ff79079c55ae68eb1f4cb1c82737546
SHA3-384 hash: e11e4e02a5c541957a11c6a6ba5de9facfb5786b67d31cdba7ce7684fa32a5c46875e7b037c4faf1eea6a555d9f2901f
SHA1 hash: 96316df3be7727b0d66fb9c5554c491ddd0bc033
MD5 hash: a3c2a08b2adcbb3b8ea948b1041b6076
humanhash: cat-carolina-music-friend
File name:SAIF.pdf.r01
Download: download sample
Signature AgentTesla
File size:1'128'456 bytes
First seen:2020-03-14 06:25:52 UTC
Last seen:Never
File type: r01
MIME type:application/x-rar
ssdeep 24576:M3unkp/1IlxZbRSgUL9TrhSdp+8JZPuXTU140r2L:AukptYxZA/5TrhShuXwA
TLSH 833533B72622DEE522CC2275DFBC8B56D31B35EB3E2A51D11294C32E3FD31A1297A504
Reporter cocaman
Tags:AgentTesla COVID-19 delivery:attachment r01

Intelligence


File Origin
# of uploads :
1
# of downloads :
97
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-03-14 17:26:05 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

AgentTesla

r01 83f59d228a20c78769ee1fa2527f4c7a7ff79079c55ae68eb1f4cb1c82737546

(this sample)

Comments



Avatar
Corsin Camichel commented on 2020-03-14 06:28:33 UTC

COVID-19 themed malspam

Subject: Preventive Measures - COVID-19
From: "SAIF-Zone" <admin.donotreply@saif-zone[.]com> (spoofed)