MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a07efbb1fc308b46a5f2e0e69cf86c1769a47bea4ecd4c15d8d605045341bd7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0a07efbb1fc308b46a5f2e0e69cf86c1769a47bea4ecd4c15d8d605045341bd7
SHA3-384 hash: 905acf9ada701e7319f5c59cac0e59eb9ffea4e767c9e955ce2b1544c2963becd8dfebfd4f21dafb6129b4c34bfaa611
SHA1 hash: 7bc528a812006a7cd6d4e5a47fb1efdcc988ff2b
MD5 hash: 8970a9a6d30d8bc605ad7027dc7289db
humanhash: echo-white-fix-high
File name:Purchase Order No.0137.pdf.zip
Download: download sample
Signature AgentTesla
File size:428'678 bytes
First seen:2020-06-24 05:10:21 UTC
Last seen:2020-06-24 10:12:01 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:QORtDybRWTvWbOWl/tPpygLKx+ISAPWyctr0FW9JhRmX50BBPvqJfc:QCDyRWTWOiVNKkT9JJYCBBPsfc
TLSH CF9423D9DE50D64FC461291B88BCA5CD18C80CDD887ADEB23E395551BCAB3F53881E2E
Reporter cocaman
Tags:AgentTesla zip


Avatar
cocaman
Malicious email
From: Kateel Vinutha <sales@hhb-lighting.com >
Received: from hhb-lighting.com (unknown [88.150.210.243])
Date: 24 Jun 2020 04:10:01 +0100
Subject: Purchase Order No.0137
Attachment: Purchase Order No.0137.pdf.zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-24 05:12:06 UTC
File Type:
Binary (Archive)
Extracted files:
11
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0a07efbb1fc308b46a5f2e0e69cf86c1769a47bea4ecd4c15d8d605045341bd7

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments