MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34ccb105325cd3955b579d9bb41b3c6ae76946e14159f4a94691f39fd022c522. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 34ccb105325cd3955b579d9bb41b3c6ae76946e14159f4a94691f39fd022c522
SHA3-384 hash: fd8a51dc3b11911b93edb22d1307e3718d11f66c2a1bfbf74ba602576f27b1c17ed8c482a04a75f27ed24615e2be9ff9
SHA1 hash: be2cca87dfc3596d285502cd44b6758081f8be77
MD5 hash: 247d61e0751c638b39b0cb5777c78768
humanhash: indigo-whiskey-juliet-pennsylvania
File name:Order_611_MALEK93032_2098302_2920293_90HU90_30092F_DHUU3HAPRIL.lzh
Download: download sample
Signature AgentTesla
File size:280'244 bytes
First seen:2021-04-08 07:04:44 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:i8E1eiqne2wkmxzn874Z5HrmL2eJAy5kNSUxqPLyqEuIgzWz:HE1eiomVOvlYS0qjUz
TLSH 4D542357E4F2FEFBF49E664B01F643ACD17276F42AEAD950FA3820636C0506990E1528
Reporter abuse_ch
Tags:lzh


Avatar
abuse_ch
Malspam distributing unidentified malware:

From: Malek Zalloum <sales@kunlonfood.com>
Subject: general price
Attachment: Order_611_MALEK93032_2098302_2920293_90HU90_30092F_DHUU3HAPRIL.lzh (contains "Order_611_MALEK#93032_2098302_2920293_90HU90_30092F_DHUU3HAPRIL.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-04-08 07:05:17 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar 34ccb105325cd3955b579d9bb41b3c6ae76946e14159f4a94691f39fd022c522

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments