MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d9ad93d59c90d990853a976552382bfb7498e07822971e5fdfff5d8dd2b55d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4d9ad93d59c90d990853a976552382bfb7498e07822971e5fdfff5d8dd2b55d7
SHA3-384 hash: 0cc3ad9d67a3d75eb9fee2457690586d2cc40bfc03f9734e5c8ab6f931dacc2c0765cba23d75d481bae6f86aaaedd7f8
SHA1 hash: 78455cfe645dcd0b7d09e3b185cd1a961aa8172e
MD5 hash: 045c474824628ffde7a0dd2c290d88e9
humanhash: earth-south-fix-hawaii
File name:FYI.zip
Download: download sample
Signature AgentTesla
File size:586'356 bytes
First seen:2021-01-13 20:15:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:IVS/i4M11Iw6N3kBOl7128igb4hpgwi6L3n27Ourt9w:I6it4xNaOl7Tg1iI3n27pS
TLSH 90C42343144E37D54E733A438AF068D443D62A29373763BFD62C4A9BD0494BC29BA76B
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: shengdatrade.com.cn
Sending IP: 185.196.8.241
From: info@shengdatrade.com.cn
Subject: FYI
Attachment: FYI.zip (contains "FYI.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-13 20:16:15 UTC
AV detection:
9 of 44 (20.45%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

zip 4d9ad93d59c90d990853a976552382bfb7498e07822971e5fdfff5d8dd2b55d7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments