MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ca3ec5f1edbbc99fee08a02b5e9acca760bde186e5f3e2775bdbe889419b1bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0ca3ec5f1edbbc99fee08a02b5e9acca760bde186e5f3e2775bdbe889419b1bc
SHA3-384 hash: ffe6dae0009765e330adca234a7ed5e0b53dcacbc9dd8204f2fb899d6fef9678d85130ddd78b58ef03891b21af870f5c
SHA1 hash: 2cac3ac9b242631dde60d35aefc0a3b8027d0700
MD5 hash: a320665e9e17c884624a611c059a7206
humanhash: yankee-paris-moon-low
File name:Swift Copy#947026.zip
Download: download sample
Signature AgentTesla
File size:474'189 bytes
First seen:2021-04-02 13:27:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:htRucgAHctTkQ/AO3/2XrgeZpLTW5B0acBpVT4rtn/u:JucjIkQoO3uX0qLT8mbBrE/u
TLSH 16A423C043F8821C87866815DF6E95F2C815E575F82918357A3B28D4C2BC389EADE17F
Reporter GovCERT_CH
Tags:AgentTesla

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-04-02 02:02:16 UTC
AV detection:
10 of 42 (23.81%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 0ca3ec5f1edbbc99fee08a02b5e9acca760bde186e5f3e2775bdbe889419b1bc

(this sample)

  
Dropped by
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments