MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a540c0ef20f1d9fef77c0c4fd5f111a195b3707f5631eb3f5abfe731bb22f36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0a540c0ef20f1d9fef77c0c4fd5f111a195b3707f5631eb3f5abfe731bb22f36
SHA3-384 hash: 19933b8aeb7a17e7bba03950728cdaefb8a0b333f9e18c9c8255b3c808d877f627bc20c70f688e873742a4af32a2c75b
SHA1 hash: 67c3e3c32b691b9b8c03348ca8caabb6c3a93813
MD5 hash: c2f24c9d1a0fada829a89f6d43b4d734
humanhash: cat-double-floor-india
File name:P.O..zip
Download: download sample
Signature AgentTesla
File size:547'625 bytes
First seen:2020-10-30 20:50:12 UTC
Last seen:2020-10-31 06:43:08 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:pUoNtrxFOCxOdFwanyebTw8NuaPkmm/P8kYvaOYLa7:pUoNkdFpTw8JPI/Pw0La7
TLSH B8C4236CE151A1D0CA26013DC5D7C550C2822B4509BCCA9CBAFD3BC397AB7A057BA67F
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
2
# of downloads :
93
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-10-30 21:23:01 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0a540c0ef20f1d9fef77c0c4fd5f111a195b3707f5631eb3f5abfe731bb22f36

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments