MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a81b6946f231ea574e2f32b85f29c7e3601f196c74f45b2bf2e565c0542b159b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | a81b6946f231ea574e2f32b85f29c7e3601f196c74f45b2bf2e565c0542b159b |
|---|---|
| SHA3-384 hash: | d09235104ff9dd712818ba27ad1cf3a8134533680efce2e043b24bafda53306b448741e93d1c4a2276df9b47ffe4fd3c |
| SHA1 hash: | c323bd079762cdb1d039134ed2b1b47aa45d9d69 |
| MD5 hash: | 9df8b94c748dcef5f2a71039a4b05cef |
| humanhash: | twelve-river-wyoming-fifteen |
| File name: | PO 345678..rar |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 384'551 bytes |
| First seen: | 2020-07-24 07:55:42 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:8d2QuZdSctuIZ7ZYgNB914bRJ5TRe8OqK0v/A9krgkKp5ueQP6A8uLBi:Fbuc7ZYk4NTQtFkrgkk5jQP6AvA |
| TLSH | 728423530A35A1BAFB61C6F1D2A226133DB5D9123F0BCA03948D9C1EB1E54C3CEBD246 |
| Reporter | |
| Tags: | AgentTesla rar |
abuse_ch
Malspam distributing AgentTesla:HELO: vps.confidencegroup.co
Sending IP: 162.144.54.78
From: Jose Luis Carbacho Tamayo <edi@zaccaria.com.br>
Subject: PO 345678.
Attachment: PO 345678..rar (contains "PO 345678..exe")
AgentTesla SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-07-24 07:57:05 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.