MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c153d9ac2d4d19f277d1e91b06bf604ea1ccb21556c03792ac833dd3cdfccac8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | c153d9ac2d4d19f277d1e91b06bf604ea1ccb21556c03792ac833dd3cdfccac8 |
|---|---|
| SHA3-384 hash: | a823bb8969cd3b887d429847fdd7fbd6feca3107fddd0e8890f9901f4e64dc333d5364a01b7bb76dd3b38b147b7bb54f |
| SHA1 hash: | 0e7fe556095696592f311c7687fa254cc19b91f5 |
| MD5 hash: | 96929f86d90db1be2c469d2eaed47d00 |
| humanhash: | juliet-seventeen-wolfram-west |
| File name: | 탑엔지니어링_PO73284383_2020-08-17_dwg.z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 680'604 bytes |
| First seen: | 2020-08-17 06:25:07 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 12288:ei/fY5xrf+/QkOCcKIsnlFRIG/qGmbY7n2HOdp3CjlZBWGFqr:BwXf+2CcKIsnloGxm1HO3yjlZFqr |
| TLSH | 4AE423B362426422EFE2805B9716DFB9A9CF316293593F50E32833ED1579BF00568DD4 |
| Reporter | |
| Tags: | AgentTesla geo KOR z |
abuse_ch
Malspam distributing AgentTesla:HELO: mail-smail-vm47.hanmail.net
Sending IP: 203.133.180.235
From: 김장민 <dewpack@dewpack.com>
Subject: 듀팩장원기계 입니다 - PO73284383
Attachment: 탑엔지니어링_PO73284383_2020-08-17_dwg.z (contains "탑엔지니어링_PO73284383_2020-08-17_dwg.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Backdoor.Remcos
Status:
Malicious
First seen:
2020-08-17 06:27:07 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AgentTesla
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.