MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33383629973397eed8a7ed14f35e27d81c2381f0c945f0e2fd12e010c91c2cae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 33383629973397eed8a7ed14f35e27d81c2381f0c945f0e2fd12e010c91c2cae
SHA3-384 hash: 502ee31270b218776b7740254e9d3b06e5c39be5c209ec5f3c967d8d37cc4f53c8938711d8737431a11fb5db2be7b9d1
SHA1 hash: 558d75943d3463daa0af4e935cb736fc59785ca3
MD5 hash: 95f7f28780ace79d9d971e69f0c4b91e
humanhash: sixteen-steak-spaghetti-fix
File name:Purchase Order No. STG1772020.pdf.z
Download: download sample
Signature AgentTesla
File size:281'053 bytes
First seen:2020-08-10 09:29:19 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:BV1yeYWpRipLFvUZv1JIlj458po2rPHmG7wbX1B8NIH6MHDs:BVQe3pRipLpUZ7IWaVrN0RBcIzjs
TLSH 2E54234CAAFBB227F18149018750E743345E658CA068B4B3A7BAC53A1174B7FF16D6B3
Reporter abuse_ch
Tags:AgentTesla z


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: al-tuwaijri.com
Sending IP: 5.79.121.92
From: Abdulmohsen Al-Tuwaijri <am@al-tuwaijri.com>
Subject: Purchase Order No. STG/177/2020
Attachment: Purchase Order No. STG1772020.pdf.z (contains "Purchase Order No. STG1772020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2020-08-10 09:31:11 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

z 33383629973397eed8a7ed14f35e27d81c2381f0c945f0e2fd12e010c91c2cae

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments