MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c69228ebf9357abdbc1fd0a94c44e951f179208b932d627dbab57fb5135ec4ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c69228ebf9357abdbc1fd0a94c44e951f179208b932d627dbab57fb5135ec4ff
SHA3-384 hash: 715d459f457d082cdc8fd9b335dd9504b5243fa4254fbf9b99c8983ffcc990aec3d42b14d6021baba732592a6ee4fd29
SHA1 hash: 35a5ecda0086fc5d20525f4d3de85dd7643a72aa
MD5 hash: 28f715a0ebb61589898c43ca42a34b0a
humanhash: nineteen-jig-mango-princess
File name:SOA.rar
Download: download sample
Signature AgentTesla
File size:396'224 bytes
First seen:2020-08-19 04:40:43 UTC
Last seen:2020-08-21 09:44:27 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:D58Qo/y0/unSwO9FIWp4qaUvhYGcuAjpIb5eoFVcF:syeun5O9mwRaUvhVqjSlLcF
TLSH F18423B89020195365A72430BAC0B24EF4CCCF0F651AAD713BED78FA8CB5DA79D59D18
Reporter cocaman
Tags:AgentTesla NanoCore rar


Avatar
cocaman
Malicious email
From: anne@goodrichuae.com
Received: from goodrichuae.com (unknown [95.211.253.212])
Date: 19 Aug 2020 00:34:28 -0700
Subject: RE- Statement Of Account
Attachment: SOA.rar

Intelligence


File Origin
# of uploads :
3
# of downloads :
111
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.SmartAssembly
Status:
Malicious
First seen:
2020-08-19 00:15:01 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar c69228ebf9357abdbc1fd0a94c44e951f179208b932d627dbab57fb5135ec4ff

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
NanoCore

Comments