MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 91a4725c57de14d80b45c345df628622ab8e1d8e119251a3364f922ea2e89a10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 91a4725c57de14d80b45c345df628622ab8e1d8e119251a3364f922ea2e89a10
SHA3-384 hash: 06b0d5487a4fc7f9a3cfc64a76bb801086faf0a72e3626cb34746a4737ab4d89e899acb86a531c64ec7ca7b143349f14
SHA1 hash: 73bf2d927b0bffb11e2cdaf40cb6ef9257990831
MD5 hash: f5411c3e9a83294cb6ee5d65336724e8
humanhash: hot-speaker-sink-angel
File name:PO-894659-0857548-0299-Order_Specfications_Quote,xlxs.z
Download: download sample
Signature AgentTesla
File size:634'481 bytes
First seen:2020-08-17 08:07:58 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:OFAjgKyZYWKq8NlYJ7TxBnq36+Nm8EkeDLmZ7+/5mTtIRAX26:OCjUN8NS5TxBq3Xm8ALDBmTWRl6
TLSH 16D4239E19E7A27F742278AB3C6A9ACC4F711135C525C50C055EC6E22123F972B3E8ED
Reporter abuse_ch
Tags:AgentTesla geo KOR z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail-smail-vm82.hanmail.net
Sending IP: 211.231.106.157
From: 부산문화사 <pmwc6003@hanmail.net>
Subject: Re: 견적에 대한 새로운 요청
Attachment: PO-894659-0857548-0299-Order_Specfications_Quote,xlxs.z (contains "PO-894659-0857548-0299-Order_Specfications_Quote,xlxs.exe")

AgentTesla SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-17 08:09:07 UTC
AV detection:
10 of 47 (21.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 91a4725c57de14d80b45c345df628622ab8e1d8e119251a3364f922ea2e89a10

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments