MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc4a1a0f095d5d633783cab4be7dcfccaefdcbd6c4187a91d1a2f594ec4ae6c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bc4a1a0f095d5d633783cab4be7dcfccaefdcbd6c4187a91d1a2f594ec4ae6c7
SHA3-384 hash: 5ae0d9cfeb972dab3c4e7230c83b2f4c820b8502fdd3831f4525caa41818d195a69e8a0ddc552a3788c519b4b858e3d1
SHA1 hash: 2b6d48a341c6c8137f1217bedd23356a47c11fa9
MD5 hash: 5f98117faeb66b90d98437b7a0af0237
humanhash: michigan-artist-lima-muppet
File name:Payment Receipt_pdf.gz
Download: download sample
Signature AgentTesla
File size:1'234'370 bytes
First seen:2020-04-21 06:43:43 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 24576:Qz3n8RR+rIdZO2YStBun2eLmDkpRhRy/zzS8TBaTWVgF+yEd+an7yx4:e8RR+8/z3PeRhRcze+/VgFhE7yS
TLSH 014533CFD227AF80594A5E6D28BB8C584A349F0017D1C1B63B6E217E1E917B059B738F
Reporter cocaman
Tags:AgentTesla COVID-19 gz


Avatar
cocaman
Malicious email
From: Ameen Hisham <ameen@amguae.net>
Received: from kpop.com (unknown [89.38.148.151])
Date: Mon, 20 Apr 2020 22:59:58 -0400
Subject: Payment Reversal/IBAN or SWIFT

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Script-AutoIt.Trojan.Aitinject
Status:
Malicious
First seen:
2020-04-21 14:19:13 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz bc4a1a0f095d5d633783cab4be7dcfccaefdcbd6c4187a91d1a2f594ec4ae6c7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments