MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b7063e9e1a761a64941721578d820514f01fdd5b812fc54b7b5a6817c25b43a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 4
| SHA256 hash: | b7063e9e1a761a64941721578d820514f01fdd5b812fc54b7b5a6817c25b43a9 |
|---|---|
| SHA3-384 hash: | 32054c3c58792d5de97618ae8bf5a713179e6369266af09cf10a643ed1a88ab1f56df11ae2c3046c51c08f5762a6f1e8 |
| SHA1 hash: | 5815eba621f6d3d21401197cefe6186807714d0f |
| MD5 hash: | 510092bb8a375f746adfe2908b9515dd |
| humanhash: | alaska-venus-floor-crazy |
| File name: | GBP789,828.96.zip |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 514'624 bytes |
| First seen: | 2020-08-11 11:19:10 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:/ykKotGi1dDktSVetYVAcOO1KaDc1V9QgPR5BKRJxUKZVrFCyy5UMcS9JL4C3eKg:KgLTOZsU8FI5T9a5+jwzdQC8p6TINI5 |
| TLSH | 01B423E590D5396B0C2F0AF1B488F0D119EE2652AC03B77594BC99C22FF4D86D3D5A2B |
| Reporter | |
| Tags: | AgentTesla zip |
abuse_ch
Malspam distributing unidentified malware:HELO: hm-gmbh-lb.com
Sending IP: 103.99.1.226
From: Amy Gan <h.marx@hm-gmbh-lb.com>
Subject: [EXT] RE: Parts and Machine Statement of account as of 31 Jul 2020
Attachment: GBP789,828.96.zip (contains "GBP789,828.96.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-08-11 11:21:05 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.