MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 91a4725c57de14d80b45c345df628622ab8e1d8e119251a3364f922ea2e89a10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | 91a4725c57de14d80b45c345df628622ab8e1d8e119251a3364f922ea2e89a10 |
|---|---|
| SHA3-384 hash: | 06b0d5487a4fc7f9a3cfc64a76bb801086faf0a72e3626cb34746a4737ab4d89e899acb86a531c64ec7ca7b143349f14 |
| SHA1 hash: | 73bf2d927b0bffb11e2cdaf40cb6ef9257990831 |
| MD5 hash: | f5411c3e9a83294cb6ee5d65336724e8 |
| humanhash: | hot-speaker-sink-angel |
| File name: | PO-894659-0857548-0299-Order_Specfications_Quote,xlxs.z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 634'481 bytes |
| First seen: | 2020-08-17 08:07:58 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 12288:OFAjgKyZYWKq8NlYJ7TxBnq36+Nm8EkeDLmZ7+/5mTtIRAX26:OCjUN8NS5TxBq3Xm8ALDBmTWRl6 |
| TLSH | 16D4239E19E7A27F742278AB3C6A9ACC4F711135C525C50C055EC6E22123F972B3E8ED |
| Reporter | |
| Tags: | AgentTesla geo KOR z |
abuse_ch
Malspam distributing AgentTesla:HELO: mail-smail-vm82.hanmail.net
Sending IP: 211.231.106.157
From: 부산문화사 <pmwc6003@hanmail.net>
Subject: Re: 견적에 대한 새로운 요청
Attachment: PO-894659-0857548-0299-Order_Specfications_Quote,xlxs.z (contains "PO-894659-0857548-0299-Order_Specfications_Quote,xlxs.exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-17 08:09:07 UTC
AV detection:
10 of 47 (21.28%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.