MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2a093ddcc8647c09f85340ebf88d5f77c7db8e9b384d04f2e68295d23d4d6d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b2a093ddcc8647c09f85340ebf88d5f77c7db8e9b384d04f2e68295d23d4d6d8
SHA3-384 hash: 56ec16891bda1b6b551d70fd61290bd48426d48363cc04a635cbe9b29e617a6c6200ef3caf8e6d1f266090ecab4fc9ca
SHA1 hash: f44dfe71bf1d425aa93f6858ff61ed9cb1311786
MD5 hash: 89b06d4199dac2c62321b4c2b3b0a0bd
humanhash: monkey-double-wisconsin-snake
File name:Purchase order.pdf.arj
Download: download sample
Signature AgentTesla
File size:420'314 bytes
First seen:2020-04-30 06:06:32 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:Vr6hxo9G+SXuCLYKdnxbuaj/e+IJ17rrTTXkEWaaJ86RrAkZsgRx/qe5BTqA3z7M:Vmf+SpLDdnJ2nH3Zsn/rSe2A3z7aP
TLSH 8C9423A04407B1BAD726414DA71F9FFCFBA0085AA504FF5B99D5E649EE3E66A700C303
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hjunkel.com.my
Sending IP: 209.58.149.97
From: Sales <sales@hjunkel.com.my>
Subject: Purchase Order
Attachment: Purchase order.pdf.arj (contains "Purchase order##.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Rrat
Status:
Malicious
First seen:
2020-04-30 06:35:39 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj b2a093ddcc8647c09f85340ebf88d5f77c7db8e9b384d04f2e68295d23d4d6d8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments