MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 e00f6331ce320d87c2eba5e70298bbb97c11b7d48d4d59a533943e34377ca53e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | e00f6331ce320d87c2eba5e70298bbb97c11b7d48d4d59a533943e34377ca53e |
|---|---|
| SHA3-384 hash: | cc8a49a63928a216a4a4b6e11c3c9d42974f565ab2e2d87775b8d880c45f35c291d795777efe719fb8462f5198ba43b1 |
| SHA1 hash: | 238af4f52e606bf5dac3a55202842d68961b09c1 |
| MD5 hash: | 42759948ef1cb0a0d00b13214e474170 |
| humanhash: | snake-whiskey-delta-louisiana |
| File name: | Remittance Advice.pdf.z |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 433'381 bytes |
| First seen: | 2020-06-10 06:45:53 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 6144:j3b2VlKP/EGvbrS6ksU/bOugjwq5TtuudB7itY8FIHgTDM0D9N386g/8+12mqKC:jrRvfsONrhFdZvuTY0O17u |
| TLSH | DC9423D98402C2470B94CBE7427C52EAB1018E97728BF5634F614EEA5E6E41F7A85FF0 |
| Reporter | |
| Tags: | AgentTesla z |
cocaman
Malicious emailFrom: Account<denibadxb@adobeequipment.com>
Received: from adobeequipment.com (unknown [37.48.85.217])
Date: 10 Jun 2020 05:00:55 -0700
Subject: FW: Fwd: Transfer Remittance 014475 Advice Fx Ref: 4934
Attachment: Remittance Advice.pdf.z
Intelligence
File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-06-10 04:49:56 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
18 of 31 (58.06%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.