MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa6c646d659ecfa87a166fb912d92de3206922ea8ac804816692ab6a3d2bd76f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fa6c646d659ecfa87a166fb912d92de3206922ea8ac804816692ab6a3d2bd76f
SHA3-384 hash: 1656518cce9f5167d5f53db5d9ec8755bccfa497d7139edc8131b36d7e5cd824e08d2174dca12b2c7ec8bd7efb04e37e
SHA1 hash: 7585e93e04d607e5aa050a819797ffcabd30461b
MD5 hash: 88f0bc9c62643e4d90a3687769a320d8
humanhash: alaska-salami-fish-nine
File name:CATALOGUE.ARJ
Download: download sample
Signature AgentTesla
File size:523'586 bytes
First seen:2020-08-06 07:57:32 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:XDnn5wxFFQhBjCuHt649TV4mB2Esl0/ZZ:Xjn5wx7i+uN604mB2tkZ
TLSH 2AB423AB804E5D28FB3A58AB4F2301CB4BA75B0D96B6F1D0F16826FBD2654630D65C70
Reporter abuse_ch
Tags:AgentTesla arj


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: hshgroups.co
Sending IP: 104.168.166.26
From: Joyce Lee<sxdfzc@hotmail.com>
Subject: FIRST ORDER FROM SEAWAY CHINA TRADING
Attachment: CATALOGUE.ARJ (contains "fNpfx9reymzBhA3.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-06 07:59:07 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

arj fa6c646d659ecfa87a166fb912d92de3206922ea8ac804816692ab6a3d2bd76f

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments