MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0805d50d4c3d3bcbb81035416d74f7ff3e7facc02790297b70d0e82b4d9110b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0805d50d4c3d3bcbb81035416d74f7ff3e7facc02790297b70d0e82b4d9110b3
SHA3-384 hash: 752d4a1fa6a8156831317462069666b2773540492099f58ea51160889b812ab175433f8b779abf0fc2f750b4846b15bb
SHA1 hash: 50905d3878fadddad248ceb82b349c9e8559a899
MD5 hash: bf91beb6c4692b501c2d99dcb76b78bf
humanhash: glucose-sodium-six-burger
File name:LC AGAINST.gz
Download: download sample
Signature AgentTesla
File size:624'445 bytes
First seen:2020-10-07 08:27:58 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:L/EOxgnxUOnDyQVfTVh05VJmjzL6++Y53EK6Q1oCo4TMU:L7xMvb/0TJmjv6++Y5f3oU9
TLSH 09D42377866CD1DFB88275DDD71A0C2CCADB64DCE1DA3033B5608409267A27F69E9780
Reporter cocaman
Tags:AgentTesla gz


Avatar
cocaman
Malicious email (T1566.001)
From: "Angela phillipo <angela.phillipo@grupobimbo.com>"
Received: "from server50.a2zcreatorz.com (unknown [69.16.232.53]) "
Date: "Wed, 07 Oct 2020 13:08:21 +0500"
Subject: "Our new orders & new buyer Fabrics Booking and fabrics"
Attachment: "LC AGAINST.gz"

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-10-07 08:03:50 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 0805d50d4c3d3bcbb81035416d74f7ff3e7facc02790297b70d0e82b4d9110b3

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments