MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f95085fe7403225f44ce927bce4943689ce4ff24bcf9ad0072f5165cb49a6ad0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: f95085fe7403225f44ce927bce4943689ce4ff24bcf9ad0072f5165cb49a6ad0
SHA3-384 hash: d709b6fa36e77e9e3984fadaf55a32270792e467e67b14988722b0b7f6c7306a6d11cbf80eca7c8230d66ea2bb8b18fe
SHA1 hash: 320b886e279d8ebf05b42ba03febfc01469d2989
MD5 hash: 571f295f7b811e7858017f5a9fadb94c
humanhash: table-south-football-happy
File name:AWB (Our ref. BSL-HOU-220616)........PDF(1).r00
Download: download sample
Signature AgentTesla
File size:1'358'027 bytes
First seen:2020-03-16 07:00:13 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:atHtoC7sV+HAVOmNV+PiL5GO1/wp1CpO1kaJ42lkI1A+a+fst7YuSw:atH2feejUORwp1uO1ki4skI1Ta+fstuw
TLSH A855339C4D636F88D85C55B4982EF5655A2F050CEE0A881EF72E382FD44F79632C8726
Reporter cocaman
Tags:AgentTesla r00

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Btualfh
Status:
Malicious
First seen:
2020-03-16 08:52:37 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
14 of 43 (32.56%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

r00 f95085fe7403225f44ce927bce4943689ce4ff24bcf9ad0072f5165cb49a6ad0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
Corsin Camichel commented on 2020-03-16 07:00:50 UTC

RE: Shipping documents (Our ref.: BSL-HOU-220616).