MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c153d9ac2d4d19f277d1e91b06bf604ea1ccb21556c03792ac833dd3cdfccac8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c153d9ac2d4d19f277d1e91b06bf604ea1ccb21556c03792ac833dd3cdfccac8
SHA3-384 hash: a823bb8969cd3b887d429847fdd7fbd6feca3107fddd0e8890f9901f4e64dc333d5364a01b7bb76dd3b38b147b7bb54f
SHA1 hash: 0e7fe556095696592f311c7687fa254cc19b91f5
MD5 hash: 96929f86d90db1be2c469d2eaed47d00
humanhash: juliet-seventeen-wolfram-west
File name:탑엔지니어링_PO73284383_2020-08-17_dwg.z
Download: download sample
Signature AgentTesla
File size:680'604 bytes
First seen:2020-08-17 06:25:07 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:ei/fY5xrf+/QkOCcKIsnlFRIG/qGmbY7n2HOdp3CjlZBWGFqr:BwXf+2CcKIsnloGxm1HO3yjlZFqr
TLSH 4AE423B362426422EFE2805B9716DFB9A9CF316293593F50E32833ED1579BF00568DD4
Reporter abuse_ch
Tags:AgentTesla geo KOR z


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: mail-smail-vm47.hanmail.net
Sending IP: 203.133.180.235
From: 김장민 <dewpack@dewpack.com>
Subject: 듀팩장원기계 입니다 - PO73284383
Attachment: 탑엔지니어링_PO73284383_2020-08-17_dwg.z (contains "탑엔지니어링_PO73284383_2020-08-17_dwg.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Remcos
Status:
Malicious
First seen:
2020-08-17 06:27:07 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z c153d9ac2d4d19f277d1e91b06bf604ea1ccb21556c03792ac833dd3cdfccac8

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments