MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 144da621021ed42edb46b8f667ec10623625521635bee18664c60ae19946cb51. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 144da621021ed42edb46b8f667ec10623625521635bee18664c60ae19946cb51
SHA3-384 hash: 8fcf163a12d519328bb47a9fe13f8d5ac0f8d24b4369f688ec30866ee6c7107dc7dd4b5cf7062a2b601a4508d14e98a9
SHA1 hash: 5b97a7e32500831fdec2e826aa740e1033f10afe
MD5 hash: 880679e723026f5543a4882572ff4d38
humanhash: east-colorado-robin-aspen
File name:PPO040963RG02 LYNB (3).rar
Download: download sample
Signature AgentTesla
File size:434'457 bytes
First seen:2020-08-14 15:11:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:cdTYDI21eePL0Fqi5H0Skj9I9ieW4tVGoN8drmpZTYV:d1eewq+0SMewBEGXmp4
TLSH 419423F9AE842E1FC384FBC2F0CA1896601BD60ED8D3764849C5E4E70E57E0E5643EA5
Reporter cocaman
Tags:AgentTesla rar


Avatar
cocaman
Malicious email
From: sale-cici@xyuapshang.com
Received: from xyuapshang.com (unknown [23.226.130.108])
Date: 14 Aug 2020 17:02:52 +0200
Subject: RE: PO NO.: PO2000241 - BERKINS TECHNOLOGIES SDN. BHD. - BERKINS-#147
Attachment: PPO040963RG02 LYNB (3).rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-14 15:13:04 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 144da621021ed42edb46b8f667ec10623625521635bee18664c60ae19946cb51

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AgentTesla

Comments