MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34ced2565f618bc28a5b5bb9e2353c455519bf600d6d5e516cb96fbed5bd6de2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 34ced2565f618bc28a5b5bb9e2353c455519bf600d6d5e516cb96fbed5bd6de2
SHA3-384 hash: 8b0908a66f637e429a154dc767d8581cf99b7c69cbc369f30e844188a00bd42f7004ab3bbcf3d054e2ea3dcaa35d3637
SHA1 hash: 7c0a53223e042e738111cf13814bbcf6201cdd45
MD5 hash: 6c320c19cf0b7da5ee8faf4315e8702f
humanhash: arkansas-nitrogen-yankee-twenty
File name:ENQUIRY 1500145314.zip
Download: download sample
Signature AgentTesla
File size:69'998 bytes
First seen:2020-10-16 10:40:51 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:EmHAlTF3C93IzntpKROu+q2MNebrz0JkDbdErbzj8CE3w:DACgntp7DrYwrtDb2/8CR
TLSH 21630259D87D68B08735747582B932C10D3ABAE1A0FD59C86F781B737B64B07CA8E182
Reporter abuse_ch
Tags:AgentTesla zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: attbi.com
Sending IP: 209.58.149.76
From: Purchase<dileep.angelo@attbi.com>
Subject: Quotation : ENQUIRY 1500145314
Attachment: ENQUIRY 1500145314.zip (contains "ENQUIRY 1500145314.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injuke
Status:
Malicious
First seen:
2020-10-16 01:25:43 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 34ced2565f618bc28a5b5bb9e2353c455519bf600d6d5e516cb96fbed5bd6de2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments