MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e27b8cca5a715de583f8e9dad96bfa39635dbcd21d1683c161ae1246aef0f36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0e27b8cca5a715de583f8e9dad96bfa39635dbcd21d1683c161ae1246aef0f36
SHA3-384 hash: daf1bcc86cde4e19475837bc6b46faa74dc4f4f7a3737bc3ede7dc6fdabc06edfe64e0672ae3b4a6874b94cc08c57e44
SHA1 hash: d179500df0907d164c0c27779e4979f4b571f1fb
MD5 hash: 429dafc689598af5316a658e3ed22f93
humanhash: mountain-georgia-bakerloo-lake
File name:PO - 2020764.pdf.gz
Download: download sample
Signature AgentTesla
File size:479'959 bytes
First seen:2020-04-30 12:24:37 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:FfMaTnTVo0Z4aXGNesRPdUgxlBmLZE92q5dFKHKw61IS5xLhzhMiF6ti3HjfGY6z:bTTp4cidUe/m+2q5de05BR16tID5TY
TLSH 0BA4232305A4CB347DA763F97D43A2816583A6CE418C6D91BE3C9BFA780652DD1C8EF4
Reporter abuse_ch
Tags:AgentTesla gz


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: yooileng.co.kr
Sending IP: 212.32.245.155
From: jaelee@yooileng.co.kr
Subject: KN95 Orders
Attachment: PO - 2020764.pdf.gz (contains "PO - 2020764.pdf.bat")

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-30 19:10:19 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
19 of 31 (61.29%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

gz 0e27b8cca5a715de583f8e9dad96bfa39635dbcd21d1683c161ae1246aef0f36

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments