MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7063e9e1a761a64941721578d820514f01fdd5b812fc54b7b5a6817c25b43a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b7063e9e1a761a64941721578d820514f01fdd5b812fc54b7b5a6817c25b43a9
SHA3-384 hash: 32054c3c58792d5de97618ae8bf5a713179e6369266af09cf10a643ed1a88ab1f56df11ae2c3046c51c08f5762a6f1e8
SHA1 hash: 5815eba621f6d3d21401197cefe6186807714d0f
MD5 hash: 510092bb8a375f746adfe2908b9515dd
humanhash: alaska-venus-floor-crazy
File name:GBP789,828.96.zip
Download: download sample
Signature AgentTesla
File size:514'624 bytes
First seen:2020-08-11 11:19:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:/ykKotGi1dDktSVetYVAcOO1KaDc1V9QgPR5BKRJxUKZVrFCyy5UMcS9JL4C3eKg:KgLTOZsU8FI5T9a5+jwzdQC8p6TINI5
TLSH 01B423E590D5396B0C2F0AF1B488F0D119EE2652AC03B77594BC99C22FF4D86D3D5A2B
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: hm-gmbh-lb.com
Sending IP: 103.99.1.226
From: Amy Gan <h.marx@hm-gmbh-lb.com>
Subject: [EXT] RE: Parts and Machine Statement of account as of 31 Jul 2020
Attachment: GBP789,828.96.zip (contains "GBP789,828.96.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-08-11 11:21:05 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip b7063e9e1a761a64941721578d820514f01fdd5b812fc54b7b5a6817c25b43a9

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments