MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 eeff7d436d4b75154451fc47bc795ecfc50be5eb9d12114e4fc6e335add62db6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AgentTesla
Vendor detections: 3
| SHA256 hash: | eeff7d436d4b75154451fc47bc795ecfc50be5eb9d12114e4fc6e335add62db6 |
|---|---|
| SHA3-384 hash: | 2c158d5f3cf8b30bce82d4b617d443d8ea5233b7c7ffcc6a3086219471a3d292faad28c3ea05e157cc7942c1409d0a44 |
| SHA1 hash: | c0c51d5cb32306fb179c1dc6a8ade66e13c7958c |
| MD5 hash: | f3542bc5b3992e7bcc21ec40d147369d |
| humanhash: | jersey-wyoming-bacon-salami |
| File name: | NewyorkUSA-hsbc - confirmation.img |
| Download: | download sample |
| Signature | AgentTesla |
| File size: | 1'245'184 bytes |
| First seen: | 2020-07-29 08:24:06 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:FCbC95QG3ZrhuMIRzWXjdm99V9fh+QGNUVfD6wFLrU5Ofn+HOvFBc8S:kCThuMOJ9V95+3UVfdgC+Hezc |
| TLSH | 1C45DF6CE1411673D6EB0FFCE4DB194422BE6FE2A551C7193EAA3F697F33A400650A12 |
| Reporter | |
| Tags: | AgentTesla img |
cocaman
Malicious emailFrom: HSBC_Banking Corporation Ltd <consultant@pactesting.com>
Received: from green8.newpages.com.my (green8.newpages.com.my [110.74.178.137])
Date: Wed, 29 Jul 2020 15:16:51 +0800
Subject: HSBC_Payment Details
Attachment: NewyorkUSA-hsbc - confirmation.img
Intelligence
File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-29 08:26:08 UTC
File Type:
Binary (Archive)
Extracted files:
16
AV detection:
14 of 29 (48.28%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
AgentTesla
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.